Epic Healthcare MCP Server

Epic Healthcare MCP Server

Enables AI assistants to securely access Epic Healthcare Systems patient data through FHIR R4 API integration. Provides tools for searching patients, retrieving clinical summaries, vital signs, medications, and generating healthcare reports with HIPAA-compliant OAuth 2.0 authentication.

Category
访问服务器

README

Epic Healthcare MCP Server

A production-level Model Context Protocol (MCP) server for Epic Healthcare Systems, designed to securely integrate with Epic's FHIR R4 API and provide AI assistants with access to patient healthcare data.

🏥 Features

  • FHIR R4 Compliance: Full integration with Epic's FHIR R4 API
  • OAuth 2.0 Authentication: Secure authentication using Epic's OAuth 2.0 with JWT client assertions
  • MCP Protocol Support: Standard Model Context Protocol implementation for AI assistant integration
  • Production Ready: Comprehensive logging, error handling, and rate limiting
  • HIPAA Considerations: Designed with healthcare data security and privacy in mind
  • Scalable Architecture: Hybrid Node.js/TypeScript implementation

Available MCP Resources

  • Patient Demographics: Access to patient basic information and identifiers
  • Clinical Observations: Vital signs, lab results, and clinical measurements
  • Medications: Current and historical medication lists
  • Allergies: Patient allergy and intolerance information
  • Encounters: Healthcare visits and encounter data
  • FHIR Metadata: Server capabilities and resource definitions

Available MCP Tools

  • search_patients: Search for patients using various criteria
  • get_patient_summary: Comprehensive patient data aggregation
  • get_vital_signs: Recent vital signs and observations
  • search_observations: Query specific clinical observations

Available MCP Prompts

  • patient_summary: Generate clinical summary reports
  • clinical_assessment: Create clinical assessments from patient data

🚀 Quick Start

Prerequisites

  • Node.js 18+
  • Epic Healthcare System access
  • Epic App registration with FHIR API access
  • Valid JWT private key for Epic authentication

Installation

  1. Clone and install dependencies:
# Install MCP Server dependencies
cd mcp-server
npm install

# Install MCP Client dependencies (for testing)
cd ../mcp-client
npm install
  1. Configure environment variables:
# Copy and configure environment file
cp .env.example .env

Required environment variables:

# Epic FHIR Configuration
EPIC_CLIENT_ID=your-epic-client-id
EPIC_CLIENT_SECRET=your-epic-client-secret
EPIC_FHIR_BASE_URL=https://fhir.epic.com/interconnect-fhir-oauth/api/FHIR/R4

# JWT Authentication
JWT_PRIVATE_KEY=your-jwt-private-key
JWT_KEY_ID=your-jwt-key-id

# Server Configuration
MCP_SERVER_PORT=3000
NODE_ENV=production
LOG_LEVEL=info
  1. Build and run the server:
cd mcp-server
npm run build
npm start

Testing with MCP Client

Run the included test client to verify functionality:

cd mcp-client
npm run build
npm start

📖 Usage

Integrating with AI Assistants

The Epic Healthcare MCP Server can be integrated with AI assistants that support the Model Context Protocol:

  1. Configure the AI assistant to connect to the MCP server
  2. Use MCP resources to access patient data contextually
  3. Execute MCP tools for specific healthcare queries
  4. Leverage MCP prompts for clinical summaries and assessments

Example MCP Tool Usage

{
  "name": "search_patients",
  "arguments": {
    "name": "John Doe",
    "birthdate": "1990-01-01",
    "count": 10
  }
}
{
  "name": "get_patient_summary",
  "arguments": {
    "patientId": "patient-12345"
  }
}

🔧 Configuration

Epic FHIR Setup

  1. Register your application with Epic's developer program

  2. Configure FHIR scopes for required resource access:

    • system/Patient.read
    • system/Observation.read
    • system/Encounter.read
    • system/Medication.read
    • system/AllergyIntolerance.read
  3. Generate JWT key pair for client authentication

  4. Configure redirect URLs and authentication endpoints

Security Configuration

  • Rate Limiting: Configurable request limits to prevent API abuse
  • JWT Authentication: Secure client assertion-based authentication
  • HTTPS Only: All API communications use encrypted connections
  • Audit Logging: Comprehensive logging for security monitoring

🏗️ Architecture

Epic Healthcare MCP Server
├── mcp-server/              # Main MCP server implementation
│   ├── src/
│   │   ├── auth/            # Epic OAuth 2.0 authentication
│   │   ├── clients/         # Epic FHIR API client
│   │   ├── config/          # Environment and configuration
│   │   ├── mcp/             # MCP protocol implementation
│   │   └── utils/           # Logging and utilities
│   └── dist/                # Built JavaScript files
├── mcp-client/              # Test client for development
└── logs/                    # Application logs

Key Components

  • EpicOAuthClient: Handles Epic's OAuth 2.0 JWT authentication
  • EpicFHIRClient: Axios-based client for FHIR API interactions
  • EpicMCPServer: Core MCP protocol server implementation
  • Environment Configuration: Zod-based configuration validation
  • Winston Logging: Structured logging for production monitoring

🧪 Development

Running in Development Mode

cd mcp-server
npm run dev

Building the Project

npm run build

Type Checking

npm run type-check

Linting

npm run lint

📋 FHIR Resource Support

Resource Type Read Search Supported Operations
Patient Demographics, identifiers
Observation Vital signs, lab results
Encounter Visits, appointments
MedicationRequest Prescriptions, medications
AllergyIntolerance Allergies, intolerances
Condition Diagnoses, problems
Procedure Medical procedures

🔒 Security & Compliance

HIPAA Considerations

  • Data Minimization: Only request necessary patient data
  • Audit Trails: Comprehensive logging of all data access
  • Encryption: All data transmission uses TLS encryption
  • Access Controls: OAuth 2.0 scoped access to Epic resources

Best Practices

  • Store JWT private keys securely
  • Rotate authentication tokens regularly
  • Monitor API usage and access patterns
  • Implement proper error handling to prevent data leakage
  • Regular security audits and penetration testing

📚 API Documentation

Epic FHIR API Documentation

MCP Protocol Documentation

🐛 Troubleshooting

Common Issues

Authentication Failures

  • Verify Epic client ID and private key configuration
  • Check JWT key ID matches Epic app registration
  • Ensure proper OAuth scopes are configured

FHIR API Errors

  • Verify Epic FHIR base URL is correct
  • Check patient ID format and existence
  • Review Epic API rate limits and quotas

MCP Connection Issues

  • Verify MCP client configuration
  • Check server logs for connection errors
  • Ensure proper transport configuration

Logging

Logs are written to:

  • logs/combined.log - All application logs
  • logs/error.log - Error-level logs only
  • Console output in development mode

📄 License

MIT License - see LICENSE file for details.

🤝 Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Make changes with proper tests
  4. Submit a pull request

📞 Support

For Epic-specific issues:

For MCP protocol issues:

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选