EHR Integration: FHIR, HL7, Epic, Cerner

Connect your platform to Epic, Cerner, and every major EHR without the six-month detour.

Most digital health companies underestimate EHR integration. The FHIR spec exists, but every major EHR vendor implements it differently. Epic's sandbox environment has its own certification process. Cerner's APIs have their own quirks. HL7 v2 messages look standard until you hit the proprietary segments that vary by hospital. Engineering teams without prior EHR experience routinely burn four to six months on integrations that should take eight to twelve weeks.
At RaftLabs, we've built FHIR R4 integrations against Epic, Cerner, Allscripts, Meditech, and Athena. We know the certification workflows, the common data normalization traps, and how to architect a HIPAA-compliant data layer that your legal and compliance teams will accept. We handle the EHR side so your team can focus on the product.
Most EHR integration builds ship in 8 to 24 weeks depending on scope, at a fixed price.

  • FHIR R4 API integration with Epic, Cerner, Allscripts, Meditech, and Athena

  • HL7 v2 message parsing and transformation across ADT, ORU, ORM, and MDM message types

  • Bi-directional data sync covering patient demographics, appointments, lab results, medications, and diagnoses

  • HIPAA-compliant architecture with PHI handling, BAA support, and audit trails built in

Recent outcomes

Voice AI · Research

6× deeper insights

Text-based interviews converted to automated phone calls

AI Automation · Ops

20k+ txns day one

Manual invoice OCR across 40+ gas stations

Loyalty · Retail

1,062 users in 4 weeks

SuperValu & Centra loyalty platform with receipt validation

SaaS · Logistics

2,000+ shipments yr 1

Multi-carrier shipping hub for Indonesian eCommerce

4.9
on Clutch
See our work

The problem

Sound familiar?

  • Spending months on HL7/FHIR integration that should take weeks because your engineering team has no prior EHR experience?

  • Blocked from closing healthcare enterprise deals because you can't demonstrate a live Epic or Cerner integration?

Short answer

RaftLabs builds FHIR R4 and HL7 v2 EHR integrations for digital health companies across the US, UK, Europe, Canada, GCC, South Africa, and Southeast Asia. We connect to Epic, Cerner, Athena, and Meditech with HIPAA-compliant architecture. A single-EHR integration ships in 8 to 16 weeks at a fixed price from $40,000.

Key takeaways

  • A single-EHR FHIR R4 integration ships in 8 to 16 weeks at a fixed price from $40,000.
  • Multi-system integrations covering two or three EHR vendors deliver in 16 to 24 weeks.
  • RaftLabs connects to Epic, Cerner, Allscripts, Meditech, and Athena via FHIR R4 APIs.
  • HL7 v2 message parsing covers ADT, ORU, ORM, and MDM message types with bi-directional sync.
  • Every integration includes HIPAA-compliant architecture with PHI handling, BAA support, and audit trails.
  • Epic App Orchard certification adds 8 to 16 weeks to production readiness independent of development time.

Trusted by

Vodafone logo
Aldi logo
Nike logo
Microsoft logo
Heineken logo
Cisco logo
Calorgas logo
Energia Rewards logo
GE logo
Bank of America logo
T-Mobile logo
Valero logo
Techstars logo
East Ventures logo
TuneClub logo

The Epic integration that was scoped as 'a few weeks of API work.'

A digital health team promised a hospital customer a live Epic integration by the next quarter. Four months in, they are still fighting Epic's sandbox. Cerner returns fields the spec never mentioned. An HL7 v2 feed keeps dropping messages nobody can trace.

The deal that was supposed to close is now waiting on an integration everyone assumed was routine. The FHIR spec was never the hard part. Every vendor implements it differently, and experience is the only thing that closes the gap.

The spec is public. The experience is not.

The real reason EHR integration takes so long

The FHIR spec is public. Epic publishes developer documentation. So why do digital health companies spend six months on integrations that should take two?

Three reasons. First, every EHR vendor implements FHIR differently. The spec is a framework, not a contract. Epic's FHIR implementation supports certain resource types and ignores others. Cerner's API quirks are different from Epic's. Athena has its own conventions. Your team needs EHR-specific experience, not just FHIR spec knowledge.

According to the Office of the National Coordinator for Health IT (ONC), only 30% of US hospitals had achieved full interoperability across their systems as of 2024. For digital health companies integrating with EHRs, this gap means even technically complete integrations frequently hit data quality and routing problems that only surface against production systems.

Second, production access requires certification. Epic's App Orchard review, Cerner's code program, and similar vendor processes take weeks of their own. You can complete the technical integration while waiting for certification approval, but you cannot ship to customers until it clears.

Third, the data is messy. Patient demographics vary in completeness. Lab result units are non-standard. Medication names and codes differ between systems. Building a normalization layer that makes this data usable in your application adds time that most roadmaps do not account for.

RaftLabs has shipped 15+ HIPAA-compliant products since 2015, with FHIR R4 integrations built against Epic, Cerner, Allscripts, Meditech, and Athena, and clients including Vodafone, T-Mobile, Aldi, Nike, Cisco, and Lockheed Martin. Every healthcare engagement is HIPAA-compliant, clients rate us 4.9/5 on Clutch, and the team that scopes your integration is the team that ships it.

This pays off when you have a real EHR to connect to and a deal waiting on it.

Everything on the left should already be true for your product. Even one thing on the right, and a full EHR integration build isn't the right first step yet.

A fit
01

You're a digital health, telehealth, or remote patient monitoring platform that needs to connect to Epic, Cerner, Athena, or Meditech.

02

You're blocked from closing healthcare enterprise deals because you can't demonstrate a live Epic or Cerner integration.

03

Your engineering team has no prior EHR experience, and the roadmap can't absorb a four-to-six-month detour.

Not a fit
  • There's no EHR or clinical system in scope, just a standard application build.
  • You already have in-house FHIR and HL7 v2 expertise and only need extra hands.
  • The data carries no PHI and no HIPAA obligations to design around.

What we build

What we build

  • 01
    FHIR R4 API integration
    Connection to Epic, Cerner PowerChart, Allscripts, Meditech, and Athena via their FHIR R4 endpoints, covering Patient, Encounter, Observation, Condition, MedicationRequest, and Appointment resources. OAuth 2.0 and SMART on FHIR authentication support patient- and clinician-facing access, and a normalization layer maps EHR-specific extensions and coding systems (SNOMED, LOINC, RxNorm, ICD-10) to a consistent internal representation.
  • 02
    HL7 v2 message processing
    Parsing and transformation of HL7 v2 messages from hospital interface engines and legacy EHR systems, handling ADT, ORU, ORM, MDM, and SIU message types over MLLP and TCP. An MLLP listener receives messages with acknowledgment handling and a reliability queue, transforming pipe-delimited HL7 into structured JSON or FHIR-equivalent resources, with error handling for malformed messages and non-standard vendor extensions.
  • 03
    SMART on FHIR app development
    SMART on FHIR applications that launch from within the EHR clinician workflow, receiving the current patient's FHIR ID for immediate querying without a separate search. Launch from Epic Hyperspace, Cerner PowerChart, or any SMART-compatible EHR, with App Orchard submission support: we prepare the technical documentation, complete Epic's review questionnaire, and handle clarification rounds.
  • 04
    Bi-directional data sync
    Two-way data flow between your platform and the EHR: reading patient demographics, appointments, lab results, medications, and diagnoses, and writing structured data back into the EHR record. Write-back covers clinical notes as DocumentReference resources, care plan updates, appointment status changes, and observations, scoped against what each EHR vendor's API permits, with gaps flagged before we build.
  • 05
    HIPAA-compliant data architecture
    PHI handling architecture designed for HIPAA compliance: encryption in transit (TLS 1.2 minimum) and at rest (AES-256), role-based access with minimum-necessary scope, full audit logging of every PHI access, and secure credential management. Data minimization stores only the fields your application needs, and architecture documentation is produced for your compliance team's HIPAA risk assessment and enterprise security reviews.
  • 06
    Patient identity matching and deduplication
    Master Patient Index (MPI) logic that resolves patient identity across multiple EHR systems and data sources: deterministic matching on exact field combinations, probabilistic matching with confidence scoring for partial matches, and a review queue for near-match exceptions. Deduplication handles name variations, address changes, and multiple MRN assignments, presenting one unified patient record with configurable thresholds.

What makes EHR integration complex

Three layers of complexity compound on each other.

Proprietary implementations on top of open standards. FHIR R4 is a standard. But Epic's FHIR endpoints support a specific subset of resources, return vendor-specific extensions, and require Epic-specific authentication flows. What works in Epic's sandbox does not always work in Cerner's. What works in Cerner does not always work in Allscripts. Your team needs EHR-specific experience, not just FHIR knowledge.

Certification adds timeline independent of development. Epic's App Orchard review process runs 8 to 16 weeks from submission to approval. You can complete your technical integration in parallel, but you cannot connect to production Epic systems at a customer site until the review clears. That timeline needs to be on your product roadmap before you promise a launch date to a hospital customer.

Data quality is inconsistent. Patient records in production EHR systems contain incomplete fields, non-standard coding, duplicate entries, and historical data entered in free-text fields rather than structured codes. Building a normalization layer that makes this data reliably usable in your application, and deciding what to do when required fields are missing, adds meaningful development time that spec-reading does not reveal.

Which EHR system do you need to connect to?

Tell us your target EHR, the data types you need to sync, and whether you need read-only or bi-directional. We'll scope the integration and give you a fixed price and timeline.

How it works

From scope to shipped

Every EHR integration follows the same four phases. Scope is locked and price is fixed before development starts.

  1. Week 1
    01

    Discovery and scope

    We map the target EHR systems, the data types you need to access or write, your authentication patterns, and your HIPAA requirements. You leave week 1 with a written scope document and a fixed-price quote. No development starts without your sign-off.

  2. Weeks 2-4
    02

    Sandbox integration and certification prep

    We build against sandbox credentials first. Epic, Cerner, and Athena all provide sandbox environments. If Epic is in scope, we prepare the App Orchard submission documentation in parallel so the review clock starts while we build.

  3. Weeks 4-12
    03

    Production integration, normalization, and QA

    We connect to production EHR endpoints at your first customer site, build the data normalization layer, and run live data validation. QA runs in parallel with every sprint. Bi-weekly demos so you see working software throughout.

  4. Weeks 12+
    04

    Go-live and post-launch support

    Production deployment with monitoring activated on launch day. 8 weeks of post-launch support included. Handoff documentation covers the integration patterns, certification requirements, and normalization decisions so your team can extend the codebase.

How RaftLabs approaches EHR integration

We start with discovery. Before any code is written, we need to understand your target EHR systems, the specific data types you need to access or write, whether patients or clinicians are the API users, and what your compliance requirements are. That conversation typically takes two to three hours and produces a scope document with the exact API endpoints, data flows, and architecture decisions we will make.

From there, we build against the EHR sandbox environment first. Epic, Cerner, and Athena all provide sandbox credentials for development. We build and test against sandbox data before you have access to any patient information. That phase also covers the App Orchard submission documentation if Epic is in scope.

Production integration and normalization come next. We connect to production EHR endpoints at your first customer site, build the data normalization layer for that site's specific EHR configuration, and run live data validation against real (but de-identified in development) patient records.

We deliver working integrations, not architectural documents. Your engineering team inherits a codebase they can extend, test, and operate. We document the integration patterns, the certification requirements for each EHR vendor, and the data normalization decisions so the next engineer who touches the code understands what was built and why.

If you need to connect to Epic, Cerner, or any major EHR system, contact us and tell us which system and what data you need. We will scope it and give you a fixed price before you commit to anything.

Cost and timeline expectations

ScopeTimelineCost range
Single EHR, FHIR R4 read-only (demographics, appointments, labs)8 to 12 weeks$40,000 to $65,000
Single EHR, FHIR R4 bi-directional with write-back12 to 16 weeks$55,000 to $90,000
Multi-system HL7 v2 integration (hospital interface engine)10 to 16 weeks$45,000 to $80,000
Multi-EHR FHIR + HL7 v2 with patient identity matching16 to 24 weeks$80,000 to $150,000

Epic App Orchard certification adds 8 to 16 weeks to production readiness and is not included in development time above. These are fixed-price engagements, we scope before we quote, and the price does not change during delivery unless the scope changes.

Single EHR integration, $40,000-$90,000
A FHIR R4 integration with one system (Epic, Cerner, or Athena) covering patient demographics, appointments, and clinical data, read-only or bi-directional with write-back, in 8 to 16 weeks.
Multi-system integration, $80,000-$150,000
HL7 v2 message parsing from a hospital interface engine plus multi-EHR FHIR integration with patient identity matching, in 16 to 24 weeks.

What it costs

EHR integration, starting at $40,000.

A written scope and a firm quote in week 1. No development starts without your sign-off, and the price does not change during delivery unless the scope changes.

Starts at $40,000

Scoped before we quote. Epic App Orchard certification adds 8 to 16 weeks to production readiness, independent of development time. Most clients start with a single integration, then add others once the first is live.

Most clients start with the highest-priority EHR system, prove the integration in production, then extend to Cerner, Athenahealth, or others once the first is live.

No hourly billing

Once we scope the first integration, that price is locked in writing. No hourly billing, no surprise line items on the final invoice.

One team, start to finish

The team that scopes your EHR integration in week 1 is the team that ships it. No offshore handoff after the contract is signed.

Stay on topic

More on healthcare

Frequently asked questions

HL7 v2 is the older messaging standard. It has been in use since the late 1980s and is still the dominant format for hospital-to-hospital and system-to-system event notifications, admission, discharge, transfer, lab result delivery, order placement. If a hospital needs to push patient admission data or lab results to your platform in real time, they are most likely sending HL7 v2 ADT or ORU messages over MLLP or TCP. FHIR R4 is the modern REST-based API standard. Major EHR vendors now expose FHIR R4 endpoints, and it is the required standard for US ONC interoperability rules under the 21st Century Cures Act. If you need to query patient records, pull appointment data, or write clinical notes back into the EHR via API, FHIR R4 is the right approach. In practice, most healthcare integrations involve both. Your platform might receive real-time HL7 v2 ADT feeds from a hospital's interface engine, while also querying the EHR's FHIR API to pull richer structured data on demand. We scope which protocols apply to your specific use case before we build.

Epic's FHIR API implementation is more complete than most EHR vendors, but their certification and sandbox process adds time. To get production API credentials for an Epic customer, your application has to pass Epic's App Orchard review process. That involves submitting the app for review, demonstrating HIPAA-compliant data handling, and meeting Epic's technical requirements. The timeline from sandbox access to production approval typically runs 8 to 16 weeks, independent of the technical integration work itself. We have experience navigating the Epic App Orchard process. We know what documentation Epic requires, what the common rejection reasons are, and how to structure the integration to pass review without multiple rounds of changes. If your target customers are on Epic, and most large US hospital systems are, the certification timeline needs to be factored into your product roadmap from the start.

Patient identity matching is one of the harder problems in healthcare interoperability. Each EHR system assigns its own internal patient ID. When a patient exists in Epic at hospital A and in Cerner at hospital B, there is no shared universal identifier. Master Patient Index (MPI) matching uses a combination of deterministic and probabilistic matching: exact matches on name, date of birth, gender, and address are deterministic; partial matches on subsets of those fields with confidence scoring are probabilistic. Building a reliable MPI for a multi-system integration requires defining your matching rules, handling edge cases like name changes, address updates, and transcription errors, and deciding how to handle near-matches that could be the same person or two different people. We build the patient deduplication logic that sits between your platform and the EHR systems, so your application works with a clean patient record regardless of how many source systems feed into it.

A FHIR R4 integration with a single EHR system, Epic, Cerner, or Athena, covering patient demographics, appointments, and clinical data reads typically runs $40,000 to $90,000 and delivers in 8 to 16 weeks. If the scope includes HL7 v2 message parsing from a hospital interface engine plus multi-system integration against two or three EHR vendors, expect $80,000 to $150,000 and 16 to 24 weeks. The largest cost drivers are the number of EHR systems in scope, the data types you need to sync (read-only versus bi-directional write-back), and whether you need a custom FHIR server or are querying existing EHR-hosted endpoints. Epic App Orchard certification adds 8 to 16 weeks to production readiness independent of development time. We scope every integration after reviewing your target EHR systems, data flow requirements, and compliance constraints before pricing.

HIPAA compliance is built into how we architect healthcare integrations, not added at the end. PHI (protected health information) handling, audit trails, encryption at rest and in transit, access controls, and BAA (business associate agreement) requirements are scoped during discovery and addressed in the architecture before a line of code is written. We do not sign BAAs as a subcontractor on behalf of your organization, that is between your business and the EHR vendor or covered entity, but we design the technical architecture to support your compliance obligations and document the data flows that your compliance team needs for their assessment. If your legal team needs documentation of how PHI moves through the integration layer, we produce it.

Most of our EHR integration clients are digital health startups, telehealth platforms, remote patient monitoring companies, and healthcare SaaS vendors that need to connect their product to a hospital or clinic's EHR system. We work with companies at Series A through Series C as well as established healthcare software vendors adding new integrations. We have shipped HIPAA-compliant integrations for US-based clients targeting Epic-heavy hospital networks and for UK-based clients connecting to NHS-adjacent systems. If your product is in healthcare and you need data from Epic, Cerner, Athena, or a legacy HL7 v2 interface, we have relevant experience.

Work with us

Tell us what you need. We'll tell you what it would take.

We scope EHR Integration Services in 30 minutes. You walk away with a clear cost, timeline, and approach. No commitment required.

  • Scope and cost agreed before work starts. No surprises. No obligation.
  • Working prototype within 3 weeks of kickoff.
  • Pay by milestone. You see progress before each invoice.
  • 60-day post-launch warranty. Bug fixes, UI tweaks, and deployment support. No retainer.
  • All conversations are NDA-protected.