ADAM PULSE Knowledge Base
Zoom Administration · Epic FHIR · Telehealth · HIPAA

Zoom Epic FHIR Integration: Deployment Guide, User Experience, Best Practices and Troubleshooting

Short answer

Epic remains the clinical system of record. Zoom is the video layer. Providers launch from Hyperspace. Patients launch from MyChart. Nurses and inpatient rooms have their own launches. Device test is a separate launch. SMS can carry a telehealth join link. Authenticate with OAuth, not JWT — Zoom deprecated JWT in September 2023.

This is a deployment guide, not a product brochure. Field labels below come from Zoom’s current Epic FHIR article. Do not paste API keys, secrets, private keys, org IDs, or real Epic URLs into tickets, emails, or this page. Do not invent field names from memory.

Screenshots

This article does not embed screenshots. Use Zoom’s official Epic FHIR Marketplace listing and support article, or captures from your own authorized Test environment. Do not publish production Hyperspace or MyChart screens. Tables and workflow lists below stand in for screen tours.

Verification date

Field labels, launch types, and account-level unlocks were checked on 28 August 2026 against Zoom KB0069113 (Epic FHIR; Zoom last modified 14 July 2026), KB0069029 (older Epic listing; Zoom last modified 26 August 2026), Zoom’s JWT FAQ, Zoom’s HIPAA-ready page, and the Zoom App Marketplace healthcare category. Zoom and Epic change labels. The live Marketplace configuration page controls.

What this integration is

Zoom video links sit on the video-visit appointment. The clinician documents in Epic. The visit media runs in Zoom. Zoom’s FHIR article states that meetings are created on behalf of the encounter provider, or the first provider who joins if that person is different. The integration can create temporary Zoom user accounts for patients, and providers can send telehealth meeting links by SMS.

There are two Zoom Marketplace listings. Search for Epic FHIR. The older listing is titled Epic and is documented separately. If the configuration page shows Encryption Key and Encryption Secret, you are not on the FHIR app. Stop and switch listings before anyone copies values into Epic.

Who launches from where. Epic owns the chart. Zoom owns the session.
Role Launch surface Zoom FHIR launch type What success looks like
Provider Hyperspace Provider launch Host joins; chart stays in Epic; patient-joined indicator can light
Patient MyChart, desktop or mobile Patient launch Wait-for-host if early; then auto-join or manual admit per policy
Nurse / clinical staff Hyperspace Nurse launch Staff join the same encounter session without becoming a second clinical chart
Inpatient room Zoom Rooms Zoom Room launch Named room joins the encounter as the in-room endpoint
Pre-visit check Device test flow Device test launch Camera, speaker, and network check before the scheduled visit

Requirements

Zoom’s Epic FHIR article lists:

You also need working Epic endpoints for this app, supplied by your Epic team — not invented here:

Coordinate four groups before anyone clicks Add: Zoom admin, Epic ambulatory / technical services, network / firewall (notifications originate from Zoom address space), and privacy / compliance (BAA, recording policy, AI features). Clinical champions own the test matrix, not the Marketplace form.

BAA is necessary, not sufficient

Zoom’s HIPAA-ready materials describe a BAA as the contractual path for HIPAA-enabled use of covered Zoom services. Signing it does not make every Zoom feature, every AI add-on, every recording setting, or every workstation HIPAA compliant by itself. Confirm which services the BAA covers, lock meeting features you do not want on a visit (recording, annotation, file transfer), and keep PHI out of chat titles and SMS bodies. See Zoom AI Companion in 2026 before turning AI on for clinical visits.

OAuth, not JWT

Zoom deprecated JWT authentication in September 2023. The Epic FHIR article tells an account admin to migrate from Marketplace: Manage → Added Apps → Epic FHIR → Update, then authorize the requested permissions. When that finishes, you return to the Epic FHIR Marketplace page.

The FHIR configuration page still has a Zoom API Key field. That is a label on the form, not permission to keep JWT as the live auth method. Do not paste the key, the app secret, or the private key into this article, a public ticket, or a screenshot gallery.

Zoom’s FHIR notes also say: if you Regenerate the API Key field on the Epic FHIR configuration page, you must add the acc_id URL parameter to FDI records. Existing customers who have not regenerated can continue with org_id only. Confirm which state you are in before rewriting FDI URLs.

Deployment phases

  1. Coordinate teams. Name Zoom admin, Epic TS, network, compliance, and a clinical tester. Agree Test versus Production. Do not point Production URLs at a Test Zoom app or the reverse.
  2. Marketplace install. Sign in to the Zoom App Marketplace as the account administrator. Search Epic FHIR. Open that listing. Click Add. Confirm permissions. Click Allow. The installer opens the configuration page.
  3. Configure field labels only from the live form. Fill values from Epic and Zoom credentials stores. Never paste secrets into chat, email, or a knowledge-base draft.
  4. Unlock two account-level Meeting settings. Join before host and Waiting Room must remain unlocked so the integration can drive wait and admit behavior.
  5. Build FDI records in Epic. One record per launch type you will actually use. URL and CONTEXT live in Installation Mnemonic Values. Pull the current mnemonic strings from Zoom KB0069113 — do not copy a blog post.
  6. Run the test matrix in Test. Provider-first, patient-first, MyChart desktop, MyChart mobile, nurse, room if in scope, device test, SMS link, and Notification Records for the patient-joined indicator.
  7. Promote to Production only after Test is signed off, with Epic Environment set to Production and Production base URLs — not a relabeled Test client.

Marketplace field labels (Epic FHIR)

These labels are from Zoom KB0069113 as retrieved 28 August 2026. If your form differs, trust the form. This table is labels and purpose — not sample values.

Zoom Epic FHIR configuration field labels. Do not paste secrets into tickets or this page.
Field label Required? What it is for Do not
Zoom API Key Yes Identifies the Zoom side of the integration; also referenced as org_id on FDI URLs Share with third parties; paste into email or screenshots
Zoom App Secret Yes Client secret Zoom provides when enabling the Zoom app in App Orchard Invent a value; reuse a JWT API Secret from a different listing
Zoom App Private Key Yes Value from the privatekey.pem file Zoom provides for App Orchard enablement Commit the PEM to git or attach it to a public ticket
Epic FHIR R4 Base URL Yes Base URL where this Epic instance exposes FHIR R4 endpoints Paste a real org URL into public docs; mix Test and Production hosts
Epic Telehealth Base URL Yes Base URL for Epic 2020 telehealth endpoints; also used for join/leave notifications Guess the path; skip allow-listing Zoom notification source IPs
Epic OAuth Base URL Optional Epic FHIR authorization server; Zoom says it can skip a remote lookup at launch Treat blank as a defect if Epic has not given you one
Epic Environment Yes Test or Production. Must match the Epic instance behind those base URLs Set Production against a Test host “just to try it”
Patient Admittance Policy Yes After the provider joins: automatic entry versus provider-manual admit Assume Waiting Room UI in Zoom is the only control; this policy is the integration’s admit rule
Provider User Type Yes Zoom user type assigned when the integration creates a provider account that did not already exist Leave unlicensed if those providers will host visits
Epic Device Test Endpoint URL Optional Where device-test results are posted Skip the device-test launch if you still promised patients a pre-visit check
Healthcare Provider Device Test Help URL Optional Help page during device test Point this at an internal wiki patients cannot open

Save Changes on that page when the labels are filled from your credential store. Then unlock the two account settings.

Unlock Join before host and Waiting Room

Zoom web portal, as an admin who can edit account settings: Account Management → Account Settings → Meetings tab. Zoom requires these two settings to remain unlocked:

Unlocked means the Epic FHIR app can set visit behavior. It does not mean every standing Zoom meeting in the tenant should let guests in early. Keep ordinary meeting policy locked at group or user level where you still need it. Visit admit behavior is then governed by Patient Admittance Policy on the FHIR app.

Zoom’s Usage section: if the patient launches before the provider, they see a loading screen that says they should wait for the host to start the meeting. After the provider joins, they either enter automatically or wait to be admitted, depending on that policy.

FDI records

The FHIR integration is used by configuring FDI records for each launch type. Each record has a URL string for a Zoom API on applications.zoom.us/epicfhir/ and a CONTEXT string that identifies the encounter and participants. Zoom tells you to enter those in Installation Mnemonic Values: URL field and CONTEXT field.

Launch path names Zoom currently documents (append your own org_id and, when required, acc_id — do not copy anyone else’s):

Epic FHIR launch path names. Get current URL and CONTEXT mnemonic strings from Zoom KB0069113.
Launch type Path name CONTEXT parameter names Zoom lists
Provider (Hyperspace) providerlaunch epicSessionId, firstName, lastName, epicUserId, useProviderZoomAccount, noRedirect
Nurse (Hyperspace) nurselaunch epicSessionId, firstName, lastName, epicProviderId, useProviderZoomAccount, noRedirect
Patient (MyChart) patientlaunch epicSessionId, epicUserId, firstName, lastName, encounterProviderId, useProviderZoomAccount, noRedirect
Zoom Room (in-patient) zoomroomlaunch epicSessionId, epicProviderId, useProviderZoomAccount, roomName, roomDisplay, noRedirect
Device test devicetest epicSessionId, epicUserId, firstName, lastName

Copy the live mnemonic strings from Zoom’s article into Epic. Do not type example CSNs, user IDs, room names, or email addresses into this page. Do not use patient names in test scripts that leave the Test environment.

User experience

Provider

Open the telehealth appointment in Hyperspace and launch. The provider is host and joins when the visit starts. Documentation stays in Epic. If Patient Admittance Policy is manual admit, the provider admits the waiting patient. Hyperspace can show a green light when the patient has joined — that light is a notification, not the video stack itself.

Patient

Find the appointment in MyChart and launch on a computer or a phone. Early joiners wait for the host. After the provider is in, policy either drops them into the session or holds them for admit. Zoom states patients can rejoin while the provider is still in the session. SMS is a separate delivery path for the telehealth link; treat the SMS body as operational, not a place for diagnoses or identifiers you would not put on a postcard.

Nurse and inpatient Zoom Rooms

Nurse launch is the Hyperspace path for staff who are not the encounter provider. Zoom Room launch is the in-patient / monitor path: the room name and display name in CONTEXT select the room. Test the physical room on the same encounter the clinic will use, not a leftover Zoom Room from a conference calendar.

Temporary accounts

Zoom creates Zoom user accounts for patients and providers from FDI data. Patient accounts are described as temporary. Provider accounts created this way are identified by emails ending in @zoomtelevisit.com; an admin can delete them under User Management → Users. If you set useProviderZoomAccount so an existing Zoom login is used instead, that is a different identity path — test it explicitly.

Test matrix

Run this in the Epic Test environment with Epic Environment set to Test. No production charts. No real patient names in recordings or tickets.

Minimum Epic FHIR test matrix before Production.
Case Who launches first Pass if If it fails, look at
Provider first, desktop MyChart Provider, then patient on a computer Host in session; patient joins per admit policy; green light if you use it Provider FDI URL/CONTEXT; Telehealth Base URL; Notification Records
Patient first, desktop MyChart Patient, then provider Wait-for-host screen; then auto-join or manual admit matches policy Unlocked join-before-host / Waiting Room; Patient Admittance Policy
Patient first, mobile MyChart Patient on a phone, then provider Same wait and admit behavior as desktop; audio/video usable Client install/permissions; network; device test launch
Nurse join Provider in session, nurse launches Nurse in the same encounter session Nurse FDI record, not a second Provider record
Zoom Room Room launch for an inpatient encounter Correct room; display name matches; OAuth scopes for Rooms if you just migrated from JWT roomName / roomDisplay; Marketplace Update for OAuth; Rooms license
Device test Patient or clinic workstation before the visit Test completes; optional result URL receives the result devicetest FDI; Device Test Endpoint URL; Help URL reachability
SMS link Provider sends the telehealth link Patient can open the visit without a second Epic login maze you did not design SMS feature eligibility; link expiry; do not put PHI in the message body
Patient-joined indicator Patient joins while provider is in Hyperspace Green light; Notification Records RespCode 200 for that meeting or CSN Telehealth Base URL; Zoom notification IPs on the allow list; FDI

Security

Zoom’s Epic FHIR Data Security section states:

What Zoom says it reads from Zoom: provider first and last name for display, and account-wide meeting settings when creating the visit. What Zoom says it reads from Epic: session ID, Epic user ID, Epic provider ID, encounter provider ID, names used to create Zoom accounts, provider email when using an existing Zoom account, and Zoom Room name for room visits. That is encounter and identity context for launch and notifications. It is still PHI in your environment. Keep it in Epic and Zoom. Do not copy it into this knowledge base.

This integration is commercial healthcare Zoom. It is not a FedRAMP authorization and not a CMMC Level 2 certification of your organization. If the real requirement is CUI or a government Zoom environment, start with Zoom, Zoom for Government and CMMC and do not assume Epic FHIR is available or authorized there.

Troubleshooting

Patient-joined indicator (green light)

Hyperspace shows a green light when the patient joins. When that light is wrong, Zoom tells you to use Notification Records:

  1. Sign in to the Zoom App Marketplace as the account administrator.
  2. Manage → Epic FHIR → Configure → Notification Records.
  3. Search by Zoom meeting ID or the encounter CSN.
  4. Each row is a notification Zoom sent to Epic (join/leave). RespCode 200 means Epic handled it. Any other value means the notification did not land cleanly, which is why the indicator lies.

Then check, in order: Epic Telehealth Base URL, IP allow list for Zoom notification sources (current list on Zoom’s network firewall / proxy article — do not freeze an old IP table here), and FDI records. Contact Zoom Support if those three are correct and RespCode is still not 200.

Launch fails or wrong host

Video or audio is the complaint

If Hyperspace launched and Notification Records are 200, the integration did its job. Frozen video and robotic audio are network path problems: packet loss, jitter, Wi-Fi, VPN. Use Why does Zoom keep freezing? rather than rebuilding FDI records.

Best practices

Frequently asked questions

Does Zoom integrate with Epic FHIR?

Yes. Zoom’s Epic FHIR Marketplace app lets providers launch Zoom video visits from Hyperspace and patients launch from MyChart. Epic remains the clinical system of record. Zoom is the video layer.

Is this the same as Zoom’s older Epic app?

No. Zoom documents two listings: Epic FHIR (KB0069113) and the older Epic integration (KB0069029). Search Marketplace for Epic FHIR. If the configuration page shows Encryption Key and Encryption Secret, you are on the non-FHIR listing.

Do I still use JWT for Zoom Epic FHIR?

No. Zoom deprecated JWT authentication in September 2023. An account admin should migrate the Epic FHIR app to OAuth from Marketplace Added Apps by clicking Update and authorizing the requested permissions.

Do we need a Business Associate Agreement?

Zoom’s Epic FHIR requirements include a signed BAA for HIPAA-enabled compliance, plus a paid Zoom account and an admin who can add the app. A signed BAA does not by itself make the whole environment HIPAA compliant.

Where does the provider launch the visit?

From Hyperspace, using the Provider FDI launch. Zoom creates the meeting on behalf of the encounter provider, or the first provider who joins if that person is different. The provider is the host and joins when the visit starts.

Where does the patient join?

From MyChart on a computer or mobile device. If the provider has not joined, Zoom shows a wait-for-host screen. After the provider joins, Patient Admittance Policy either admits the patient automatically or requires the provider to admit them.

Why unlock Join before host and Waiting Room?

The Epic FHIR integration requires those two account-level Meeting settings to remain unlocked so the integration can control wait and admit behavior. Unlocking is not the same as turning them on for every ordinary meeting.

Are patient Zoom accounts permanent?

Zoom describes temporary Zoom user accounts created for patients from Epic FDI data. Provider accounts created by the integration are identified by emails ending in @zoomtelevisit.com and can be deleted manually in User Management. Confirm current patient-account lifecycle in Zoom’s live article before writing it into policy.

How do we diagnose a missing patient-joined indicator?

Hyperspace shows a green light when the patient joins. If it does not, open Notification Records on the Epic FHIR app, search by Zoom meeting ID or encounter CSN, and check RespCode. 200 means Epic handled the notification. Anything else usually means the Telehealth Base URL, IP allow list, or FDI records.

Is Zoom Epic FHIR FedRAMP authorized or CMMC Level 2 certified?

This article does not claim that. Epic FHIR is a commercial healthcare integration. Government-cloud and CUI questions belong on a separate Zoom environment decision, not on this Marketplace app. See Zoom, Zoom for Government and CMMC.

References

First-party Zoom pages, verified 28 August 2026. Labels, OAuth migration, and HIPAA contract language change; the current vendor page controls. No patient data, org URLs, or credentials are reproduced here.

  1. Zoom — Using Zoom’s Epic FHIR integration (KB0069113)— retrieved 28 August 2026; Zoom dateModified 14 July 2026. Source for FHIR field labels, OAuth Update path, unlocked Join before host and Waiting Room, FDI launch types, Patient Admittance Policy behavior, temporary patient accounts, SMS links, Notification Records / RespCode 200, AES-256, dynamic passwords, and @zoomtelevisit.com provider accounts.
  2. Zoom — Using Zoom’s Epic integration (KB0069029)— retrieved 28 August 2026; Zoom dateModified 26 August 2026. The older non-FHIR listing. Use it only to recognize Encryption Key / Encryption Secret and to avoid configuring the wrong app. JWT deprecation note (September 2023) also appears here.
  3. Zoom App Marketplace — Health care category— live listings including Epic FHIR and Epic. Search Epic FHIR rather than assuming a bookmarked app ID.
  4. Zoom Developers — JWT app type FAQ— JWT end of support; migrate to OAuth. Linked from Zoom’s Epic articles as the September 2023 deprecation notice.
  5. Zoom — Health data and HIPAA-ready / BAA— contractual BAA path. Does not, by itself, certify a customer environment.
  6. Zoom — Network firewall or proxy server settings (KB0060548)— current Zoom address ranges for notification allow lists. Do not copy a stale IP table into a runbook.
  7. Zoom — Allowing participants to join before host (KB0060501)— the account setting the FHIR article requires unlocked.
  8. Zoom — Using Waiting Room (KB0063329)— the Security setting the FHIR article requires unlocked.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed Zoom and healthcare voice/video deployments, SDVOSB. We keep Epic as the chart, Zoom as the video layer, OAuth on the Marketplace app, and Test signed off before Production URLs ever go live. We do not put secrets, patient names, or production org URLs in working notes that leave the tenant. Support: (888) 989-4872 · support@adampulse.us