CODEXA.Technologiez
All insightsEngineering

What integrating with a clinical system actually involves

Codexa Engineering · Sep 26, 2026 · 2 min read

Health software rarely lives alone. Almost every project involves reading from or writing to a system that already holds the records — and that integration is usually the largest, least visible part of the work.

Find out what it actually exposes

"It has an API" covers an enormous range in this sector:

  • A documented FHIR endpoint with a sandbox — days of work.
  • An HL7 v2 interface over a VPN — weeks, and a message format with local variations.
  • A nightly CSV export to a shared folder — workable, but your product is now a day behind.
  • Nothing, and a vendor who will quote you five figures to enable access.

That last one is a commercial problem rather than a technical one, and it is far better discovered during discovery than during the build.

FHIR is a standard, not a guarantee

Two systems can both be FHIR-compliant and still disagree about how to represent the same clinical fact. Profiles vary by region and by vendor, optional fields are used differently, and extensions carry meaning that is not in the base specification.

Budget for mapping, not just connecting. The engineering is not the hard part; agreeing what a field means is.

Identity is harder than it looks

Matching a person across systems without a shared identifier is a genuine problem, and getting it wrong in healthcare is not a data-quality issue — it is a safety one.

Where a national or regional patient identifier exists, use it. Where it does not, be conservative: a lower match rate that a human resolves beats a confident match that attaches one person's results to another.

Never use real data to build

Patient records do not belong in development or test environments, regardless of how careful the team is.

Realistic synthetic data covers the same shapes and edge cases without the exposure, and it removes an entire category of risk from the project. Generating it is a small task that pays for itself the first time a laptop goes missing.

Plan for the integration failing

External systems go down, change without notice, and return success for requests they did not actually process.

  • Queue and retry rather than failing the user's action.
  • Alert loudly on sustained failure — silent degradation is how a week of data goes missing.
  • Reconcile periodically rather than trusting that every message landed.

More on how we scope this kind of work on our healthcare page, and on what integrations do to a budget in what drives software project cost.

How long does an HL7 or FHIR integration take?

A documented FHIR endpoint with a working sandbox is typically days of engineering. An HL7 v2 interface over a VPN is usually weeks, because the message format carries local variations that have to be mapped rather than merely parsed. A nightly file export is workable in days but leaves your product a day behind the source of truth.

Can we develop against real patient data?

No. Patient records should never enter a development or test environment, however careful the team is. Realistic synthetic data covers the same shapes and edge cases without the exposure, and generating it is a small task that removes an entire category of risk from the project.

Enjoyed this? Let's work together.

Start a project