Zoom Epic FHIR Integration: Deployment Guide, User Experience, Best Practices and Troubleshooting
Short answer
Epic remains the clinical system of record. Zoom is the video layer. Providers launch from Hyperspace. Patients launch from MyChart. Nurses and inpatient rooms have their own launches. Device test is a separate launch. SMS can carry a telehealth join link. Authenticate with OAuth, not JWT — Zoom deprecated JWT in September 2023.
This is a deployment guide, not a product brochure. Field labels below come from Zoom’s current Epic FHIR article. Do not paste API keys, secrets, private keys, org IDs, or real Epic URLs into tickets, emails, or this page. Do not invent field names from memory.
This article does not embed screenshots. Use Zoom’s official Epic FHIR Marketplace listing and support article, or captures from your own authorized Test environment. Do not publish production Hyperspace or MyChart screens. Tables and workflow lists below stand in for screen tours.
Field labels, launch types, and account-level unlocks were checked on 28 August 2026 against Zoom KB0069113 (Epic FHIR; Zoom last modified 14 July 2026), KB0069029 (older Epic listing; Zoom last modified 26 August 2026), Zoom’s JWT FAQ, Zoom’s HIPAA-ready page, and the Zoom App Marketplace healthcare category. Zoom and Epic change labels. The live Marketplace configuration page controls.
What this integration is
Zoom video links sit on the video-visit appointment. The clinician documents in Epic. The visit media runs in Zoom. Zoom’s FHIR article states that meetings are created on behalf of the encounter provider, or the first provider who joins if that person is different. The integration can create temporary Zoom user accounts for patients, and providers can send telehealth meeting links by SMS.
There are two Zoom Marketplace listings. Search for Epic FHIR. The older listing is titled Epic and is documented separately. If the configuration page shows Encryption Key and Encryption Secret, you are not on the FHIR app. Stop and switch listings before anyone copies values into Epic.
| Role | Launch surface | Zoom FHIR launch type | What success looks like |
|---|---|---|---|
| Provider | Hyperspace | Provider launch | Host joins; chart stays in Epic; patient-joined indicator can light |
| Patient | MyChart, desktop or mobile | Patient launch | Wait-for-host if early; then auto-join or manual admit per policy |
| Nurse / clinical staff | Hyperspace | Nurse launch | Staff join the same encounter session without becoming a second clinical chart |
| Inpatient room | Zoom Rooms | Zoom Room launch | Named room joins the encounter as the in-room endpoint |
| Pre-visit check | Device test flow | Device test launch | Camera, speaker, and network check before the scheduled visit |
Requirements
Zoom’s Epic FHIR article lists:
- A paid Zoom account
- Account owner or admin privileges to add and configure the app
- A signed BAA for HIPAA-enabled workflows
You also need working Epic endpoints for this app, supplied by your Epic team — not invented here:
- Epic FHIR R4 base URL
- Epic Telehealth base URL
- Epic OAuth base URL (optional, but Zoom says it can skip a remote lookup at launch)
- Test versus Production selected to match the Epic environment you are pointing at
Coordinate four groups before anyone clicks Add: Zoom admin, Epic ambulatory / technical services, network / firewall (notifications originate from Zoom address space), and privacy / compliance (BAA, recording policy, AI features). Clinical champions own the test matrix, not the Marketplace form.
Zoom’s HIPAA-ready materials describe a BAA as the contractual path for HIPAA-enabled use of covered Zoom services. Signing it does not make every Zoom feature, every AI add-on, every recording setting, or every workstation HIPAA compliant by itself. Confirm which services the BAA covers, lock meeting features you do not want on a visit (recording, annotation, file transfer), and keep PHI out of chat titles and SMS bodies. See Zoom AI Companion in 2026 before turning AI on for clinical visits.
OAuth, not JWT
Zoom deprecated JWT authentication in September 2023. The Epic FHIR article tells an account admin to migrate from Marketplace: Manage → Added Apps → Epic FHIR → Update, then authorize the requested permissions. When that finishes, you return to the Epic FHIR Marketplace page.
The FHIR configuration page still has a Zoom API Key field. That is a label on the form, not permission to keep JWT as the live auth method. Do not paste the key, the app secret, or the private key into this article, a public ticket, or a screenshot gallery.
Zoom’s FHIR notes also say: if you Regenerate the API Key field on the Epic FHIR configuration page, you must add the acc_id URL parameter to FDI records. Existing customers who have not regenerated can continue with org_id only. Confirm which state you are in before rewriting FDI URLs.
Deployment phases
- Coordinate teams. Name Zoom admin, Epic TS, network, compliance, and a clinical tester. Agree Test versus Production. Do not point Production URLs at a Test Zoom app or the reverse.
- Marketplace install. Sign in to the Zoom App Marketplace as the account administrator. Search Epic FHIR. Open that listing. Click Add. Confirm permissions. Click Allow. The installer opens the configuration page.
- Configure field labels only from the live form. Fill values from Epic and Zoom credentials stores. Never paste secrets into chat, email, or a knowledge-base draft.
- Unlock two account-level Meeting settings. Join before host and Waiting Room must remain unlocked so the integration can drive wait and admit behavior.
- Build FDI records in Epic. One record per launch type you will actually use. URL and CONTEXT live in Installation Mnemonic Values. Pull the current mnemonic strings from Zoom KB0069113 — do not copy a blog post.
- Run the test matrix in Test. Provider-first, patient-first, MyChart desktop, MyChart mobile, nurse, room if in scope, device test, SMS link, and Notification Records for the patient-joined indicator.
- Promote to Production only after Test is signed off, with Epic Environment set to Production and Production base URLs — not a relabeled Test client.
Marketplace field labels (Epic FHIR)
These labels are from Zoom KB0069113 as retrieved 28 August 2026. If your form differs, trust the form. This table is labels and purpose — not sample values.
| Field label | Required? | What it is for | Do not |
|---|---|---|---|
| Zoom API Key | Yes | Identifies the Zoom side of the integration; also referenced as org_id on FDI URLs | Share with third parties; paste into email or screenshots |
| Zoom App Secret | Yes | Client secret Zoom provides when enabling the Zoom app in App Orchard | Invent a value; reuse a JWT API Secret from a different listing |
| Zoom App Private Key | Yes | Value from the privatekey.pem file Zoom provides for App Orchard enablement | Commit the PEM to git or attach it to a public ticket |
| Epic FHIR R4 Base URL | Yes | Base URL where this Epic instance exposes FHIR R4 endpoints | Paste a real org URL into public docs; mix Test and Production hosts |
| Epic Telehealth Base URL | Yes | Base URL for Epic 2020 telehealth endpoints; also used for join/leave notifications | Guess the path; skip allow-listing Zoom notification source IPs |
| Epic OAuth Base URL | Optional | Epic FHIR authorization server; Zoom says it can skip a remote lookup at launch | Treat blank as a defect if Epic has not given you one |
| Epic Environment | Yes | Test or Production. Must match the Epic instance behind those base URLs | Set Production against a Test host “just to try it” |
| Patient Admittance Policy | Yes | After the provider joins: automatic entry versus provider-manual admit | Assume Waiting Room UI in Zoom is the only control; this policy is the integration’s admit rule |
| Provider User Type | Yes | Zoom user type assigned when the integration creates a provider account that did not already exist | Leave unlicensed if those providers will host visits |
| Epic Device Test Endpoint URL | Optional | Where device-test results are posted | Skip the device-test launch if you still promised patients a pre-visit check |
| Healthcare Provider Device Test Help URL | Optional | Help page during device test | Point this at an internal wiki patients cannot open |
Save Changes on that page when the labels are filled from your credential store. Then unlock the two account settings.
Unlock Join before host and Waiting Room
Zoom web portal, as an admin who can edit account settings: Account Management → Account Settings → Meetings tab. Zoom requires these two settings to remain unlocked:
- Under Schedule meeting: Allow participants to join before host
- Under Security: Waiting Room
Unlocked means the Epic FHIR app can set visit behavior. It does not mean every standing Zoom meeting in the tenant should let guests in early. Keep ordinary meeting policy locked at group or user level where you still need it. Visit admit behavior is then governed by Patient Admittance Policy on the FHIR app.
Zoom’s Usage section: if the patient launches before the provider, they see a loading screen that says they should wait for the host to start the meeting. After the provider joins, they either enter automatically or wait to be admitted, depending on that policy.
FDI records
The FHIR integration is used by configuring FDI records for each launch type. Each record has a URL string for a Zoom API on applications.zoom.us/epicfhir/ and a CONTEXT string that identifies the encounter and participants. Zoom tells you to enter those in Installation Mnemonic Values: URL field and CONTEXT field.
Launch path names Zoom currently documents (append your own org_id and, when required, acc_id — do not copy anyone else’s):
| Launch type | Path name | CONTEXT parameter names Zoom lists |
|---|---|---|
| Provider (Hyperspace) | providerlaunch | epicSessionId, firstName, lastName, epicUserId, useProviderZoomAccount, noRedirect |
| Nurse (Hyperspace) | nurselaunch | epicSessionId, firstName, lastName, epicProviderId, useProviderZoomAccount, noRedirect |
| Patient (MyChart) | patientlaunch | epicSessionId, epicUserId, firstName, lastName, encounterProviderId, useProviderZoomAccount, noRedirect |
| Zoom Room (in-patient) | zoomroomlaunch | epicSessionId, epicProviderId, useProviderZoomAccount, roomName, roomDisplay, noRedirect |
| Device test | devicetest | epicSessionId, epicUserId, firstName, lastName |
Copy the live mnemonic strings from Zoom’s article into Epic. Do not type example CSNs, user IDs, room names, or email addresses into this page. Do not use patient names in test scripts that leave the Test environment.
User experience
Provider
Open the telehealth appointment in Hyperspace and launch. The provider is host and joins when the visit starts. Documentation stays in Epic. If Patient Admittance Policy is manual admit, the provider admits the waiting patient. Hyperspace can show a green light when the patient has joined — that light is a notification, not the video stack itself.
Patient
Find the appointment in MyChart and launch on a computer or a phone. Early joiners wait for the host. After the provider is in, policy either drops them into the session or holds them for admit. Zoom states patients can rejoin while the provider is still in the session. SMS is a separate delivery path for the telehealth link; treat the SMS body as operational, not a place for diagnoses or identifiers you would not put on a postcard.
Nurse and inpatient Zoom Rooms
Nurse launch is the Hyperspace path for staff who are not the encounter provider. Zoom Room launch is the in-patient / monitor path: the room name and display name in CONTEXT select the room. Test the physical room on the same encounter the clinic will use, not a leftover Zoom Room from a conference calendar.
Temporary accounts
Zoom creates Zoom user accounts for patients and providers from FDI data. Patient accounts are described as temporary. Provider accounts created this way are identified by emails ending in @zoomtelevisit.com; an admin can delete them under User Management → Users. If you set useProviderZoomAccount so an existing Zoom login is used instead, that is a different identity path — test it explicitly.
Test matrix
Run this in the Epic Test environment with Epic Environment set to Test. No production charts. No real patient names in recordings or tickets.
| Case | Who launches first | Pass if | If it fails, look at |
|---|---|---|---|
| Provider first, desktop MyChart | Provider, then patient on a computer | Host in session; patient joins per admit policy; green light if you use it | Provider FDI URL/CONTEXT; Telehealth Base URL; Notification Records |
| Patient first, desktop MyChart | Patient, then provider | Wait-for-host screen; then auto-join or manual admit matches policy | Unlocked join-before-host / Waiting Room; Patient Admittance Policy |
| Patient first, mobile MyChart | Patient on a phone, then provider | Same wait and admit behavior as desktop; audio/video usable | Client install/permissions; network; device test launch |
| Nurse join | Provider in session, nurse launches | Nurse in the same encounter session | Nurse FDI record, not a second Provider record |
| Zoom Room | Room launch for an inpatient encounter | Correct room; display name matches; OAuth scopes for Rooms if you just migrated from JWT | roomName / roomDisplay; Marketplace Update for OAuth; Rooms license |
| Device test | Patient or clinic workstation before the visit | Test completes; optional result URL receives the result | devicetest FDI; Device Test Endpoint URL; Help URL reachability |
| SMS link | Provider sends the telehealth link | Patient can open the visit without a second Epic login maze you did not design | SMS feature eligibility; link expiry; do not put PHI in the message body |
| Patient-joined indicator | Patient joins while provider is in Hyperspace | Green light; Notification Records RespCode 200 for that meeting or CSN | Telehealth Base URL; Zoom notification IPs on the allow list; FDI |
Security
Zoom’s Epic FHIR Data Security section states:
- Zoom helps enable HIPAA compliance — it does not declare your tenant compliant
- Communications between Zoom and Epic, and Zoom video sessions, use AES-256
- Video visits launched from Epic are dynamic password protected
- Account-level meeting settings apply to these sessions; disable recording, annotation, and similar features if policy requires it
What Zoom says it reads from Zoom: provider first and last name for display, and account-wide meeting settings when creating the visit. What Zoom says it reads from Epic: session ID, Epic user ID, Epic provider ID, encounter provider ID, names used to create Zoom accounts, provider email when using an existing Zoom account, and Zoom Room name for room visits. That is encounter and identity context for launch and notifications. It is still PHI in your environment. Keep it in Epic and Zoom. Do not copy it into this knowledge base.
This integration is commercial healthcare Zoom. It is not a FedRAMP authorization and not a CMMC Level 2 certification of your organization. If the real requirement is CUI or a government Zoom environment, start with Zoom, Zoom for Government and CMMC and do not assume Epic FHIR is available or authorized there.
Troubleshooting
Patient-joined indicator (green light)
Hyperspace shows a green light when the patient joins. When that light is wrong, Zoom tells you to use Notification Records:
- Sign in to the Zoom App Marketplace as the account administrator.
- Manage → Epic FHIR → Configure → Notification Records.
- Search by Zoom meeting ID or the encounter CSN.
- Each row is a notification Zoom sent to Epic (join/leave). RespCode 200 means Epic handled it. Any other value means the notification did not land cleanly, which is why the indicator lies.
Then check, in order: Epic Telehealth Base URL, IP allow list for Zoom notification sources (current list on Zoom’s network firewall / proxy article — do not freeze an old IP table here), and FDI records. Contact Zoom Support if those three are correct and RespCode is still not 200.
Launch fails or wrong host
- Wrong Marketplace listing (Epic versus Epic FHIR)
- Epic Environment mismatch (Test URL with Production toggle, or the reverse)
- Stale JWT: run Marketplace Update for OAuth
- FDI URL missing acc_id after an API Key regenerate
- Join before host or Waiting Room locked at account level
- Provider User Type created an account that cannot host
Video or audio is the complaint
If Hyperspace launched and Notification Records are 200, the integration did its job. Frozen video and robotic audio are network path problems: packet loss, jitter, Wi-Fi, VPN. Use Why does Zoom keep freezing? rather than rebuilding FDI records.
Best practices
- One integration owner on Zoom, one on Epic. Shared spreadsheet of field labels and which team fills them — not a spreadsheet of secrets.
- Test environment first, always. Promote the same FDI pattern, not a rewritten Production shortcut.
- Decide Patient Admittance Policy with clinicians, not only IT. Automatic entry is faster. Manual admit is the control when a waiting room is the clinical requirement.
- Turn off recording and file transfer at account or group level for visit hosts unless compliance has approved them under the BAA.
- Review @zoomtelevisit.com users on a schedule so leftover provider shells do not accumulate.
- Do not enable Zoom AI features on visit accounts until eligibility, retention, and BAA coverage are confirmed for those features.
- Keep JWT retired. If someone still has a developer.zoom.us JWT app, treat it as legacy copy-paste history, not production auth.
Frequently asked questions
Does Zoom integrate with Epic FHIR?
Yes. Zoom’s Epic FHIR Marketplace app lets providers launch Zoom video visits from Hyperspace and patients launch from MyChart. Epic remains the clinical system of record. Zoom is the video layer.
Is this the same as Zoom’s older Epic app?
No. Zoom documents two listings: Epic FHIR (KB0069113) and the older Epic integration (KB0069029). Search Marketplace for Epic FHIR. If the configuration page shows Encryption Key and Encryption Secret, you are on the non-FHIR listing.
Do I still use JWT for Zoom Epic FHIR?
No. Zoom deprecated JWT authentication in September 2023. An account admin should migrate the Epic FHIR app to OAuth from Marketplace Added Apps by clicking Update and authorizing the requested permissions.
Do we need a Business Associate Agreement?
Zoom’s Epic FHIR requirements include a signed BAA for HIPAA-enabled compliance, plus a paid Zoom account and an admin who can add the app. A signed BAA does not by itself make the whole environment HIPAA compliant.
Where does the provider launch the visit?
From Hyperspace, using the Provider FDI launch. Zoom creates the meeting on behalf of the encounter provider, or the first provider who joins if that person is different. The provider is the host and joins when the visit starts.
Where does the patient join?
From MyChart on a computer or mobile device. If the provider has not joined, Zoom shows a wait-for-host screen. After the provider joins, Patient Admittance Policy either admits the patient automatically or requires the provider to admit them.
Why unlock Join before host and Waiting Room?
The Epic FHIR integration requires those two account-level Meeting settings to remain unlocked so the integration can control wait and admit behavior. Unlocking is not the same as turning them on for every ordinary meeting.
Are patient Zoom accounts permanent?
Zoom describes temporary Zoom user accounts created for patients from Epic FDI data. Provider accounts created by the integration are identified by emails ending in @zoomtelevisit.com and can be deleted manually in User Management. Confirm current patient-account lifecycle in Zoom’s live article before writing it into policy.
How do we diagnose a missing patient-joined indicator?
Hyperspace shows a green light when the patient joins. If it does not, open Notification Records on the Epic FHIR app, search by Zoom meeting ID or encounter CSN, and check RespCode. 200 means Epic handled the notification. Anything else usually means the Telehealth Base URL, IP allow list, or FDI records.
Is Zoom Epic FHIR FedRAMP authorized or CMMC Level 2 certified?
This article does not claim that. Epic FHIR is a commercial healthcare integration. Government-cloud and CUI questions belong on a separate Zoom environment decision, not on this Marketplace app. See Zoom, Zoom for Government and CMMC.
Related articles
- Zoom AI Companion in 2026: what it includes and how to deploy it — a BAA on Meetings does not automatically clear AI features for a clinical visit. Confirm eligibility before you turn them on.
- Does Zoom use your meetings to train AI? — what Zoom’s no-training terms cover, and what they do not.
- Zoom, Zoom for Government and CMMC: which one do you actually need? — commercial healthcare Zoom is not a government-cloud authorization. Do not treat this FHIR app as FedRAMP or CMMC L2.
- Why does Zoom keep freezing? — when the launch worked and the media path did not.
- Zoom + Microsoft Teams: Complete Integration Guide — a different Zoom integration problem; do not mix Teams PSTN architectures into an Epic FHIR build.
- SIP ALG, QoS and DSCP for Zoom Phone — firewall and marking notes that still matter for real-time media, even when the visit launched from MyChart.
References
First-party Zoom pages, verified 28 August 2026. Labels, OAuth migration, and HIPAA contract language change; the current vendor page controls. No patient data, org URLs, or credentials are reproduced here.
- Zoom — Using Zoom’s Epic FHIR integration (KB0069113)— retrieved 28 August 2026; Zoom dateModified 14 July 2026. Source for FHIR field labels, OAuth Update path, unlocked Join before host and Waiting Room, FDI launch types, Patient Admittance Policy behavior, temporary patient accounts, SMS links, Notification Records / RespCode 200, AES-256, dynamic passwords, and @zoomtelevisit.com provider accounts.
- Zoom — Using Zoom’s Epic integration (KB0069029)— retrieved 28 August 2026; Zoom dateModified 26 August 2026. The older non-FHIR listing. Use it only to recognize Encryption Key / Encryption Secret and to avoid configuring the wrong app. JWT deprecation note (September 2023) also appears here.
- Zoom App Marketplace — Health care category— live listings including Epic FHIR and Epic. Search Epic FHIR rather than assuming a bookmarked app ID.
- Zoom Developers — JWT app type FAQ— JWT end of support; migrate to OAuth. Linked from Zoom’s Epic articles as the September 2023 deprecation notice.
- Zoom — Health data and HIPAA-ready / BAA— contractual BAA path. Does not, by itself, certify a customer environment.
- Zoom — Network firewall or proxy server settings (KB0060548)— current Zoom address ranges for notification allow lists. Do not copy a stale IP table into a runbook.
- Zoom — Allowing participants to join before host (KB0060501)— the account setting the FHIR article requires unlocked.
- Zoom — Using Waiting Room (KB0063329)— the Security setting the FHIR article requires unlocked.
Managed Zoom and healthcare voice/video deployments, SDVOSB. We keep Epic as the chart, Zoom as the video layer, OAuth on the Marketplace app, and Test signed off before Production URLs ever go live. We do not put secrets, patient names, or production org URLs in working notes that leave the tenant. Support: (888) 989-4872 · support@adampulse.us