Epic Showroom vs a SMART on FHIR runtime
Which tool for which job
| Job | What it is | What it is not | When you need it |
|---|---|---|---|
| Epic Showroom (listing / distribution) | Epic's vendor marketplace. Hospitals discover, evaluate, and request third-party apps for deployment in their Epic instance. Formerly App Orchard. | Not a runtime, host, BAA, SOC 2 program, or integration engine. A listing does not make the app launch in a hospital's Epic. | Whenever a third-party app will be deployed across Epic-using hospitals. Internal health-system apps registered only inside one Epic instance can skip Showroom; everyone else cannot. |
| Redox or similar (data translation / integration) | An integration platform that translates and moves clinical data between systems — HL7 v2, FHIR, non-Epic sources, payers, devices. | Not a SMART on FHIR launch runtime, not Epic Showroom, and not a substitute for HIPAA hosting or hospital security review of an in-EHR app. | When you must exchange data with systems outside the Epic SMART launch path — other EHRs, ADT feeds, labs, payers, device clouds. Often used alongside a runtime, not instead of one. |
| SoFaaS™ (compliant SMART on FHIR runtime) | A managed runtime your app launches on inside Epic: SMART App Launch and OAuth, FHIR mappings, HIPAA hosting and BAA, SOC 2 Type II evidence, Showroom submission, per-hospital deploy, quarterly Epic maintenance. | Not a listing, not a data-translation bus, not a public site host, not a server-to-server FHIR client, and not VectorCare's patient-logistics product. | When the product must launch inside the clinician workflow via SMART on FHIR and the bottleneck is compliance, distribution, and keeping the integration alive — not scaffolding the app. |
The short version
Epic Showroom is Epic's customer-facing marketplace where hospitals running Epic discover, evaluate, and request third-party products. It is listing and distribution: a Showroom presence makes an app requestable. It does not host the app, sign a Business Associate Agreement, produce a SOC 2 report, pass each hospital's security review, or keep the integration working when Epic ships changes.
A runtime is the layer the listing points at. It owns SMART App Launch and OAuth, FHIR resource handling and write-back, HIPAA hosting and the BAA, audit logging, per-hospital deployment, and quarterly Epic compatibility. SoFaaS™ — SMART on FHIR as a Service — is VectorCare's runtime, the same one we built for our own Epic integration.
An integration platform — Redox, 1upHealth, and similar — translates and moves clinical data between systems. It is the right tool for HL7 v2 feeds, other EHRs, payer and device data. It does not put a clinician-facing app in the chart.
Explicit non-goals of SoFaaS™
Stated plainly, so nobody buys the wrong thing:
- Not a public website host.
- Not a server-to-server FHIR consumer. Headless SMART Backend Services, bulk export, and no-user-launch integrations are a different SMART pattern.
- Not a Redox (or 1upHealth) replacement. Many customers use both.
- Not a patient-logistics / NEMT product. That is vectorcare.com.
- Not Epic Showroom. SoFaaS™ can run the submission; it is not the listing program.
- Not the SMART on FHIR standard.
- Not a substitute for the vendor's own security program.
- Not a claim on vendor IP or hospital data.
- Not a way to skip Epic's vendor program. Showroom still requires enrollment; SoFaaS™ runs that process for you.
- Not a Cerner-first platform. Epic is fully supported; Oracle Health (Cerner) is available on request.
Frequently asked questions
What's the difference between Epic Showroom, a runtime, and an integration platform?
Three different jobs. Epic Showroom is distribution — hospitals find and request the app. A runtime (SoFaaS™) is what actually launches the app inside Epic: SMART App Launch, OAuth, FHIR, HIPAA hosting, BAA, SOC 2 evidence, and per-hospital deploy. An integration platform (Redox and similar) translates data between systems and does not put a clinician-facing app in the chart. You typically need the listing and a runtime; you need Redox only if you also have non-Epic data flows.
Do I still need Redox if I use SoFaaS™?
Only if you still have a data-translation problem. SoFaaS™ is not a Redox replacement. If the app launches in Epic, reads and writes FHIR in that launch context, and does not need HL7 v2 or other-EHR/payer/device pipes, you may not need Redox. If you do, run it alongside SoFaaS™ for those flows.
Is Epic Showroom the same as App Orchard?
Same role, new name and tighter program. App Orchard (later App Market) was Epic's older third-party program; it was restructured into Epic Showroom (the public catalog) and Vendor Services (developer enrollment and sandboxes). A Showroom listing is still required for multi-hospital third-party apps; it still does not host or comply the app.
Do I still need a Showroom listing if I run on SoFaaS™?
Yes, for any third-party app a hospital will deploy into Epic. SoFaaS™ does not replace Showroom; it files the submission and is the runtime the listing points at. Internal tools built by a health system for its own Epic instance can use Internal App Registration and skip Showroom.
What about HIPAA, a BAA, and SOC 2?
Hospitals will ask for all three before go-live; Showroom supplies none of them. SoFaaS™ is SOC 2 Type II audited (report under NDA), operates as a HIPAA Business Associate, and puts a BAA in place on day one — typically one platform template hospitals review at organization level, with per-hospital amendments when a health system requires its own. Vendors inherit that posture for traffic through the runtime; they still own security of their own application code and any data they handle outside SoFaaS™.
How long does it actually take to go live?
Day 1 in Epic, Week 2 on Showroom, Week 3+ live at the hospital: signup provisions a workspace and Epic-connected sandbox the first day, SoFaaS™ files the Showroom submission in the first two weeks, and a hospital that is ready deploys onto the already-reviewed runtime in about a week. Two honest caveats: Epic's Showroom review queue can run into additional weeks (intake in weeks 1–3, Epic review typically weeks 2–8), and a first hospital can pilot on the runtime in parallel while the listing is in flight. DIY from-scratch builds are cited at 12–18 months to first hospital.
Do we need our own Epic relationship?
You need enrollment in Epic's Showroom / Vendor Services program, not a pre-existing personal relationship with Epic. SoFaaS™ customers do not have to have that enrollment already — VectorCare runs submission and the vendor process as part of the engagement. You still own the clinical product, the hospital relationship, and the customer contract.
Who owns the code and the data?
The vendor owns the application code and IP. The hospital owns its clinical data. SoFaaS™ operates the runtime in between — auth, FHIR mapping, hosting, audit logs — and does not take the product or the chart.
Have a deal stuck on Epic?
SoFaaS™ is the compliant runtime that ships SMART on FHIR apps into Epic in weeks, not quarters.
Talk to us