Skip to content

Health records from MyChart and any SMART on FHIR portal; hqtui dashboard (v0.4.0) - #6

Merged
ralyodio merged 2 commits into
masterfrom
provider-connect
Oct 6, 2026
Merged

ralyodio merged 2 commits into
masterfrom
provider-connect

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

What

Connect a provider and import everything. A patient picks their provider at /portal/records (or tleehealth connect "<name>"): every Epic/MyChart organization from open.epic.com's directory, any SMART on FHIR server by address, or a demo sandbox. They sign in on the provider's own site (SMART standalone patient launch with PKCE), and sync copies everything the patient API returns:

  • personal information: name, DOB, sex, phones, emails, addresses, MRN/SSN/other identifiers, contacts
  • visits, after-visit summaries, clinical notes, labs, imaging, reports, medications (references resolved to drug names), conditions, allergies, immunizations, procedures, vitals, care plans, insurance
  • every attached file: AVS PDFs, scanned notes, images, Binary resources

Download all of it: one zip (patient.txt, records.md, labs.csv, files/<category>/…, raw FHIR by category, fhir-bundle.json) or one FHIR Bundle with files inlined. Share a connection with a practice the patient belongs to; it then shows on the chart (audit-logged), and clinicians can download it.

hqtui dashboard: tleehealth dashboard (alias tui) has four tabs. Today shows appointments with AI call state; Needs shows flagged calls, refills, labs to release and summaries to sign; Caseload; and Records shows providers, personal info and categories, with Enter to drill in, s to sync and e to export.

Every surface: API (/api/v1/records*, listed in llms.txt), web portal + chart card, CLI (providers connect records sync share export file disconnect), MCP (7 new tools), TUI.

Safety

  • Tokens are sealed with AES-256-GCM (HEALTH_TOKEN_KEY, now in vault tleehealth--prod). Production refuses to run without it.
  • A user-entered FHIR URL must be https and resolve to public addresses (SSRF guard). Bearer tokens only go to the provider's own origin; a cross-origin attachment is skipped, and a redirect is followed once without the token.
  • Records belong to the account. A practice sees nothing until the patient shares. Disconnecting deletes everything imported.

Verified

  • bun test: 98 pass on a fresh Postgres. New: records.test.js runs a fake Epic-like server (PKCE check, paging, Observation refusing a search without a category, Binary PDF + FHIR-Binary image, inline files, a cross-origin file that must not be fetched, medication by reference) through connect → callback → sync → read → share → export → disconnect. tui.test.js renders every dashboard tab off-screen.
  • Live against launch.smarthealthit.org through the real code: 646 records, full PII, a 1.2 MB zip that passes unzip -t. Clicked through in Chromium (connect → provider → back → import → labs → share → the practice's chart).

Not done / needs a human

  • MyChart in production needs our Epic app registration (fhir.epic.com, patient-facing USCDI app, redirect https://tleehealth.com/connect/callback) and then EPIC_CLIENT_ID in the vault. Until then, Epic orgs show "coming soon" and the demo sandbox works. Oracle Health would take CERNER_CLIENT_ID.
  • Known pre-existing issue: test/calls.test.js fails when re-run against a reused test database (old queued calls take the dial batch). CI uses a fresh database, so CI is unaffected.

🤖 Generated with Claude Code

ralyodio and others added 2 commits October 6, 2026 19:42
…oard

A patient connects their provider (every Epic/MyChart organization from
open.epic.com, any SMART on FHIR server by address, or a demo sandbox) with
the SMART standalone patient launch: PKCE, tokens sealed with AES-256-GCM.
Sync copies everything the patient API returns: personal information and
identifiers, visits, after-visit summaries, notes, labs, imaging, meds,
conditions, allergies, immunizations, procedures, care plans, coverage, and
every attached file (PDFs, images, Binary resources). Download it all as a
zip (patient.txt, records.md, labs.csv, files/, raw FHIR) or one FHIR Bundle;
share a connection with a practice and it appears on the chart.

Every surface: /api/v1/records*, /portal/records, chart card, CLI
(providers/connect/records/sync/share/export/file/disconnect), MCP (7 tools),
and `tleehealth dashboard`: an hqtui screen with Today, Needs, Caseload and
Records tabs. User-entered FHIR URLs must be public https (SSRF guard);
tokens are only sent to the provider's own origin.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…esolves hqtui

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ralyodio
ralyodio merged commit 3346285 into master Oct 6, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant