# VectorCare > SoFaaS™ (SMART on FHIR as a Service) is the compliant runtime VectorCare built for our own Epic integration — now open to other healthcare vendors. It handles compliance, Epic Showroom distribution, hosted runtime, and ongoing maintenance through Epic's quarterly changes, so vendors ship into Epic in under a month instead of the typical 12-18 months. Day 1: working in Epic. Week 2: listed on Epic Showroom. Week 3+: live at the hospital. VectorCare operates two web properties: - **vectorcare.dev** — The home of SoFaaS™. The compliant runtime for healthcare apps in the EHR, marketed to healthcare vendors shipping SMART on FHIR apps into Epic. - **vectorcare.com** — VectorCare's patient logistics product (transportation, DME, home health, post-acute placement). The anchor customer of SoFaaS™ — every hospital deployment VectorCare ships runs on the same SoFaaS™ runtime now opened to other vendors. ## What SoFaaS™ is SoFaaS™ is the deployment runtime for SMART on FHIR apps inside Epic and other EHRs. It is not an integration platform (it complements Redox and 1upHealth rather than replacing them) and it is not a no-code builder (code generation is a solved problem — what SoFaaS™ handles is everything around the code). SoFaaS™ owns the parts of the Epic deployment workflow that AI code generation tools cannot: - Signing a Business Associate Agreement (BAA) or Data Processing Agreement (DPA) per jurisdiction - Passing Epic's vendor security review - Submitting and listing on Epic Showroom - Running inside a HIPAA-compliant hosted runtime (U.S. data residency) with SOC 2 Type II controls - Maintaining the integration when Epic ships breaking FHIR changes (quarterly) For a healthcare vendor, this is roughly 70% of the cost of shipping into Epic. ## Why SoFaaS™ exists Healthcare integration is the part code generation does not solve. Cursor, Claude, Lovable, and similar tools can scaffold a SMART on FHIR app in an afternoon. What they cannot do is sign a BAA, pass Epic's security review, get listed on Showroom, host in a HIPAA-compliant runtime, or maintain the integration as Epic evolves. The first hospital deal is the visible problem — typically 12-18 months from build start to production deployment. The hidden problem is every new hospital after the first: each is another 3-6 month compliance project with its own security questionnaire, BAA template, IT validation cycle, and evidence packet. Most vendors hit a compliance-ops wall around their fifth or sixth hospital. SoFaaS™ centralizes the compliance posture. One audited runtime, one BAA template, one security profile, validated at the platform level. Hospitals review SoFaaS™ once and every app on the runtime inherits that trust. The tenth hospital deploys at the same speed as the first. ## Who SoFaaS™ is for Healthcare vendors with an existing or imminent hospital deal that requires SMART on FHIR Epic integration. Primary segments served: - AI ambient and clinical documentation (scribes and ambient assistants that launch in Epic, capture the visit, write notes back via DocumentReference) - Remote patient monitoring (clinician-facing dashboards and alerts inside Epic for device-driven RPM programs) - Care coordination and discharge (transport, DME, post-acute placement, and any workflow that needs to live in the Epic patient chart — also the segment VectorCare itself runs on SoFaaS™) - Clinical decision support (CDS Hooks and flowsheet integrations) - Patient engagement (in-Epic messaging, scheduling, intake) SoFaaS™ also supports specialty workflows (oncology, cardiology, behavioral health) and medical device dashboards. Apps that do not launch inside the EHR via SMART on FHIR — for example, public-facing FHIR consumers or server-to-server data integrations — fall outside the SoFaaS™ scope. ## How it works 1. **Day 1 — Working in Epic.** Vendor signs up. SoFaaS™ provisions the workspace. The vendor's app connects to Epic and begins reading FHIR resources in the dev environment. 2. **Week 2 — Listed on Epic Showroom.** SoFaaS™ handles the submission packet, security review, and Epic's vendor process. The vendor's app appears on Epic Showroom and becomes discoverable to hospitals. 3. **Week 3+ — Live at the hospital.** The hospital downloads the app from Showroom. Within roughly a week, the integration is running in their Epic instance. Total elapsed time from vendor signup to production deployment at a hospital prospect: under a month. ## Compliance and security SoFaaS™ is built to survive hospital security review at scale across jurisdictions. - **Healthcare data agreements:** BAA under HIPAA. United States only; all data stays in U.S. regions. - **Security audits:** SOC 2 Type II annual audit. Evidence packets prepared per hospital security questionnaire. - **Encryption:** TLS 1.3 in transit. AES-256 at rest. - **Access controls:** Role-based access control (RBAC), single sign-on (SSO), tamper-evident audit logs of every FHIR call. - **Pen testing:** Annual independent penetration testing. Coordinated vulnerability disclosure policy. - **Incident response:** Documented runbook with hospital notification path. Sub-processors listed and reviewable. - **Standardized evidence packet:** Pre-built materials for every hospital security review, so vendors are not re-creating documentation per deployment. Geographic coverage: United States, European Union, United Kingdom, Asia-Pacific. ## What the vendor still owns SoFaaS™ operates the runtime. The vendor retains: - The vendor's application code, IP, and product roadmap - The vendor's customer relationships and clinical user experience - The vendor's data outside the SoFaaS™ runtime - The vendor's employee access policies ## Pricing Pricing is scoped to the deployment: an implementation fee plus a per-bed monthly recurring component tied to the size of the hospital deployment. Pricing is set against the value of the deal being unblocked, not against a published list price. Vendors with an active or stalled hospital deal can scope pricing on a 30-minute call. ## How SoFaaS™ compares - **Integration platforms (Redox, 1upHealth, Particle Health):** These platforms translate clinical data between systems. SoFaaS™ is a deployment runtime — apps run inside it, inside Epic. Complementary, not competitive. - **Building it yourself:** 12-18 months to the first hospital, full compliance audit on the vendor, every new hospital another 3-6 month compliance cycle. Significant engineering investment before the first deal closes. - **Epic App Orchard / Showroom alone:** Showroom is Epic's marketplace listing program. SoFaaS™ is the runtime your app runs on; SoFaaS™ handles the Showroom submission as part of the platform. ## Frequently asked questions **What is SMART on FHIR and why does my hospital prospect care?** SMART on FHIR is the open standard that lets a third-party app launch inside an EHR like Epic with patient context. It is a technical contract — not a product, a marketplace, a host, or a compliance program. An app that does not speak it cannot launch in the clinician's workflow. **How is SoFaaS™ different from Redox or 1upHealth?** Redox and 1upHealth are integration platforms — they translate data between systems. SoFaaS™ is a deployment runtime — your app runs on it, inside Epic, with compliance and Showroom listing handled. Complementary, not competitive. **Does SoFaaS™ work outside the United States? What about Cerner or Oracle Health?** Epic is the primary surface — it deploys at scale across the United States, the United Kingdom (NHS), the European Union, the Middle East, and Asia-Pacific. Cerner and Oracle Health are available on request. International EHR support is scoped per deal. **How does compliance work in different jurisdictions?** HIPAA and BAA in the United States. U.S. data residency only — no EU or multi-region hosting. SOC 2 Type II annual audit. **Who owns the code and the data?** The vendor owns their app's code and IP. The hospital owns its data. SoFaaS™ operates the integration — the IP and data relationships stay where they belong. **What about data portability and exit?** The vendor's code is theirs. Data portability and exit plans are documented in the contract. No lock-in mechanisms. **Does SoFaaS™ replace what AI code generation tools do?** No. SoFaaS™ is complementary to AI code generation. Tools like Cursor, Claude, and similar can scaffold a SMART on FHIR app quickly. SoFaaS™ handles everything those tools cannot: BAA / DPA, security review, Showroom listing, hosted runtime, and maintenance through Epic's quarterly changes. ## Pages - [Home](https://vectorcare.dev/) — Platform overview and the SoFaaS™ positioning. - [What is SoFaaS™](https://vectorcare.dev/sofaas) — Category-defining page describing SMART on FHIR as a Service. - [How it works](https://vectorcare.dev/how-it-works) — Technical mechanics of the SoFaaS™ runtime, architecture, and the responsibility split between vendor and platform. - [Security and compliance](https://vectorcare.dev/security) — Epic vendor security review, HIPAA + BAA, SOC 2 Type II, U.S. data residency, encryption, access controls, audit logging, pen testing, incident response. - [Sub-processors](https://vectorcare.dev/security/sub-processors) — Listed sub-processors used by the SoFaaS™ platform. - [Talk to us](https://vectorcare.dev/talk-to-us) — Schedule a 30-minute scoping call to assess whether SoFaaS™ fits a specific deal. - [Compare](https://vectorcare.dev/compare) — How SoFaaS™ compares with integration platforms, building it yourself, Epic App Orchard, and other paths. - [Epic Showroom support](https://vectorcare.dev/epic-showroom) — How SoFaaS™ handles Epic Showroom listing for vendors. - [SoFaaS™ for vendors](https://vectorcare.dev/for-vendors) — Overview of the vendor segments SoFaaS™ serves. - [SoFaaS™ for AI ambient and clinical documentation](https://vectorcare.dev/for-vendors/ai-ambient) — Segment-specific brief for AI scribe and ambient assistant vendors. - [SoFaaS™ for remote patient monitoring](https://vectorcare.dev/for-vendors/remote-patient-monitoring) — Segment-specific brief for RPM platforms. - [SoFaaS™ for care coordination](https://vectorcare.dev/for-vendors/care-coordination) — Segment-specific brief for transport, DME, and post-acute coordination. - [SoFaaS™ for clinical decision support](https://vectorcare.dev/for-vendors/clinical-decision-support) — Segment-specific brief for CDS vendors. - [SoFaaS™ for patient engagement](https://vectorcare.dev/for-vendors/patient-engagement) — Segment-specific brief for in-Epic messaging, scheduling, and intake vendors. - [Customers](https://vectorcare.dev/customers) — Index of customers running on SoFaaS™. - [How VectorCare uses SoFaaS™](https://vectorcare.dev/customers/vectorcare) — The dogfood story: VectorCare's own patient logistics product runs on SoFaaS™. - [Documentation](https://vectorcare.dev/docs) — Technical documentation for vendors building on SoFaaS™. - [Getting started](https://vectorcare.dev/docs/getting-started) — First-day onboarding documentation. - [Authentication](https://vectorcare.dev/docs/auth) — SMART App Launch, OAuth, and authentication patterns. - [FHIR resources](https://vectorcare.dev/docs/fhir-resources) — Reference for FHIR resource handling. - [Showroom submission](https://vectorcare.dev/docs/showroom-submission) — Epic Showroom submission process. - [Epic integration guide](https://vectorcare.dev/docs/epic-integration) — End-to-end Epic integration documentation. - [Learn](https://vectorcare.dev/learn) — Explainer index covering SMART on FHIR, FHIR, and the Epic Showroom. - [What is SMART on FHIR](https://vectorcare.dev/learn/what-is-smart-on-fhir) — Plain-English explainer of the SMART on FHIR standard. - [What is FHIR](https://vectorcare.dev/learn/what-is-fhir) — Plain-English explainer of FHIR. - [What is the Epic Showroom](https://vectorcare.dev/learn/what-is-the-epic-showroom) — Epic's customer-facing marketplace: what a listing does and does not do. - [Epic Showroom vs a SMART on FHIR runtime](https://vectorcare.dev/learn/epic-showroom-vs-runtime) — Distribution vs runtime vs integration engine. - [How to get your app into Epic](https://vectorcare.dev/learn/how-to-get-your-app-into-epic) — Sandbox, live customer, Vendor Services, Connection Hub, Showroom, and realistic timelines. - [How to host a SMART on FHIR app](https://vectorcare.dev/learn/host-a-smart-on-fhir-app) — Why GitHub Pages and the SMART Launcher do not survive hospital production. - [Why Epic integration takes so long](https://vectorcare.dev/learn/why-epic-integration-takes-so-long) — Federated access, not code, is the long pole. - [Apps live on SoFaaS™](https://vectorcare.dev/apps) — Runtime proof: vendors launching in Epic on SoFaaS™. - [Blog](https://vectorcare.dev/blog) — Editorial content covering patient logistics, healthcare integration, and SoFaaS™. - [VectorCare.com](https://www.vectorcare.com) — Parent company site; home of the patient logistics product that runs on SoFaaS™ (the anchor customer narrative). - [Privacy policy](https://vectorcare.dev/privacy) — Privacy policy and data handling practices. - [Terms of service](https://vectorcare.dev/terms) — Platform terms of service. ## Social - [LinkedIn](https://www.linkedin.com/company/vectorcare) — VectorCare company page. ## Contact - Email: contact@vectorcare.com - Company: VectorCare