Integrations
Yes, Surface can work with Epic, and your institution holds the key
What is Epic and where is it used?
Epic is the largest electronic health record in the world by patient volume. The company states that more than 325 million patients have a current electronic record in Epic, across academic medical centers, community hospitals, mental health, urgent care and payers.
It also runs the most mature public API program in the sector. Epic publishes over 750 no-cost APIs and interfaces and a catalogue of hundreds of FHIR APIs across R4, STU3 and DSTU2 on its developer site.
Does Epic grant the access, or does the provider?
The provider does. Epic's documentation is explicit: a third-party application registered on the Epic on FHIR site requires the community member to sign the open.epic API Subscription Agreement, and its own staff, holding the relevant internal security point, to enable the client identifier against their instance.
Worth saying plainly: we have no partnership with Epic, no certification and no marketplace listing, and none of the three is needed to start. The key sits on the customer's desk. While that enablement moves through internal channels, the export can already be producing results.
What does Surface need out of Epic?
Four fields per order, none of which requires access to the full chart.
- What was ordered. The text of the exam order, the referral or the pending check-up.
- For whom. A patient identifier, pseudonymized inside the institution if policy requires it.
- When. The date of the encounter where the order was written.
- How to reach them. A current mobile number and the contact language.
The rest of the chart stays where it is. A small scope also shortens the security review, which in Epic institutions tends to be the longest stage.
A real integration, or a CSV the provider controls?
With Epic the standards path is the most mature of the four systems we write about, and it still starts after the institution enables access. The export runs in parallel from day one and produces the first result while the other process advances.
| Epic APIs | CSV the provider controls | |
|---|---|---|
| Time to first result | Begins when the institution enables the client on its instance | One week of setup and it is in production |
| Enablement requirement | An agreement signed by the institution plus client registration | None outside the institution |
| Who grants access | The institution, on its own instance | The institution, on its own report |
| Coverage | Continuous, within the permissions granted | The exported slice, at the frequency the institution sets |
The order matters little as long as one of the two is running. The full reasoning is in you can do this without an API and the calendar in in three weeks.
What does the IT team have to do?
On the export route, three things, and none of them touches clinical configuration.
Define the report.
The period's unscheduled orders with the four fields, written by the reporting team the institution already has.
Schedule the delivery.
A daily run into a destination you control, inside your own perimeter.
Review the first week.
We validate the file against what the clinical team sees and adjust the report with you before scaling the volume.
How do free-text orders inside the system get read?
A well-implemented standard hands over the order as data. What decides whether that order is bookable still travels in text: the encounter note, the comment the clinician attached to the order, the preparation the site requires, the condition that forces a prior exam.
That is where Surface does the work: it turns the text into a bookable service, carries over the conditions that change the preparation, and flags for human review whatever stays ambiguous. The criteria are published in how the agent decides, and how the result is measured in how we measure.
What does running on Epic not change?
The scheduling rules stay the institution's own and Surface executes them as written. The message goes out under the institution's brand and the data stays theirs, per the detail in your brand, your data.