App Orchard vs Epic Showroom: what changed and what still sits on you
Epic App Orchard was the earlier name for Epic's third-party app marketplace program. Vendors should treat Epic Showroom as the current catalog listing surface and Vendor Services as the enrollment path. A Showroom listing can make an app requestable by Epic-using hospitals; it does not host the app, sign a hospital BAA, complete each site's security review, or equal go-live. Epic is federated — there is no single central production endpoint — so after a live customer a listing is often still needed for multi-hospital distribution, while HIPAA hosting, BAA, SOC 2 Type II evidence, per-hospital questionnaires, and quarterly Epic maintenance still sit on the vendor unless a compliant SMART on FHIR runtime covers them.
If your decks, RFPs, or partner emails still say "App Orchard," update the language. The rename is not cosmetic only: the old one-stop label split into a catalog (Showroom) and an enrollment path (Vendor Services). What did not change is the residual stack that sits on you after a listing exists.
Orchard retired: Showroom is the catalog, Vendor Services is enrollment
App Orchard is retired. Epic no longer markets a single "Orchard" program name for third-party apps. In current vendor language:
- Epic Showroom is the public-facing catalog where hospitals can discover and request apps.
- Vendor Services is how vendors enroll, maintain program standing, and work through Epic's vendor-facing process.
Use those names in RFPs, security questionnaires, and partner decks. Saying "we're on App Orchard" dates your materials and confuses buyers who already hear "Showroom" from Epic or peer vendors. For a definitional overview of Showroom itself, see What is the Epic Showroom and the product page at /epic-showroom — this page is about the rename and what still sits on the vendor afterward, not ownership of the Showroom definition.
The practical split matters because catalog and enrollment are not the same job as hosting, contracting, or go-live. Orchard's retirement did not collapse those jobs into the listing.
Connection Hub is not a host, BAA, or security review
Epic's Connection Hub (and related vendor connectivity surfaces) helps hospitals and vendors connect apps into Epic environments. It is a connection and request path — not a substitute for your compliance posture.
Connection Hub does not:
- Host your application or store your PHI on your behalf
- Sign a business associate agreement (BAA) with the hospital for your product
- Complete the hospital's security questionnaire or risk review
- Make your app production-ready at a specific site
Vendors still need a place the app actually runs under HIPAA expectations, a BAA path with each customer (or a runtime that already carries one), and evidence packets hospitals trust — typically including SOC 2 Type II, U.S. residency for production PHI, and TLS 1.2 or higher in flight. Connection Hub gets you into the conversation; it does not finish the compliance stack.
Listing is optional after a live customer — Epic is federated
Epic deployments are federated. There is no single central production endpoint where one listing "turns on" every hospital. Each health system runs its own Epic instance, its own security process, and its own contracting calendar.
That has two consequences vendors often miss:
- You can go live with a customer without a Showroom listing. A hospital that already wants your app can work through Vendor Services / Connection Hub and site-level integration without waiting on catalog discoverability.
- A listing still helps multi-hospital distribution. Once you have a live reference site, Showroom makes the app requestable by other Epic-using organizations that will not hand-walk every vendor relationship. For one-site or tightly sponsored deployments, listing can wait; for a go-to-market that spans many hospitals, listing is usually still on the path.
Optional after a live customer does not mean optional forever if you want inbound hospital demand. It means listing is a distribution surface, not the only gate to first production use.
Listing is not go-live — what still sits on you
A Showroom listing answers: can hospitals find and request this app? It does not answer: is this app live, contracted, and cleared at Hospital X?
What still sits on the vendor (or on a runtime you buy) after rename and listing:
| Residual item | Why it still sits on you |
|---|---|
| HIPAA-capable host | The app needs somewhere to run with PHI controls. Catalog placement is not hosting. |
| BAA | Each hospital (or your runtime provider) needs a business associate agreement covering your processing. |
| SOC 2 Type II packet | Security reviews ask for independent evidence; a listing badge is not a Type II report. |
| Per-hospital questionnaire | Sites reuse themes but still send their own forms. Expect repetition across customers. |
| Quarterly Epic maintenance | Program standing, version posture, and Epic-side changes continue after you are listed. |
Timeline ranges that are honest to cite (not Epic SLAs): intake commonly lands in weeks 1–3; Epic review commonly lands in weeks 2–8. Those are process ranges, not promises that a listing appears on a fixed calendar day. If you package submission ops tightly, "Week 2: Showroom submission filed" can describe your packet speed — not Epic's listing decision. Outer bound for first hospital live remains Epic's queue plus that hospital's BAA and security review. See also Epic Showroom vs runtime and How to get your app into Epic.
Comparison: Orchard, Showroom, Vendor Services, and a compliant runtime
| Orchard (legacy) | Showroom | Vendor Services | Compliant runtime (SoFaaS) | |
|---|---|---|---|---|
| What it was / is | Former marketplace program name | Current catalog listing surface | Enrollment and vendor program path | Host + compliance package your listing can point at |
| Status | Retired — do not use in new materials | Current name for discoverability | Current path for vendor standing | Separate buy: not a listing substitute |
| Hosts your app? | No | No | No | Yes (HIPAA host) |
| Hospital BAA? | No | No | No | Yes (via provider BAA path) |
| SOC 2 Type II evidence? | No | No | No | Packet you can reuse across sites |
| Security review done? | No | No | No | Posture hospitals can evaluate; site forms still happen |
| Equals go-live? | No | No | No | Day-1 SMART launch possible; site BAA still outer-bounds live |
| Primary job | Historical label | Make app requestable | Get / keep you in Epic's vendor process | Run the app under HIPAA, BAA, U.S. residency, TLS 1.2+ |
Read the table left to right as rename clarity, then rightmost column as the residual economics: listing and enrollment never absorbed hosting and evidence.
FAQ
Is App Orchard still the program?
No. Treat App Orchard as a retired name. Use Epic Showroom for the catalog and Vendor Services for enrollment. Keep Orchard only when quoting historical docs or explaining a rename to stakeholders who still search that phrase.
What is the difference between Showroom and Vendor Services?
Showroom is where hospitals discover and request apps. Vendor Services is how vendors enroll and maintain standing with Epic. You need the enrollment path to operate as a vendor; you use the catalog when you want broader discoverability. Neither one hosts your product or completes a hospital's security review.
What is Connection Hub — and what isn't it?
Connection Hub is a connectivity / request surface between hospitals and vendor apps inside Epic's ecosystem. It is not your HIPAA host, not your BAA, and not a completed security review. Treat it as how connection work gets routed — not as compliance completion.
Does a Showroom listing equal go-live?
No. Listing means hospitals can find and request the app. Go-live at a given hospital still requires site-level connection work, security review, and a BAA (or equivalent coverage through a runtime provider). Epic is federated; each site is its own production reality.
Do I still need a runtime after I'm listed?
Yes, if the app processes PHI or launches into Epic as a SMART on FHIR experience. A listing points at something that must actually run. Without a compliant runtime you still own HIPAA hosting, BAA logistics, SOC 2 Type II evidence packaging, and the questionnaire grind for every new hospital. For how listing and runtime differ as buys, see Epic Showroom vs runtime.
Non-goals (what this page — and a runtime buy — are not)
To keep the category clean:
- Not a Redox replacement. Compose with Redox (and similarly 1upHealth) for non-Epic data flows; a SMART on FHIR runtime does not displace those pipes.
- Not a public marketing-site host. Showroom and your .com are different jobs; do not conflate catalog listing with public website hosting.
- Not S2S FHIR as the product thesis. Server-to-server FHIR may appear in some architectures; this page is about Orchard→Showroom rename and residual vendor obligations, not S2S product claims.
- Not vectorcare.com logistics. Operational logistics for VectorCare's own .com properties are out of scope here; this Learn page is about Epic program rename and what still sits on vendors shipping clinician apps.
Next steps and related reading
- What is the Epic Showroom — definitional Showroom overview (link out; do not redefine here)
- Epic Showroom vs runtime — listing buy vs host/compliance buy
- Epic Showroom — product surface for Showroom-oriented buyers
- How to get your app into Epic — path narrative without treating listing as go-live
- Security — SOC 2 Type II, HIPAA + BAA, U.S. residency, TLS 1.2+
- Compare — package vs queue framing for first-hospital economics
- SoFaaS — compliant SMART on FHIR runtime category for vendors who need the residual stack covered
- Talk to us — if an Epic deal is stuck on compliance rather than on the rename
A Showroom listing is a catalog fact. Orchard's retirement did not move hosting, BAA, SOC 2 Type II evidence, per-hospital questionnaires, or quarterly Epic maintenance off your plate. If you need that residual stack covered as a runtime rather than built in-house, SoFaaS™ is that category — it composes with Redox or 1upHealth for non-Epic data flows and is not a listing substitute. Start at /sofaas or /talk-to-us.
Have a deal stuck on Epic?
If an Epic deal is stuck on compliance rather than on the rename, start here.
Talk to us