Health information exchange · broker, not a repository

Don't take our word for it. Call it yourself.

Most vendors answer an integration question with a slide. We issue you a scoped credential and a base URL, and you query the running exchange from your own terminal — in about sixty seconds, without talking to anyone.

What you get, immediately a credential scoped to synthetic data only FHIR R4 endpoints and the conformance statement no NDA, no data agreement, no sales call
Your terminal SYNTHETIC DATA ONLY
$ export CC_TOKEN=sbx_live_…
$ curl -s -H "Authorization: Bearer $CC_TOKEN" \
https://carecompile.com/exchange/fhir/Patient?identifier=SIM-847291
{
"resourceType": "Bundle", "type": "searchset",
"total": 1,
"entry": [{ "resource": {
"resourceType": "Patient",
"id": "sim-847291",
"meta": { "tag": [{ "code": "SYNTHETIC" }] }
}}]
}
Every record reachable with this credential is generated by our clinical simulator and tagged SYNTHETIC at the resource level. There is no path from a sandbox token to real data.
01 — WHAT IS OPEN

The machine is public.
The record is not.

You can inspect how the exchange works in as much detail as you like. What stays closed is the clinical content inside it.

01

The sandbox

Sixty seconds

A scoped credential against the live exchange. Safety is a property of the credential itself, not a special demo build — which is why we can hand it to a stranger.

02

The integration spec

Generated, not written

Rendered from the same catalog the automated grader enforces. It is structurally incapable of describing a rule we do not check.

03

The disclosure record

Read-only by construction

Hand a privacy officer the audit trail without handing them the console. There is no write path in the page — not a hidden one, none at all.

Where the
line sits

The exchange runs on open standards and open-source software — HL7 v2, FHIR R4, LOINC, HAPI. We are not pretending the plumbing is secret, and showing you exactly how it is assembled costs us nothing.

What is ours is the clinical vocabulary inside it and the record of every decision that built it. Those are not on this site anywhere, and they will not be.

02 — THE SANDBOX

Three steps, no conversation.

The credential is scoped at issue. That is what makes handing one to a stranger a non-event.

01
Say who you are

Work email and organization. No phone number, no calendar link, no qualification form.

02
Take the credential

Issued on the page. Valid 30 days, rate-limited, scoped to a synthetic participant.

03
Query the exchange

The same endpoints a production participant uses. Not a mock, not a recording.

Credential issuedEXPIRES IN 30 DAYS · 60 REQ/MIN
Base URL
https://carecompile.com/exchange/fhir
Bearer token
sbx_live_7Kq2mWx9pR4tN…
This credential can reach
PatientObservationDiagnosticReport DocumentReferenceCodeSystemValueSet $lookup$validate-code
writeany non-synthetic participant consent registrydisclosure log
What this does not prove

A sandbox proves the interface works, not that we have run at your volume. We have never carried production clinical traffic — every message through this exchange to date is synthetic. If you need a reference site under load, we do not have one yet, and we would rather you learn that here than three meetings in.

03 — INTEGRATION SPEC

This page cannot lie to you.

Not because we are careful. Because of where the text comes from.

How it is
produced

A hand-written specification drifts from the software the moment either changes, and you have no way to detect it from outside. This one renders from the same catalog the automated grader evaluates against, so a rule we do not enforce cannot appear here, and a rule we enforce cannot be missing.

You are not trusting our documentation discipline. You are reading the enforcement itself.

Conformance requirementsSAMPLE ROWS · LIVE PAGE RENDERS ALL
IDRequirementGraded byLevel
CONN-01 Mutual TLS 1.3 on every connection; client certificate pinned to the participant handshake probeREQUIRED
MSG-04 Every inbound message acknowledged before processing; control ID unique per participant per day replay corpusREQUIRED
TERM-02 Lab results carry a LOINC code present and ACTIVE in the published release, or a local code marked as local $validate-codeREQUIRED
TERM-05 Units expressed in UCUM where the observation is quantitative schema checkEXPECTED
IDN-03 Patient identifier namespaced to the assigning authority; no bare MRN match probeREQUIRED
04 — STEWARDSHIP

A queue with things in it is the proof.

An empty review queue does not mean a finished system. It means an unsupervised one.

Synthetic lab results resolved to a concept
66,901of 70,754

The remaining 3,853 are quarantined and visible in the queue below — not lost, not silently guessed at. Figures read live from the platform, as of 7 Sep 2026 05:47 UTC.

Waiting on a human decision
87

Machine-generated proposals a steward has not yet ruled on. This number going up is the system working, not falling behind.

Resolve queueCONTENT REDACTED FOR PUBLICATION
Incoming termTierMatch sourceGate
1exact, release-verifiedMAY AUTO-COMMIT
2vendor default referencePROPOSAL ONLY
3display-name similarityPROPOSAL ONLY
4unrecognizedQUARANTINED
What you can see

The tiers, which tier may commit without a person, what happens to everything else, and how much is waiting right now. The whole mechanism.

What is blocked out

The terms themselves and what they were bound to. That vocabulary is the part that took a year to build and the part a competitor would actually want. It is not on this site anywhere.

The commit rule,
in one sentence

A binding may be written automatically only when the code exists and is ACTIVE in the loaded release and matches exactly. Everything else becomes a proposal that waits for a named person on a dated action, and a result whose code we cannot resolve is quarantined rather than guessed at — then resolved retroactively when a steward finally decides.

05 — DISCLOSURE RECORD

The audit trail, without the console.

What a privacy officer asks for is rarely access. It is evidence.

READ-ONLY BY CONSTRUCTION — this view has no form, no action parameter and no write handler. It is not a permission that could be misconfigured; there is no code path here that changes anything.

WhenReleased toPurposeBasisRecords
2026-09-05 14:22:07Participant 004 — regional clinicTreatmentconsent on file3
2026-09-05 11:48:31Participant 011 — EMS agencyTreatment — emergencybreak-glass1
2026-09-04 09:15:52Participant 002 — critical access hospitalTreatmentconsent on file7
2026-09-04 08:02:19Participant 007 — community pharmacyTreatmentrefused — no consent0
Refusals are recorded too

The fourth row is a request that was denied. A log that only contains successes tells a reviewer nothing about whether the control works.

Per-person accounting

The same record exports for a single individual, which is the form 45 CFR 164.528 actually requires — built as a feature, not assembled by hand on request.

// Synthetic deployment. Participants are numbered, not named, on the public view.

06 — WHAT WE DO NOT CLAIM

The list that costs us deals.

Every vendor has one. Most make you find it out in month three.

Not true of us today

We are not certified under SOC 2, HITRUST or FedRAMP, and there is no such thing as being “HIPAA certified.” We have not run US Core conformance testing against Inferno. We do not have a production cloud deployment. We publish no service-level commitments, because we have never measured against one. And we have never carried real patient data.

If any of those are prerequisites for you, we are not the right fit today. We would rather you close the tab now than discover it during procurement.

Integrating with an exchange? Start by calling ours.

A credential takes a minute and commits you to nothing. If you would rather talk first, that works too — but the credential will tell you more.

Clinical Decision Support Notice — CareCompile is a non-diagnostic clinical decision support tool intended to augment, not replace, physician judgment. All AI-generated analyses are advisory only; clinical decisions remain the sole responsibility of the licensed treating clinician. CareCompile is not FDA-cleared or FDA-approved as a medical device. Every figure on this page is measured on synthetic data in a development environment.