What is SoFaaS™?
SoFaaS™ — SMART on FHIR as a Service — is the compliant runtime that lets healthcare vendors ship apps into Epic and other EHRs without building their own compliance, distribution, or maintenance infrastructure.
It sits between the vendor's application and the hospital's Epic instance: the runtime owns HIPAA-ready hosting and a BAA, SMART App Launch and OAuth, FHIR resource handling and write-back contracts, Epic Showroom submission, audit logging, and quarterly Epic compatibility — so the vendor can keep building product. It is not the SMART on FHIR standard, not Epic Showroom, not a data-translation or integration platform, not a public-website host, and not a server-to-server FHIR consumer that never launches in the EHR. The vendor keeps their code and IP; the hospital keeps its data; SoFaaS™ sits between, not on top.
Why SoFaaS™ exists
Code generation is solved. Cursor, Claude, and similar tools can scaffold a SMART on FHIR app in an afternoon. The hard part of getting into Epic was never the code — it was everything around it.
A healthcare vendor shipping into Epic has to: pass a security review, sign a Business Associate Agreement, get listed on Epic Showroom, run inside HIPAA-compliant hosting, maintain the integration when Epic ships breaking changes, and do all of that again for every new hospital that wants to deploy them.
Integration platforms like Redox and 1upHealth solve a different problem (data translation between systems). EHR-native tooling like the App Orchard / Showroom program is just distribution — you still have to build and run the app yourself.
SoFaaS™ is the missing layer: a managed runtime that owns the compliance, distribution, and ongoing maintenance so the vendor can stay focused on the product.
What's included
Compliant runtime
HIPAA-ready hosting with full encryption, audit logging, and access controls.
Epic Showroom listing
Submission packet, security review, and vendor process — handled end-to-end.
Business Associate Agreement
BAA available on day one. One template, accepted by every hospital that reviews SoFaaS™ at the platform level.
SOC 2 Type II
Audited annually. The report is the same one your hospital prospect's procurement team has already seen.
FHIR mapping
Pre-built handlers for the resources your category needs — Patient, Encounter, Observation, DocumentReference, and the rest.
OAuth & SMART App Launch
Standards-compliant auth with Epic, Cerner, and other major EHRs. No OAuth plumbing for you to maintain.
Maintenance
When Epic ships breaking changes — and they do, quarterly — we update the runtime. Your app keeps working.
Who SoFaaS™ is for
Healthcare vendors with a hospital deal — open or stalled — that requires shipping into Epic. The categories where SoFaaS™ shows up most:
- • AI ambient and clinical documentation
- • Remote patient monitoring
- • Care coordination, transport, DME, post-acute placement
- • Clinical decision support
- • Patient engagement and specialty workflow apps
What SoFaaS™ is not
- Not a public website host.
- Not a server-to-server FHIR consumer. Headless SMART Backend Services, bulk export, and no-user-launch integrations are a different SMART pattern.
- Not a Redox (or 1upHealth) replacement. Many customers use both.
- Not a patient-logistics / NEMT product. That is vectorcare.com.
- Not Epic Showroom. SoFaaS™ can run the submission; it is not the listing program.
- Not the SMART on FHIR standard.
- Not a substitute for the vendor's own security program.
- Not a claim on vendor IP or hospital data.
- Not a way to skip Epic's vendor program. Showroom still requires enrollment; SoFaaS™ runs that process for you.
- Not a Cerner-first platform. Epic is fully supported; Oracle Health (Cerner) is available on request.
Not sure which layer you need? Epic Showroom vs a SMART on FHIR runtime lays out which tool does which job.
How SoFaaS™ differs
vs. integration platforms (Redox, 1upHealth)
Integration platforms move data between systems. SoFaaS™ hosts and runs your app inside Epic. They solve different problems and are often used together.
vs. building it yourself
Building it yourself costs 12–18 months and significant engineering investment before the first hospital is live, plus a permanent compliance ops function as you scale. SoFaaS™ gets you live in under a month with the compliance posture inherited.
vs. EHR-native tooling (App Orchard / Showroom)
Showroom is distribution. SoFaaS™ is the runtime your app runs on — and we handle the Showroom submission as part of getting you live.
FAQ
What does SoFaaS™ stand for?
SoFaaS™ stands for SMART on FHIR as a Service. It's the category we coined for the compliant runtime layer that sits between a healthcare vendor's app and the EHR (Epic, Cerner, and others).
Is SoFaaS™ a replacement for Redox or 1upHealth?
No. Integration platforms like Redox and 1upHealth translate data between systems. SoFaaS™ is a deployment runtime — your app launches inside Epic on top of it, with compliance and distribution handled. Many SoFaaS™ customers use an integration platform for non-Epic data flows.
Do I have to give up control of my code?
No. You own your code and your IP. SoFaaS™ operates the runtime that hosts and authenticates the app inside Epic. Hospitals own their data. We sit between, not on top.
Is SoFaaS™ the same as Epic App Orchard?
No. Epic Showroom (formerly App Orchard) is Epic's marketplace. SoFaaS™ is the runtime your app runs on, and we handle the Showroom submission as part of getting you live. Showroom is distribution; SoFaaS™ is the platform.
What EHRs work with SoFaaS™ today?
Epic is fully supported. Cerner / Oracle Health is available on request. Other EHRs are added when customer demand justifies it — talk to us if your deal needs a specific system.
Who is SoFaaS™ for?
Healthcare vendors with an existing or imminent hospital deal that needs SMART on FHIR Epic integration. Most common categories today: AI ambient and clinical documentation, remote patient monitoring, care coordination, clinical decision support, and patient engagement.