Epic - Backend - Access to All Organizations

289 views
Skip to first unread message

Asmith Resho

unread,
Sep 21, 2022, 2:44:31 AM9/21/22
to SMART on FHIR
Hi,

I have created an Epic API app with "Backend Systems" option enabled. I am able to generate token and fetch data using this app.

But, I found the below line in the documentation,

"A backend system is not authorized by a specific person and might not have a user interface, but is authorized at the system level to access data."

Does this mean, using back-end system we can access any patient's data across organizations within the Epic System?

Can anyone please shed some light on this?

tomo yamano

unread,
Sep 21, 2022, 9:51:51 AM9/21/22
to Asmith Resho, SMART on FHIR

Hello Mr Resho,

In my understanding, your frontend app can access and pull the data from the backend  in sandbox env. 
 
Have you reached out to the support team? 


--
You received this message because you are subscribed to the Google Groups "SMART on FHIR" group.
To unsubscribe from this group and stop receiving emails from it, send an email to smart-on-fhi...@googlegroups.com.

Asmith MD

unread,
Sep 21, 2022, 10:03:35 AM9/21/22
to SMART on FHIR
Thank you for your reply.

Yes, I will be able to access the organization that I have under my sandbox env now. Once, the app is moved to production, will I be able to access the patient data from other organizations too ?.

If I can, I couldn't find the documentation for authorizing other organizations with our API. It will be great, if I get something to look on.


<<<Have you reached out to the support team?>>>
No, not yet.

Michele Mottini

unread,
Sep 21, 2022, 10:06:13 AM9/21/22
to SMART on FHIR
I am pretty sure you need to talk with each individual organization you want to connect to. You'll need a business agreement with them to access their data.

But really you should ask Epic, not here . .. .

  - Michele
  CareEvolution


tomo yamano

unread,
Sep 22, 2022, 8:27:14 PM9/22/22
to Michele Mottini, SMART on FHIR

I  was thinking that the organization in the EPIC network can access the data across the network beyond the boundary. 

Tomo

Asmith MD

unread,
Sep 23, 2022, 2:11:49 AM9/23/22
to SMART on FHIR
Thank you for your response Tomo.

I was also thinking in the same way. But, there is no document I could find in epic documentation that confirms the same. In addition, won't this be a security issue to access an organization's data without having an agreement with them?

Trying to figure out whether dynamic client registration will do the trick https://fhir.epic.com/Documentation?docId=oauth2&section=Standalone-Oauth2-OfflineAccess-0

tomo yamano

unread,
Sep 23, 2022, 6:46:23 AM9/23/22
to Asmith MD, SMART on FHIR

When you have joined the Epic network,  your org would not access the data through the entire system?   Then what is the reason to utilize it ? 😗 Maybe should you reach out to the suppor team. 

Asmith MD

unread,
Sep 27, 2022, 3:21:46 PM9/27/22
to tomo yamano, SMART on FHIR
Thank you tomo for your response. I will check with the Epic support team.
Reply all
Reply to author
Forward
0 new messages