Northstar.

Integrations

End-of-day reviewper-practice credentials, encrypted in your Medplum tenant

What works right now

A live check means Northstar successfully reached the service on this page load. Setup and go-live evidence are tracked separately.

checked now
Medplum clinical store
Live

FHIR read succeeded

Elation read-through
Live

OAuth token succeeded; chart read-through is available

Spruce messaging + fax
Degraded

Outbound API works; no inbound event since May 11, 2026

Hint billing
Live

Practice API read succeeded; webhooks and billing commands are tracked separately

eNavvi authentication
Live

Production embed credential accepted; prescription handoff remains gated

Google Workspace
Setup required

OAuth client and practice account are not connected

Spruce

inbound offline

The API powers outbound replies and backfill. A stable public webhook is separately required for new messages and faxes.

API
Connected
Webhook
Public receiver configured

The public receiver is configured, but no recent inbound event has been recorded. Last event: May 11, 7:20 PM.

Runtime
24h
0
7d
0
Latest
May 11, 7:20 PM
Webhook
https://cdcm4m.taild7b7dc.ts.net/api/integrations/spruce/webhook
Send the secret as x-northstar-webhook-secret or a bearer token.
Fax operationsdelivery is never inferred
Webhook queue
200
Needs review
0
Failed events
0
API accepted
0
Posted / unconfirmed
0
Oldest open
Sep 4, 8:02 AM

200 webhook events queued over 5 minutes.

Review fax destination directory·Reconcile fax attempts
YWlkX0...PT0=

Google Workspace

not configured

Drive (file inbox + storage), Gmail (inbox aggregation + send), Calendar (provider availability + appointments). Sign-in with your practice's Google Workspace account; BAA inherited from Workspace agreement (Gemini covered).

Daily-use readiness
Setup incomplete
Server OAuth settings
Missing
Google account
Needed
Required scopes
Reconnect
Drive inbox
Needed
Google setup needed

Google sign-in is not enabled in this Northstar environment yet. Once it is enabled, practices connect by signing in and granting permission.

Drive
Files and chart uploads
Gmail
Patient conversations
Calendar
Availability and scheduling
Developer details
2 server settings are missing.
Missing server settings
  • GOOGLE_CLIENT_ID
  • GOOGLE_CLIENT_SECRET
Callback URL
https://cdcm4m.taild7b7dc.ts.net/api/integrations/google/callback

Elation

connected

Read schedule and chart context from Elation while Northstar builds local patient shadows for inbox, files, summaries, and workflow state.

Access
Configured
Source
Saved
Writes
Off
Practice
1001653649670148
Clinician
1001653687222274

Hint billing

connected

Hint owns membership billing. Northstar queues signed events durably and projects only records linked by explicit integration IDs.

Practice API
Live
Webhook
Partner key missing
Practice
ID missing
Commands
Disabled pending UAT
Queued
0
Review
0
Failed
0
In progress
0
Stale >5m
0
Latest
None
Webhook
https://cdcm4m.taild7b7dc.ts.net/api/integrations/hint/webhook

Uses X-Hint-Signature. Unsupported or unlinked events remain in review; they are not silently discarded.

Open reconciliation and review queue

eNavvi

connected

eNavvi owns certified prescribing execution. Northstar verifies the server-side embed credential and releases reviewed prefill only from a complete Medplum draft.

Authentication
Live
Environment
Production
Prescribing
Reviewed handoff built

eNavvi accepted the credential and minted a 60-minute session. No prescription was created or sent.

The embed is one-way: prefill delivery is not prescription transmission. Northstar origin approval, live clinician UAT, and transmission/status reconciliation remain required before use.

Backup & recovery

not configured

Encrypted Medplum export, Binary-byte verification, and clean-project restore evidence. No backup content or keys enter this app.

Encrypted backup
Evidence path missing
Restore drill
Not yet proven

Backup evidence is unavailable. Do not assume an encrypted recovery artifact exists.

Runbook: ops/backup/README.md

VaxCare

not configured

Vaccine procurement, inventory, eligibility, billing. The partner API is gated behind NDA. Email partners@vaxcare.com from your practice domain to request access; spec packet returns auth + endpoint details we'll wire here.

awaiting partner spec

Go-live evidence

These checkpoints do not turn live connections off. They prevent Northstar from becoming the authoritative EHR until clinical and operational proof is current.

Full-EHR cutover packet

Medplum cannot be treated as authoritative until every required checkpoint links to current, restricted evidence. Connected APIs and passing local tests do not substitute for live UAT.

Cutover blocked
0/12 checkpoints evidencedPacket not foundExpires None

Security and confidentiality

Workstream 1

Per-user auth, enrollment containment, adolescent disclosure controls, and failure-state proof.

Evidence is missing.

Canonical Medplum record

Workstream 2

Identity uniqueness, referential integrity, and clinical-write reconciliation.

Evidence is missing.

Hint billing

Workstream 3

Issued contract, safe mutation/reconciliation UAT, refunds, and operator disposition.

Evidence is missing.

eNavvi prescribing

Workstream 4

Issued contract plus success, decline, timeout, replay, change, cancel, and supported EPCS UAT.

Evidence is missing.

Elation migration

Workstream 5

Full-domain counts, exact exceptions, document bytes, and delta reconciliation.

Evidence is missing.

Labs and results

Workstream 6

Order egress, inbound matching, review, acknowledgment, correction, and escalation proof.

Evidence is missing.

Scheduling

Workstream 6

Resources, concurrency, reminders, replies, changes, notices, and daily reconciliation.

Evidence is missing.

Documents

Workstream 6

Ingest, assignment, signing, versioning, delivery, and retention proof.

Evidence is missing.

Backup and restore

Workstream 6

Current encrypted backup plus measured clean-project restore drill.

Evidence is missing.

Monitoring and alerts

Workstream 6

Queue, webhook, audit, drift, backup, service-health, and accountable alert delivery proof.

Evidence is missing.

Insurance claims

Workstream 6

Working claims workflow or Lakes-approved non-goal with a safe external handoff.

Evidence is missing.

Shadow clinic and cutover

Workstream 7

Full staff/mobile shadow day, reconciled defects, rollback drill, and named go/no-go approval.

Evidence is missing.

Evidence contract: ops/cutover/README.md