DEVELOPERS · EHR INTEGRATION

How Interactly connects to your EHR.

Public documentation reference for Interactly's EHR integration app registrations — including Epic, Cerner/Oracle Health, athenahealth, NextGen, and other SMART on FHIR-compatible systems. Prepared for health system IT and security reviewers.

STANDARD
SMART on FHIR
AUTH
Backend Services
CERTIFICATION
SOC 2 Type II
EHR SUPPORT
Epic
Oracle
athena
NextGen

WHAT INTERACTLY DOES

An AI scheduling agent, disclosed to every patient.

Interactly is an AI voice and chat agent that automates appointment scheduling workflows for healthcare organizations. It connects to a health system's electronic health record (EHR) to check provider and location availability, and to book, reschedule, or cancel patient appointments on behalf of front-desk and call-center staff.

Interactly is an AI system, not a human agent. Every patient-facing interaction — by phone, SMS, or chat — is disclosed to the patient as automated. Before taking any action that reads or writes patient data, Interactly verifies patient identity using the patient's name, date of birth, and mobile number on file.

DATA ACCESSED, AND WHY

Only the FHIR resources scheduling needs.

No clinical write access is requested. No diagnoses, allergies, medications, or notes. This list reflects Interactly's target production scope set, pending completion of an internal scope audit; exact scope and operation names vary by EHR vendor.

FHIR Resource

Purpose

Patient
Locate the correct patient record before scheduling.
Schedule
Retrieve a provider's or location's available schedule.
Slot
Identify open appointment slots within that schedule.
Appointment
(read/search)
Check a patient's existing appointments.
Appointment
(find/book)
Find valid open times and book an appointment.
Practitioner
Display correct provider name and specialty to the patient.
Location
Display correct clinic or location details to the patient.

AUTHENTICATION MODEL

System-to-system, no end-user login.

Interactly connects as a backend application using the SMART on FHIR Backend Services standard — the same profile supported across Epic, Cerner/Oracle Health, athenahealth, and other major EHR platforms.

01 · GRANT TYPE

OAuth 2.0

client_credentials

Authenticated with a JWT client assertion.

02 · SIGNING

RS384, dedicated RSA key pair.

JWTs signed with an RSA key reserved for EHR integration; no reuse across services.

03 · KEY DISTRIBUTION

Public JWK Set (JWKS) URL.

Rotate keys without re-uploading a static key — the EHR always pulls the current public set.

04 · ENVIRONMENT SEPARATION

Separate key pairs · separate JWKS URLs.

Non-production and production keys are fully isolated. No key material is reused across environments.

DATA HANDLING, RETENTION & SECURITY

Encrypted end-to-end. Aligned to SOC 2 Type II.

01 · RETENTION

Ongoing

Retained for ongoing scheduling.

No fixed retention or automatic purge window is currently enforced on appointment-related EHR data.

Scope

Appointment data

Source

EHR system

02 · ENCRYPTION

End-to-end

Encrypted at rest and in transit.

All data is encrypted at rest and in transit, consistent with Interactly's SOC 2 Type II controls.

At rest

Encrypted

In transit

Encrypted

03 · CERTIFICATION

Verified

SOC 2 Type II certified.

Independent audit of Interactly's security, availability, and confidentiality controls.

Questions on integration, security, or a health-system review?

Reach us directly. For questions about this integration, security review, or technical issues.

EHR / EMR integrations

Multilingual Support

Be Part of the Change

Book a demo to discover the transformative impact interactly can have on your organization.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.