Skip to content
Hermes Health API
API referenceOpenAPI spec

Guide

Add a patient

Register someone whose records you want.

A patient belongs to a project, and the flags on the create body decide what Hermes goes and looks for:

Patient body
json
{
  "firstName":   "Jane",
  "lastNames":   ["Doe"],
  "dateOfBirth": "1990-04-12",
  "sex":         "female",
  "zipCodes":    ["94110"],
  "siteSonar":   true
}

siteSonar finds the facilities where the patient has been seen. patientHistories also retrieves their diagnoses and treatments. Set either, both or neither; with neither, the patient is registered and nothing is searched.

Upload the HIPAA authorization

No patient route accepts the authorization document in its body. Upload it separately:

  1. Read authorization.uploadUrl from any patient response. It is a short-lived upload URL, so there is no extra call to request one.
  2. PUT the PDF to that URL as raw bytes, with no Authorization header.

Send the URL exactly as issued. Its signature is in the query string, so changing any part of it returns 403.

Hermes reviews every new authorization. It sits at authorizationStatus: NeedsApproval until approved, and no search runs before then. Editing a patient field that could fix the current status sends the authorization back for review.

Some projects need no uploaded document:

  • Projects whose purpose is CoveredOperations, CoveredPayment or CoveredTreatment.
  • Projects using authorizationMethod: ial2Tokens, which must first be enabled for your company.

Next steps