Platform

Integrating AI Agents with Epic

Last updated / Reviewed by Clunic Research Team

Quick answer

AI agents reach Epic through four documented paths: the public FHIR APIs, a listing and Toolbox access through Epic's vendor programme, an embedded launch inside Hyperdrive, and traditional HL7 interfaces for write back. Which path you get depends on your own Epic contract and your integration team, not on the vendor alone.

Free tool

AI Readiness Assessment

Twelve factual questions on data access, governance and change capacity.

Need it signed off?

Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.

Book an evaluation call

Integration methods

The routes data can travel on this platform. Which one a vendor uses decides how much of the work lands on your team.

  • Epic on FHIR

    Epic publishes FHIR R4 APIs and documents them openly. This is the modern path for reading patient context and for writing structured data back, and it is the path an AI medical scribe should be asking about first. Access to production still runs through your organisation, not the vendor: someone on your side has to approve and configure the client.

  • Showroom and the vendor programme

    Epic's marketplace, formerly known as App Orchard, is where customers find third party applications, and the associated developer programme is where a vendor gets sandbox and documentation access. A listing is a useful signal that a vendor has done the work. It is not the same thing as being deployed at your site, and vendors sometimes blur the two in a sales call.

  • Embedded launch in Hyperdrive

    The best clinician experience is one where the agent opens in context inside the chart rather than in a second window. That is a SMART on FHIR style launch inside Epic's client. It takes longer to approve, and it is the difference between a tool clinicians use and a tool they mean to use.

  • HL7 v2 interfaces

    Older, unglamorous and still how a great deal of real write back happens, particularly for documents and results. If a vendor's Epic story turns out to be an HL7 interface plus a document drop, that is not automatically wrong. It just means an interface analyst on your side owns part of the project.

  • Haiku and Canto

    Epic's mobile clients. For ambient capture they matter more than any server side path, because the microphone that records the encounter is usually the phone already in the clinician's pocket running Haiku. A scribe that lives inside that app removes an entire step from the workflow.

Why does Epic integration decide whether an agent gets adopted?

Clinicians do not adopt tools that live outside the chart. They tolerate them for a pilot and abandon them by month three, and the abandonment is rarely reported as a failure because nobody is measuring by then.

An agent that opens in context, reads the encounter it is supposed to be about and writes back without a copy and paste step is used. One that requires two windows and a manual transfer is used until the first busy clinic. This is the single most reliable predictor of adoption we see discussed, and it is why we treat the integration question as the first question rather than a technical detail for later.

It is also why the honest answer to which AI scribe vendor is best often depends on your Epic build rather than on the product.

What are the actual integration paths?

Four, described in the methods above, and they are not alternatives so much as layers. A typical embedded ambient documentation deployment uses FHIR for patient context, a Hyperdrive launch for the clinician experience, and a document write back for the signed note.

When a vendor says they are Epic integrated, ask which of those they mean. The word covers everything from a full embedded launch to a folder on a shared drive, and the difference is months of project time. The same question applies to every other system, which is why our EHR integration pages ask it in the same shape each time.

What does your organisation have to do?

More than most buyers expect, and this is where timelines slip.

  • Name an Epic analyst or integration owner. Without one, nothing moves, whatever the vendor promises.
  • Raise the request through your own change process and find out how long that queue is before you sign anything.
  • Complete a security review, which for a tool handling audio of clinical encounters will be a real review rather than a formality.
  • Agree what gets written back, in what format, and into which part of the chart.
  • Agree who tests it, and against what.

We scope this work as part of an AI readiness audit, because the answer changes the shortlist. A practice with no Epic analyst should not be buying a product whose value depends on one.

What does HIPAA add on top of the integration?

Integration and compliance are separate approvals and they run on different clocks. A vendor can be listed in Epic's marketplace and still be wrong for you on retention, subprocessors or model training.

Get the business associate agreement moving in parallel with the technical work rather than after it. Ask specifically where audio is stored, how long it is kept, and whether your data trains shared models. The HIPAA and AI compliance page sets out what to insist on and what is negotiable.

How long does an Epic integration take?

There is no honest single number, and any vendor offering one is quoting their side of the work rather than yours. What we can say is that the sequence is predictable: security review, then integration request, then build, then validation, then a controlled go live.

The long pole is almost always your internal queue rather than the vendor's engineering. Two useful questions at the start: how many integration requests are ahead of this one, and who can reprioritise it. Ask them before you agree a go live date with the clinicians, because the date you promise them is the one they will remember.

Which agent use cases fit Epic sites first?

Ambient documentation is the usual first project, because the workflow is contained, the benefit is felt by the people doing the work, and the failure mode is a bad draft that a clinician corrects rather than a wrong action taken automatically.

After that, the ones with clean data boundaries tend to go best: documentation first, then the administrative queues where an agent drafts and a human approves. Anything that touches ordering, or that acts without review, belongs much later in the sequence and needs a governance conversation first.

If you want the ROI framing before the technical one, the ROI calculator models the documentation case with its assumptions on the page.

Vendor compatibility

How each vendor connects, as that vendor publicly documents it. Native means the connection is built into the platform, API means it is built on the published interfaces, workaround means neither and someone has to bridge it.

Vendors and how deeply each one integrates with Epic Systems
VendorCategoryIntegration depth
AbridgeAmbient documentationNative
Microsoft Dragon CopilotAmbient documentationNative
Ambience HealthcareAmbient documentationNative
SukiAmbient documentationAPI
NablaAmbient documentationAPI
DeepScribeAmbient documentationAPI
NotableWorkflow automationAPI
Assort HealthVoice agentsAPI
HyroPatient accessAPI
WaystarRevenue cycleAPI
AvailityPayer connectivityAPI
FreedAmbient documentationWorkaround
Heidi HealthAmbient documentationWorkaround

Questions we get asked

Does Epic charge for API access?

Epic publishes its FHIR API documentation openly, and commercial terms for vendors participating in its programme are set by Epic and change over time. Ask your Epic account team what applies to your contract, and ask the vendor what they pay, because a cost on their side eventually appears on yours.

What is the difference between App Orchard, Showroom and Toolbox?

They are stages of the same programme under names that have changed. App Orchard was the original marketplace and developer programme, Showroom is the customer facing marketplace, and Toolbox refers to the developer resources. A vendor being present in any of them means they have done integration work. It does not mean they are live at a site like yours.

Can we integrate an AI agent without Epic's involvement?

Not in any way you would want to run in production. Screen scraping and shared credentials break at the next upgrade and create access control problems that will not survive an audit. If a vendor proposes one, treat it as a statement about their engineering rather than a shortcut.

Do smaller practices on Epic get the same integration options?

The technical paths are the same, but the resourcing is not. A ten clinician group on a hosted Epic instance may have no analyst of its own and will depend on whoever hosts it. That constraint should shape the shortlist rather than be discovered during implementation, which is why we ask about it before recommending anything.

Is a Showroom listing enough due diligence?

No. It tells you a vendor has integration experience. It tells you nothing about their security posture, their retention policy, their financial stability or how they behave when something goes wrong at two in the afternoon in a full clinic. Run your own review.