API

The outside record, as an API.

One REST API over network participation, provider directories, patient matching and document parsing. Your customers' records move under their own authority; you get structured data back.

What it does

Load your patients. Get their outside records back, parsed.

Vivlio retrieves records from providers, hospitals and health systems, de-duplicates them and parses them into clinical domains. The API is that capability, addressable.

  1. Create a client for each of your customers

    A partner key provisions clients and issues their scoped API keys, so onboarding a customer is an API call rather than a support ticket. Data is isolated per client and no key reaches across that boundary.

    POST /partners/clients

  2. Send the roster, one patient or a hundred

    Batch upsert matches on the external identifier you already use, then on demographics, before creating anything, so re-sending your roster does not duplicate it.

    POST /patients/batch

  3. Let retrieval follow the calendar

    Creating an appointment can trigger a query for that patient automatically, inside a configurable lookahead window. Mirror your own scheduling and the records arrive before the visit.

    POST /appointments

  4. Read the record by domain

    Fourteen parsed domains, read-only, every record carrying the ID of the source document it came from. The files themselves are there too, when the document is what matters.

    GET /patients/{patientId}/records/{recordType}

What comes back

Fourteen parsed domains, read-only.

Not a PDF and not a bundle to parse yourself. Each domain is queryable, paginated and date-filterable, and every record names the document it was parsed from.

  • Medicationsmedications
  • Allergiesallergies
  • Problem listproblemList
  • Encountersencounters
  • Notesnotes
  • Vitalsvitals
  • Labs and diagnosticslabs
  • Procedures and surgeriesprocedures
  • Immunizationsimmunizations
  • Care teamcareTeam
  • Plan of careplanOfCare
  • Social historysocialHistory
  • Family historyfamilyHistory
  • General historyhistoryGeneral

Two tokens

Which token you hold decides what you can reach.

Authentication is an OAuth 2.0 client-credentials exchange. Tokens are signed JWTs with a sixty-minute life, and every call is HTTPS.

POST /oauth/requestToken

Partner

Manages your customers

Your own clients and their API keys, and deliberately nothing clinical: a partner cannot read patients or records directly.

/partners/*

Client

Reads one customer's records

Carries that customer's NPI and declared purpose of use, and reads patients, appointments, records and files, scoped to that one client's data.

/patients/* /appointments/*

Whose authority

Your customer's, not yours and not ours.

A client token carries an NPI and a declared purpose of use. Records move for treatment, under that provider's authority, with a signed BAA behind it.

  • Production access is gated, by design

    Real records require an NPI, a declared purpose of use, and a signed BAA. Nobody swipes a card onto live PHI.

  • HITRUST certification underway

    Vivlio's HITRUST assessment is underway and on track to complete in November 2026: the certification healthcare security teams ask for by name.

  • Provenance travels with the record

    Each line carries the source it came from and when it arrived, because a clinical decision needs to know who said it.

  • Built to WCAG 2.1 AA

    Contrast, focus order and heading structure are requirements here, not a remediation project after procurement asks.

If your customers are treating providers, this works the way it is built. If the use is case management eligibility, payer or utilization review, or disability and legal records retrieval, that is a different legal basis and a conversation to have before anything is built. The page for technology partners covers the commercial shape.

The reference

Every endpoint, in the reference.

Authentication, the scope model, every endpoint, the field reference for all fourteen domains, pagination, rate limits, errors and the changelog.

Talk to us

Talk to us about an integration

The reference covers the endpoints. The call covers what it does not: the sandbox, the scopes your integration needs, what your customers would sign, and what it costs.

  1. Send your detailsTwo minutes. Your organization, name, email and phone, and the time records cost you; the rest is optional and helps us reply with something specific.
  2. Pick a timeThirty minutes, live, over synthetic records in the shape your team works in. No slides, and no discovery call before the demo.

Who this is for, and who it is not

  • Coverage comes firstVivlio retrieves from providers, hospitals and health systems it can reach through national exchange networks and direct connections. Name the facilities your patients come from on the form and we check coverage before anyone spends thirty minutes on a demo.
  • You can say what the chasing costsThe form asks how many hours a week your team loses to chasing records. If nobody can put a number near it, the case for Vivlio is not there yet, and we would rather say so than sell you a demo.
  • Patients and files at volumeThis is built for intake that runs every day. For one record, once, your patient can request it from the provider directly, and that will be faster than going through us.
  • Treatment, with the paperwork doneProduction access needs an NPI, a declared purpose of use and a signed BAA. Nobody swipes a card onto live PHI.

If none of those describe you, say so in the last field and we will come back in writing instead of booking a call.

Or call sales directly at 404-777-5772

Step 1 of 2

Send us your details

Three to five is plenty. We check coverage for them before the call, so nobody finds out afterwards.