API
The outside record, as an API.
One REST API over network participation, provider directories, patient matching and document parsing. Your customers' records move under their own authority; you get structured data back.
What it does
Load your patients. Get their outside records back, parsed.
Vivlio retrieves records from providers, hospitals and health systems, de-duplicates them and parses them into clinical domains. The API is that capability, addressable.
Create a client for each of your customers
A partner key provisions clients and issues their scoped API keys, so onboarding a customer is an API call rather than a support ticket. Data is isolated per client and no key reaches across that boundary.
POST /partners/clientsSend the roster, one patient or a hundred
Batch upsert matches on the external identifier you already use, then on demographics, before creating anything, so re-sending your roster does not duplicate it.
POST /patients/batchLet retrieval follow the calendar
Creating an appointment can trigger a query for that patient automatically, inside a configurable lookahead window. Mirror your own scheduling and the records arrive before the visit.
POST /appointmentsRead the record by domain
Fourteen parsed domains, read-only, every record carrying the ID of the source document it came from. The files themselves are there too, when the document is what matters.
GET /patients/{patientId}/records/{recordType}
What comes back
Fourteen parsed domains, read-only.
Not a PDF and not a bundle to parse yourself. Each domain is queryable, paginated and date-filterable, and every record names the document it was parsed from.
Illustration · synthetic
- Medications
medications - Allergies
allergies - Problem list
problemList - Encounters
encounters - Notes
notes - Vitals
vitals - Labs and diagnostics
labs - Procedures and surgeries
procedures - Immunizations
immunizations - Care team
careTeam - Plan of care
planOfCare - Social history
socialHistory - Family history
familyHistory - General history
historyGeneral
Two tokens
Which token you hold decides what you can reach.
Authentication is an OAuth 2.0 client-credentials exchange. Tokens are signed JWTs with a sixty-minute life, and every call is HTTPS.
POST /oauth/requestToken
Partner
Manages your customers
Your own clients and their API keys, and deliberately nothing clinical: a partner cannot read patients or records directly.
/partners/*
Client
Reads one customer's records
Carries that customer's NPI and declared purpose of use, and reads patients, appointments, records and files, scoped to that one client's data.
/patients/* /appointments/*
Whose authority
Your customer's, not yours and not ours.
A client token carries an NPI and a declared purpose of use. Records move for treatment, under that provider's authority, with a signed BAA behind it.
Production access is gated, by design
Real records require an NPI, a declared purpose of use, and a signed BAA. Nobody swipes a card onto live PHI.
HITRUST certification underway
Vivlio's HITRUST assessment is underway and on track to complete in November 2026: the certification healthcare security teams ask for by name.
Provenance travels with the record
Each line carries the source it came from and when it arrived, because a clinical decision needs to know who said it.
Built to WCAG 2.1 AA
Contrast, focus order and heading structure are requirements here, not a remediation project after procurement asks.
If your customers are treating providers, this works the way it is built. If the use is case management eligibility, payer or utilization review, or disability and legal records retrieval, that is a different legal basis and a conversation to have before anything is built. The page for technology partners covers the commercial shape.
The reference
Every endpoint, in the reference.
Authentication, the scope model, every endpoint, the field reference for all fourteen domains, pagination, rate limits, errors and the changelog.
Talk to us
Talk to us about an integration
The reference covers the endpoints. The call covers what it does not: the sandbox, the scopes your integration needs, what your customers would sign, and what it costs.
- Send your detailsTwo minutes. Your organization, name, email and phone, and the time records cost you; the rest is optional and helps us reply with something specific.
- Pick a timeThirty minutes, live, over synthetic records in the shape your team works in. No slides, and no discovery call before the demo.
Who this is for, and who it is not
- Coverage comes firstVivlio retrieves from providers, hospitals and health systems it can reach through national exchange networks and direct connections. Name the facilities your patients come from on the form and we check coverage before anyone spends thirty minutes on a demo.
- You can say what the chasing costsThe form asks how many hours a week your team loses to chasing records. If nobody can put a number near it, the case for Vivlio is not there yet, and we would rather say so than sell you a demo.
- Patients and files at volumeThis is built for intake that runs every day. For one record, once, your patient can request it from the provider directly, and that will be faster than going through us.
- Treatment, with the paperwork doneProduction access needs an NPI, a declared purpose of use and a signed BAA. Nobody swipes a card onto live PHI.
If none of those describe you, say so in the last field and we will come back in writing instead of booking a call.
Or call sales directly at 404-777-5772
Step 1 of 2
Send us your details
Step 2 of 2
Book a 1:1 call
Thanks. Pick a time below and the invitation comes straight to your inbox.
Step 2 of 2
We will come back in writing
Thanks - that is a useful answer. Before either of us spends thirty minutes, we will come back by email with the two or three questions that size what record chasing is actually costing your team, and what we can reach for the facilities you named. If the numbers are there, we will send a time then.
If you would rather just talk, the sales line below reaches the same people.
