数据分析

Fhir Upstream Proxy

试用

Connect to real FHIR servers through the MCP guardrail proxy. Use when: (1) Connecting to HAPI FHIR, SMART Health IT, or Epic sandbox servers, (2) Proxying A...

它能做什么

Connect to real FHIR servers through the MCP guardrail proxy. Use when: (1) Connecting to HAPI FHIR, SMART Health IT, or Epic sandbox servers, (2) Proxying AI agent requests to production EHR systems with guardrails, (3) Ensuring upstream server URLs never leak to clients, (4) Understanding how redaction, audit, and step-up auth apply to upstream data.

技能文档

FHIR Upstream Server Proxy

Connect to real FHIR servers while keeping the full MCP guardrail stack active.

Client -> MCP Server -> Flask (guardrails) -> Upstream FHIR Server
                             |
               redaction, audit, step-up,
               tenant isolation, disclaimers,
               URL rewriting

When to Use This Skill

  • You need to connect an AI agent to a real FHIR server (HAPI, SMART, Epic)
  • You want automatic PHI redaction on upstream server responses
  • You need audit trails for agent access to production clinical data
  • You want URL rewriting so upstream server details never leak to clients

Configuration

Set the FHIR_UPSTREAM_URL environment variable to enable proxy mode:

# HAPI FHIR R4 (open, no auth)
FHIR_UPSTREAM_URL=https://hapi.fhir.org/baseR4 python main.py

# SMART Health IT (open, no auth)
FHIR_UPSTREAM_URL=https://r4.smarthealthit.org python main.py

# HAPI FHIR R5 (open, no auth)
FHIR_UPSTREAM_URL=https://hapi.fhir.org/baseR5 python main.py

# Local HAPI instance
FHIR_UPSTREAM_URL=http://localhost:8080/fhir python main.py

# Docker Compose with upstream
FHIR_UPSTREAM_URL=https://hapi.fhir.org/baseR4 docker-compose up -d --build

Environment Variables

VariableDefaultDescription
FHIR_UPSTREAM_URL(empty)Upstream FHIR server base URL. Enables proxy when set.
FHIR_UPSTREAM_TIMEOUT15HTTP timeout for upstream requests (seconds)
FHIR_LOCAL_BASE_URL(empty)Local server URL for URL rewriting in responses

What the Proxy Does

Reads

Fetched from upstream, then redacted + audited + disclaimers added. The agent never sees unredacted upstream data.

Searches

All query parameters forwarded to upstream. Results redacted per entry. Upstream's full search capabilities are available (chaining, _include, etc.).

Writes

Validated locally first (structural checks), then forwarded to upstream with step-up auth verification. Both local and upstream audit records created.

URL Rewriting

All upstream server URLs in responses are replaced with local proxy URLs. The agent and client never see the upstream server's hostname or paths.

Health Check

/r6/fhir/health reports upstream connection status including FHIR version and server software name.

Graceful Fallback

Network errors return proper FHIR OperationOutcome responses, not stack traces.

What the Proxy Does NOT Do

  • No caching — every request hits the upstream server
  • No SMART-on-FHIR auth forwarding — uses upstream's native auth model
  • No cross-version translation — R4 responses stay R4
  • No tenant isolation on upstream — enforced locally only
  • No response transformation — upstream resources pass through as-is (after redaction)

Tested Upstream Servers

ServerURLAuthStatus
HAPI FHIR R4https://hapi.fhir.org/baseR4NoneTested
SMART Health IThttps://r4.smarthealthit.orgNoneTested
HAPI FHIR R5https://hapi.fhir.org/baseR5NoneTested
Local HAPIhttp://localhost:8080/fhirNoneTested
Epic Sandboxhttps://open.epic.com/Interface/FHIROAuth 2.0Limited

Proxy Implementation

The proxy uses httpx for HTTP client operations with:

  • Configurable timeout (default 15 seconds)
  • Automatic redirect following
  • application/fhir+json accept header
  • User-Agent identification: HealthClaw-Guardrails/1.0.0

URL rewriting is recursive — it traverses the entire response JSON tree and replaces all occurrences of the upstream URL with the local proxy URL.

相关技能

HealthClaw Guardrails (healthclaw.io) — FHIR agent guardrails for clinical data access via MCP. Supports FHIR R4 US Core v9 (stable) and FHIR R6 ballot3 (exp...

Use this skill whenever connecting a patient's real health records from EHR systems (Epic, Cerner, Athena) or the TEFCA national network into HealthClaw Guar...

Survey ALL connected health data sources at once. Use when the patient asks: (1) "what's connected" or "what services are linked", (2) "check all my services...

Read MyAtriumHealth (Atrium Health's Epic MyChart patient portal) — test results, medications, allergies, immunizations, health issues, visits, goals — from a shell with the fpx CLI (@fetchproxy/cli), by relaying requests through your signed-in Chrome tab. Use when you want your MyChart data in a script or one-shot without running the myatriumhealth-mcp server.

1 次安装

Unlock the full potential of your AI agent with Model Context Protocol (MCP) integration. This capability connects your agent to a vast ecosystem of external tools, APIs, and data sources through multiple MCP servers—including legal databases, weather services, database connectors, and more. By cent

Generate a patient-controlled SMART Health Link (SHL) QR code for sharing health records with a clinic or provider. Use when: (1) A patient asks to share the...

1 次安装