Platform

Integrating AI Agents with Epic

Last updated / Reviewed by Clunic Research Team

Quick answer

AI agents reach Epic through four documented paths: the public FHIR APIs, a listing and Toolbox access through Epic's vendor programme, an embedded launch inside Hyperdrive, and traditional HL7 interfaces for write back. Which path you get depends on your own Epic contract and your integration team, not on the vendor alone.

Free tool

AI Readiness Assessment

Twelve factual questions on data access, governance and change capacity.

Need it signed off?

Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.

Book an evaluation call

Integration methods

The routes data can travel on this platform. Which one a vendor uses decides how much of the work lands on your team.

  • Epic on FHIR

    Epic publishes FHIR R4 APIs and documents them openly. This is the modern path for reading patient context and for writing structured data back, and it is the path an AI medical scribe should be asking about first. Access to production still runs through your organisation, not the vendor: someone on your side has to approve and configure the client.

  • Showroom and the vendor programme

    Epic's marketplace, formerly known as App Orchard, is where customers find third party applications, and the associated developer programme is where a vendor gets sandbox and documentation access. A listing is a useful signal that a vendor has done the work. It is not the same thing as being deployed at your site, and vendors sometimes blur the two in a sales call.

  • Embedded launch in Hyperdrive

    The best clinician experience is one where the agent opens in context inside the chart rather than in a second window. That is a SMART on FHIR style launch inside Epic's client. It takes longer to approve, and it is the difference between a tool clinicians use and a tool they mean to use.

  • HL7 v2 interfaces

    Older, unglamorous and still how a great deal of real write back happens, particularly for documents and results. If a vendor's Epic story turns out to be an HL7 interface plus a document drop, that is not automatically wrong. It just means an interface analyst on your side owns part of the project.

  • Haiku and Canto

    Epic's mobile clients. For ambient capture they matter more than any server side path, because the microphone that records the encounter is usually the phone already in the clinician's pocket running Haiku. A scribe that lives inside that app removes an entire step from the workflow.

Why does Epic integration decide whether an agent gets adopted?

Clinicians do not adopt tools that live outside the chart. They tolerate them for a pilot and abandon them by month three, and the abandonment is rarely reported as a failure because nobody is measuring by then.

An agent that opens in context, reads the encounter it is supposed to be about and writes back without a copy and paste step is used. One that requires two windows and a manual transfer is used until the first busy clinic. This is the single most reliable predictor of adoption we see discussed, and it is why we treat the integration question as the first question rather than a technical detail for later.

It is also why the honest answer to which AI scribe vendor is best often depends on your Epic build rather than on the product.

What are the actual integration paths?

Four, described in the methods above, and they are not alternatives so much as layers. A typical embedded ambient documentation deployment uses FHIR for patient context, a Hyperdrive launch for the clinician experience, and a document write back for the signed note.

When a vendor says they are Epic integrated, ask which of those they mean. The word covers everything from a full embedded launch to a folder on a shared drive, and the difference is months of project time. The same question applies to every other system, which is why our EHR integration pages ask it in the same shape each time.

What is the difference between Showroom, Connection Hub, Toolbox and Vendor Services?

They are the pieces of one programme that replaced App Orchard, and the names matter because vendors use them loosely in sales calls. As Epic describes the programme on its site and in trade reporting from its 2023 launch, checked in September 2026:

  • Showroom (showroom.epic.com) is the customer facing catalogue where an Epic organisation looks up third party products and services. It is the umbrella, not a tier.
  • Connection Hub is the open directory inside Showroom. Any vendor that has built a live integration with an Epic customer can list for a modest annual fee, reported at 500 US dollars at launch. A Connection Hub listing means the vendor has connected somewhere. It does not mean Epic has reviewed the integration.
  • Toolbox is the curated subset. Epic publishes recommended integration practices for particular software categories, and Toolbox lists the products that follow them. For ambient documentation this is the tier to look for, because it tells you the vendor built the launch and write back the way Epic wants it built.
  • Workshop lists vendors co-developing with Epic. A small group, and a signal of depth.
  • Vendor Services (vendorservices.epic.com) is the developer side: a paid subscription, reported at 1,900 US dollars a year at launch, that buys sandbox access, tutorials and technical support. Open.epic and fhir.epic.com carry the free public documentation.

So when a vendor says "we are in Epic's marketplace", ask which of these. Connection Hub is table stakes. Toolbox for the ambient documentation category is the meaningful claim, and it is checkable in ten minutes on the Showroom site. Neither replaces your own review, and Epic says as much in the listing terms. The fees quoted are as reported at launch; check the current figures with Epic before assuming them.

What does your organisation have to do?

More than most buyers expect, and this is where timelines slip.

  • Name an Epic analyst or integration owner. Without one, nothing moves, whatever the vendor promises.
  • Raise the request through your own change process and find out how long that queue is before you sign anything.
  • Complete a security review, which for a tool handling audio of clinical encounters will be a real review rather than a formality.
  • Agree what gets written back, in what format, and into which part of the chart.
  • Agree who tests it, and against what.

We scope this work as part of an AI readiness audit, because the answer changes the shortlist. A practice with no Epic analyst should not be buying a product whose value depends on one.

What does the security and third party review path look like?

Two reviews run in parallel and neither is Epic's. The first is your own third party risk review, run by your security team against the vendor's SOC 2 or HITRUST evidence, a completed questionnaire, a penetration test summary and the architecture diagram that shows where audio goes. The second is the BAA and privacy review, run by compliance and legal. Epic's own review of a Toolbox listing is a check that the integration follows its published practices; it is not a substitute for either of yours, and Epic's terms say so.

For an ambient scribe the security review is a real review rather than a formality, because the vendor holds audio of clinical conversations before the note exists. The questions that take longest are these:

  • Where is audio stored, in which cloud region, for how long, and can retention be set to zero after the note is signed.
  • Which subprocessors sit behind the product, in particular the speech and language model providers, and are they flowed down in the BAA.
  • How is the Epic connection authenticated: a backend system client with its own credentials, or a SMART launch carrying the clinician's context. Both are legitimate; shared service accounts are not.
  • What audit logging exists on the vendor side, and can it be exported into your SIEM.
  • Is your data used to train shared models, and what does the contract say.

Start the security review the week you shortlist, not the week you sign. At most health systems it is the item with the longest lead time, and it is the item most often blamed for a go live slipping by a quarter. The HIPAA and AI page sets out what the BAA has to say, and the questions to ask AI vendors about HIPAA are the questionnaire items in plain language. Once the vendor is live, the breach exposure tool models what a vendor side incident would mean for your notification duties.

What does HIPAA add on top of the integration?

Integration and compliance are separate approvals and they run on different clocks. A vendor can be listed in Epic's marketplace and still be wrong for you on retention, subprocessors or model training.

Get the business associate agreement moving in parallel with the technical work rather than after it. Ask specifically where audio is stored, how long it is kept, and whether your data trains shared models. The HIPAA and AI compliance page sets out what to insist on and what is negotiable.

What do Epic's own ambient features change about the buy decision?

Epic now ships generative AI features of its own inside the chart, developed with Microsoft and announced publicly since 2023, and it has described ambient documentation work built with partners. For a buyer this changes the question from "which scribe" to "buy a scribe, wait for Epic, or both".

Three things to weigh. First, availability: what Epic offers is tied to your version and your Epic contract, and the honest answer for many organisations is that the feature they read about is not yet switched on for them. Ask your Epic account team what is generally available on your version today, not what is on the roadmap. Second, depth: a third party vendor that has spent years on specialty note behaviour, coding support and multilingual encounters may still be ahead of a platform feature on the things your clinicians notice. Third, procurement: an Epic feature does not need a new BAA, a new security review or a new integration queue, which removes the three items that most often delay a third party deployment.

The practical reading is that Epic's own features raise the bar a third party has to clear, and they make "do nothing for six months" a defensible option where it was not before. They do not make the third party market irrelevant. Run the same bake off you would run between two vendors, with Epic's feature as one arm if it is available to you, and let the edit log decide. Where a third party wins, the AI scribe comparison sets out which ones are embedded in Epic.

How long does an Epic integration take?

There is no honest single number, and any vendor offering one is quoting their side of the work rather than yours. What we can say is that the sequence is predictable: security review, then integration request, then build, then validation, then a controlled go live.

The long pole is almost always your internal queue rather than the vendor's engineering. Two useful questions at the start: how many integration requests are ahead of this one, and who can reprioritise it. Ask them before you agree a go live date with the clinicians, because the date you promise them is the one they will remember.

What are the realistic timelines and the usual blockers?

No honest single number exists, so here is the sequence and where it stalls. Each stage is owned by someone on your side, and the timeline is the sum of their queues rather than the vendor's engineering.

Typical stages of an Epic ambient scribe integration
StageOwnerUsual blocker
Security and BAA reviewSecurity, compliance, legalQuestionnaire backlog; retention and training terms not agreed
Integration request and prioritisationEpic programme officeQueue position behind upgrades and regulatory work
Client build and configurationEpic analystNo named analyst; SMART launch configuration in Hyperdrive
Interface build for write backInterface analystNote type, author attribution and encounter matching not agreed
Validation in non productionAnalyst plus clinician testersTest patients and audio not prepared; Haiku device enrolment
Controlled go liveClinical sponsorTraining not scheduled; no owner for template fixes

Three blockers account for most slipped dates. The integration queue is the first: a health system mid upgrade or mid regulatory build will not prioritise a scribe, and no vendor can change that. The absence of a named Epic analyst is the second, and it is the reason we ask about it before recommending anything. The third is the write back specification: which note type, whether the scribe or the clinician is the author of record, how the encounter is matched when the clinician started recording before opening the chart. Agree all three in writing before the build starts, because changing them afterwards is a second project.

A hosted Epic instance, common for smaller organisations under a Community Connect arrangement, adds a fourth: the host's own governance and queue, over which you have little control. Ask the host what it has already approved for other Community Connect sites, because an approved vendor is months ahead of an unapproved one.

How deep does each vendor go in Epic?

Thirteen vendors in our registry document an Epic path. The depth recorded here is what the vendor and Epic publish, checked in September 2026, and each pairing has its own page with the detail and the gaps.

AI vendors and their documented Epic integration depth
VendorCategoryDepthDetail
AbridgeAmbient documentationNativeAbridge and Epic
Microsoft Dragon CopilotAmbient documentationNativeDragon Copilot and Epic
Ambience HealthcareAmbient documentationNativeAmbience and Epic
SukiAmbient documentation and dictationAPISuki and Epic
NablaAmbient documentationAPINabla and Epic
DeepScribeAmbient documentation, oncologyAPIDeepScribe and Epic
NotableWorkflow automationAPINotable and Epic
Assort HealthVoice agentsAPIAssort Health and Epic
HyroPatient accessAPIHyro and Epic
WaystarRevenue cycleAPIWaystar and Epic
AvailityPayer connectivityAPIAvaility and Epic
FreedAmbient documentationWorkaroundFreed and Epic
Heidi HealthAmbient documentationWorkaroundHeidi and Epic

Native means the vendor is embedded in Epic's clients, typically with a Hyperdrive launch and, for scribes, a presence in Haiku on the clinician's phone. API means the vendor builds on Epic on FHIR and the interfaces described above, and your team owns the connection. Workaround means no documented write back; the clinician copies the note from the vendor's app into the encounter. Workaround is not a reason to exclude a product for a small group, and it is a reason to exclude it for a health system that expects adoption to hold past month three.

Does Suki work with Epic is one of the most searched questions in this category. The short answer is yes, on Epic's published interfaces rather than as an embedded native client, so the clinician experience depends on how your team configures the launch. Dragon Copilot and Epic is the other frequent question, and the answer there is native, with the commercial path running through Microsoft. Both are answered in full on the linked pages.

What does the integration itself cost?

More than the licence for the first year at most health systems, and almost none of it appears on the vendor's quote. Budget for five things.

  • Vendor side fees. Some vendors pay Epic programme fees and pass them through as an integration or onboarding charge. Ask whether onboarding is included in the per clinician rate or invoiced separately, and whether there is a per site or per interface fee.
  • Your analyst time. An Epic analyst and an interface analyst for the build and validation, then a fraction of an analyst on an ongoing basis for upgrades. If you do not have these people, the cost is a contractor day rate or the host's charge under a Community Connect arrangement.
  • Security review time. A real review of an audio handling vendor is days of a security analyst's time, plus legal time on the BAA.
  • Devices and enrolment. Scribes that run in Haiku need enrolled phones. Shared room microphones are an alternative with their own cost.
  • Training and the internal owner. An hour per clinician at go live and a named owner who fixes templates in week three. Without the owner, adoption decays and the licence is paid for nothing.

Epic publishes its FHIR documentation openly, and the commercial terms for vendors in its programme are set by Epic and change; ask your Epic account team what applies to your contract rather than relying on a figure from a vendor. On the benefit side, the ROI calculator models returned clinician time with its assumptions printed on the page, and the EHR integration questions post lists what to ask before the order form is signed.

Which agent use cases fit Epic sites first?

Ambient documentation is the usual first project, because the workflow is contained, the benefit is felt by the people doing the work, and the failure mode is a bad draft that a clinician corrects rather than a wrong action taken automatically.

After that, the ones with clean data boundaries tend to go best: documentation first, then the administrative queues where an agent drafts and a human approves. Anything that touches ordering, or that acts without review, belongs much later in the sequence and needs a governance conversation first.

If you want the ROI framing before the technical one, the ROI calculator models the documentation case with its assumptions on the page.

What does an independent review add before you sign?

A shortlist built from your Epic version, your hosting arrangement, your integration queue and your specialties rather than from a vendor's pipeline. A read of the BAA and the order form against the retention, training and renewal clauses that matter. And a written write back specification and pilot design agreed with your analyst before the build starts, so the go live date you promise clinicians is one you can keep.

That is the work of an AI readiness audit for an organisation that has not yet chosen, and of vendor selection for one that has a shortlist. We take no vendor commissions and no referral fees, which is why the recommendation can be to wait for the feature Epic is already building for you. Book a call if you want that view before the security questionnaire goes out.

Vendor compatibility

How each vendor connects, as that vendor publicly documents it. Native means the connection is built into the platform, API means it is built on the published interfaces, workaround means neither and someone has to bridge it.

Vendors and how deeply each one integrates with Epic Systems
VendorCategoryIntegration depthHow it works
AbridgeAmbient documentationNativeAbridge on Epic Systems
Microsoft Dragon CopilotAmbient documentationNativeMicrosoft Dragon Copilot on Epic Systems
Ambience HealthcareAmbient documentationNativeAmbience Healthcare on Epic Systems
SukiAmbient documentationAPISuki on Epic Systems
NablaAmbient documentationAPINabla on Epic Systems
DeepScribeAmbient documentationAPIDeepScribe on Epic Systems
NotableWorkflow automationAPINotable on Epic Systems
Assort HealthVoice agentsAPIAssort Health on Epic Systems
HyroPatient accessAPIHyro on Epic Systems
WaystarRevenue cycleAPIWaystar on Epic Systems
AvailityPayer connectivityAPIAvaility on Epic Systems
FreedAmbient documentationWorkaroundFreed on Epic Systems
Heidi HealthAmbient documentationWorkaroundHeidi Health on Epic Systems

Questions we get asked

Does Epic charge for API access?

Epic publishes its FHIR API documentation openly, and commercial terms for vendors participating in its programme are set by Epic and change over time. Ask your Epic account team what applies to your contract, and ask the vendor what they pay, because a cost on their side eventually appears on yours.

Can we integrate an AI agent without Epic's involvement?

Not in any way you would want to run in production. Screen scraping and shared credentials break at the next upgrade and create access control problems that will not survive an audit. If a vendor proposes one, treat it as a statement about their engineering rather than a shortcut.

Do smaller practices on Epic get the same integration options?

The technical paths are the same, but the resourcing is not. A ten clinician group on a hosted Epic instance may have no analyst of its own and will depend on whoever hosts it. That constraint should shape the shortlist rather than be discovered during implementation, which is why we ask about it before recommending anything.

Is a Showroom listing enough due diligence?

No. It tells you a vendor has integration experience. It tells you nothing about their security posture, their retention policy, their financial stability or how they behave when something goes wrong at two in the afternoon in a full clinic. Run your own review.

What is the difference between App Orchard, Showroom, Connection Hub and Toolbox?

App Orchard was the original marketplace and developer programme and has been retired. Showroom is the customer facing catalogue that replaced it. Connection Hub is the open directory inside Showroom for any vendor with a live Epic integration. Toolbox is the curated subset that follows Epic's published integration practices for a category. Vendor Services is the paid developer programme. A vendor present in any of them has done integration work; only your own review tells you whether they are right for you.

Can AI integrate with Epic EHR?

Yes, through four documented paths: Epic on FHIR for reading context and writing structured data, a SMART on FHIR launch inside Hyperdrive for an embedded experience, HL7 v2 interfaces for document and result write back, and presence inside the Haiku and Canto mobile clients. Thirteen vendors in our registry document an Epic path at native, API or workaround depth, listed above. Access to your production instance always runs through your own Epic team.

Which AI scribe works best with Epic?

Abridge, Microsoft Dragon Copilot and Ambience are embedded natively, including in Haiku. Suki, Nabla and DeepScribe build on Epic's published interfaces. Freed and Heidi have no documented write back. Best depends on your version, your specialties and whether Epic's own ambient feature is available to you, so run a bake off between two rather than choosing from a list. The comparison grades each one.