{"id":2729,"date":"2026-08-18T17:00:13","date_gmt":"2026-08-18T17:00:13","guid":{"rendered":"https:\/\/www.microteklearning.com\/blog\/?p=2729"},"modified":"2026-08-18T17:14:05","modified_gmt":"2026-08-18T17:14:05","slug":"smart-on-fhir-explained","status":"publish","type":"post","link":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/","title":{"rendered":"SMART on FHIR Explained: How Apps Actually Get Built on Top of EHRs"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"538\" src=\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-1024x538.png\" alt=\"SMART on FHIR explained, Microtek Learning healthcare IT blog banner\" class=\"wp-image-2730\" srcset=\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-1024x538.png 1024w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-300x158.png 300w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-150x79.png 150w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-768x403.png 768w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-440x231.png 440w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner-680x357.png 680w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-banner.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>If you have ever wondered how a third party app shows up inside Epic or Oracle Health and reads patient data without the hospital handing over database credentials, the answer is SMART on <a href=\"https:\/\/www.microteklearning.com\/blog\/hl7-fhir-certification\/\" target=\"_blank\" rel=\"noreferrer noopener\">FHIR<\/a>. It is an open standard that combines FHIR APIs with OAuth 2.0 authorization so apps can plug into electronic health records securely, with the patient&#8217;s or clinician&#8217;s permission, and without custom integration work for every single EHR.<\/p>\n\n\n\n<p>That one paragraph is the elevator pitch. The rest of this guide unpacks how it works, what the launch flows look like in practice, where the standard is showing up in the real world, and how to build the skills to work with it. It is written for developers, interface analysts, and health IT professionals who keep seeing &#8220;SMART on FHIR experience preferred&#8221; in job listings and want to know what they are actually signing up for.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"First_untangle_the_acronym\"><\/span>First, untangle the acronym<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>SMART stands for Substitutable Medical Applications, Reusable Technologies. The name came out of a project at Boston Children&#8217;s Hospital and Harvard Medical School around 2010, back when the idea of an &#8220;app store for health&#8221; sounded ambitious bordering on naive. The original vision was simple: what if health apps worked like smartphone apps? Write once, run anywhere, swap one out for another without a six. month integration project.<\/p>\n\n\n\n<p>FHIR (Fast Healthcare Interoperability Resources) is HL7&#8217;s modern data standard. It defines how health data is structured and exposed through RESTful APIs. A Patient resource looks the same whether it comes from Epic, Oracle Health, MEDITECH, or a startup EHR nobody has heard of yet.<\/p>\n\n\n\n<p>Here is the thing people miss: FHIR by itself only answers the question &#8220;what does the data look like and how do | request it?&#8221; It says nothing about who is allowed to ask. SMART on FHIR fills that gap. It layers OAuth 2.0 and OpenID Connect on top of FHIR so there is a standard way for an app to say &#8220;I am this app, acting for this user, and | want permission to read these specific things.&#8221;<\/p>\n\n\n\n<p>So when someone says SMART on FHIR, read it as: FHIR for the data, SMART for the security and launch handshake.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_FHIR_alone_was_never_enough\"><\/span>Why FHIR alone was never enough<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>Imagine you build a beautiful medication adherence app. It reads a patient&#8217;s med list and flags risky interactions. To work, it needs three things from the EHR: proof of who the user is, permission to read medication data, and context about which patient is on screen.<\/p>\n\n\n\n<p>Without a standard for those three things, every EHR vendor invents its own answer. You end up writing one authentication flow for Epic, another for Oracle Health, a third for Athenahealth, and by then your startup has burned its runway on integration plumbing instead of the actual product. This is not a hypothetical. It is what health tech looked like for most of the 2000s and early 2010s, and it is a big part of why so many promising clinical apps died quietly.<\/p>\n\n\n\n<p>SMART on FHIR standardized the handshake. One authorization pattern, one way to receive patient context, one way to request permissions. The US government then gave it teeth: the 21st Century Cures Act and the ONC certification rules require certified EHRs to support SMART&#8217;s app launch framework and FHIR R4 APIs. That regulatory push is why every major EHR in the US market now exposes a SMART-capable endpoint, and it is why the standard matters to your career even if you never write a line of app code yourself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_building_blocks\"><\/span>The building blocks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>Four pieces do most of the work. None of them were invented for healthcare, which is exactly the point. SMART borrowed boring, battle tested web standards instead of inventing new ones.<\/p>\n\n\n\n<p>OAuth 2.0 handles authorization. It is the same protocol running behind &#8220;Sign in with Google&#8221; on half the internet. The app never sees the user&#8217;s EHR password. Instead it gets redirected to the EHR&#8217;s own login page, the user approves the request, and the app receives a short lived access token.<\/p>\n\n\n\n<p>OpenID Connect sits on top of OAuth and handles identity. It answers &#8220;who is this user?&#8221; with a signed ID token, so the app knows it is dealing with Dr. Chen and not an anonymous session.<\/p>\n\n\n\n<p>Scopes define what the app can touch. A scope like <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">patient\/OQbservation.read<\/mark> means &#8220;read observations for the patient currently in context, and nothing else.&#8221; Scopes are the permission slips of the whole system, and we will come back to them.<\/p>\n\n\n\n<p>Launch context solves a problem unique to clinical software. When a cardiologist opens an app from inside a patient chart, the app should already know which patient, which encounter, sometimes which clinician. SMART passes that context along during the launch handshake so the user never has to search for the patient a second time. Small detail, huge deal for clinical usability.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_two_launch_flows_in_plain_language\"><\/span>The two launch flows, in plain language<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>Every SMART app starts life in one of two ways, and understanding the difference is the single most useful piece of knowledge for interviews, certification exams, and actual work.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"437\" src=\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-1024x437.png\" alt=\"Four step diagram of the SMART on FHIR EHR launch flow: launch, authorize, token, FHIR calls\" class=\"wp-image-2732\" srcset=\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-1024x437.png 1024w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-300x128.png 300w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-150x64.png 150w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-768x328.png 768w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-440x188.png 440w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step-680x290.png 680w, https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir-the-ehr-launch-flow-step-by-step.png 1500w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><em>The EHR launch flow in four steps. Standalone launch uses the same standards from a different starting point.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"EHR_launch\"><\/span>EHR launch<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>This is the flow where the app lives inside the EHR. A clinician is charting, clicks a button or tab, and the app opens embedded in the workflow, already pointed at the right patient.<\/p>\n\n\n\n<p>Under the hood, the sequence goes like this. The EHR fires off a launch request to the app with two parameters: a <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">launch<\/mark> token and the <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">iss<\/mark> value, which is the FHIR server&#8217;s base URL. The app calls the server&#8217;s discovery endpoint (<mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">.wel1-known\/smart-configuration<\/mark>) to find the authorization and token URLs. It then redirects to the EHR&#8217;s authorization server, presenting the launch token and the scopes it wants. The user approves, or the health system has pre-approved the app, and the authorization server sends back an authorization code. The app exchanges that code for an access token, and along with the token it receives the context: patient ID, encounter ID, whatever was granted. From that point on, the app makes normal FHIR API calls with the token attached, and the EHR&#8217;s server enforces the scopes.<\/p>\n\n\n\n<p>Read that sequence twice and you know more about SMART than most people who mention it on their resume.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Standalone_launch\"><\/span>Standalone launch<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>Here the app starts outside the EHR. Think of a patient opening a diabetes tracking app on their phone. There is no EHR screen open and no launch token, so the app itself asks the user which provider they belong to, connects to that organization&#8217;s FHIR endpoint, and walks through the same OAuth authorization dance. The user logs in with their patient portal credentials and consents to sharing. Same standards, same tokens, different starting point.<\/p>\n\n\n\n<p>Standalone launch is the machinery behind patient access apps, the kind mandated by CMS rules that require payers and providers to let patients pull their own records into apps they choose. If you have connected a personal health app to your hospital&#8217;s MyChart account, you have used a standalone SMART launch, whether you knew it or not.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Scopes_the_part_everyone_underestimates\"><\/span>Scopes, the part everyone underestimates<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>Scopes look simple and cause a disproportionate share of real world integration pain, so they deserve their own section.<\/p>\n\n\n\n<p>A SMART scope has three parts: context, resource, and permission. <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">patient\/Observation.read<\/mark> breaks down as patient level context, Observation resources, read access. <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">user\/Practitioner.read<\/mark> means the app can read practitioner records that the logged in user is allowed to see. <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">system\/*. read<\/mark> is for backend services with no human in the loop at all, like a nightly analytics job pulling data under the SMART Backend Services profile.<\/p>\n\n\n\n<p>Two practical notes from the trenches. First, SMART v2 changed the permission syntax from <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">.read<\/mark> and <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">.write<\/mark> to granular CRUDS letters (. rs for read and search, for example), and you will encounter both versions in the wild for years to come. Second, requesting broad scopes is the fastest way to fail a health system&#8217;s security review. Apps that ask only for what they need get approved faster, which makes lean scope requests a business advantage as much as a security habit.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_building_an_app_actually_looks_like\"><\/span>What building an app actually looks like<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>You do not need a hospital&#8217;s permission to start. That is honestly the best part of this whole ecosystem.<\/p>\n\n\n\n<p>The SMART team maintains a free App Launcher at launch.smarthealthit.org that simulates both launch flows against a synthetic FHIR server loaded with fake patients. You can have a &#8220;hello world&#8221; app pulling patient demographics in an afternoon. Epic&#8217;s open.epic.com and Oracle Health&#8217;s code console both offer free developer sandboxes that mirror their production behavior, which matters because each vendor has quirks the simulator will not show you. Logica Health runs another sandbox popular in training environments.<\/p>\n\n\n\n<p>A typical first project looks like this: register your app with the sandbox to get a client ID, stand up a small web app (the official SMART libraries for JavaScript and Python handle the OAuth ceremony for you), request <mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-secondary-color\">launch, openid, fhirUser,<\/mark> and a patient scope or two, then render something uskful from the patient&#8217;s data. A growth chart. A med list. A lab trend line. The classic SMART demo apps are all variations on this pattern.<\/p>\n\n\n\n<p>From there, the jump to production is less about code and more about process: vendor app review programs, security assessments, and the governance conversations health systems run before anything touches live patient data. Developers who understand that side of the work, not just the API calls, are the ones who get hired to lead these projects.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_SMART_apps_show_up_in_the_real_world\"><\/span>Where SMART apps show up in the real world<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>The app gallery at apps.smarthealthit.org lists dozens of production examples, but the pattern is more interesting than any single app.<\/p>\n\n\n\n<p>Clinical decision support tools are the biggest category. Risk calculators that read the chart instead of making a nurse retype twelve values. Oncology dosing tools. Antibiotic stewardship dashboards. Anything where the value comes from combining live chart data with specialized logic the EHR does not have built in.<\/p>\n\n\n\n<p>Patient facing apps are the second wave, driven by the CMS interoperability rules. Record aggregators, medication managers, and condition specific coaching apps all ride on standalone launch.<\/p>\n\n\n\n<p>There is also a quieter category worth knowing about: SMART&#8217;s sibling standard, CDS Hooks, which lets external services inject suggestion cards directly into the clinician&#8217;s workflow at decision moments, like when a prescription is being written. CDS Hooks and SMART work together; a suggestion card can deep link into a full SMART app when the clinician wants to dig deeper. If you are learning one, learn at least the shape of the other.<\/p>\n\n\n\n<p>And the newest frontier: Al. Health systems piloting large language model tools are using SMART on FHIR as the access layer, because it already solves consented, scoped, auditable access to chart data. The standard written in 2010 turned out to be exactly the plumbing the 2026 Al wave needed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_actually_learn_this_a_realistic_path\"><\/span>How to actually learn this (a realistic path)<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>Here is the sequence that works, based on how interface analysts and developers typically come up to speed.<\/p>\n\n\n\n<p>Start with FHIR fundamentals before touching SMART. You need to be comfortable reading a FHIR resource, understanding references between resources, and making basic REST calls. Without that, the OAuth layer will feel like abstraction stacked on abstraction.<\/p>\n\n\n\n<p>Then work through the SMART App Launch specification alongside the free App Launcher sandbox. Reading the spec without the sandbox is sleep inducing. Using the sandbox without the spec leaves gaps. Together they click.<\/p>\n\n\n\n<p>Build one small app end to end, including both launch flows. Nothing cements the difference between EHR launch and standalone launch like implementing both and watching where they diverge.<\/p>\n\n\n\n<p>Then go deeper on the vendor side. Epic and Oracle Health each have their own developer programs, documentation styles, and review processes, and most US health IT jobs involve at least one of them.<\/p>\n\n\n\n<p>Formal training compresses this timeline considerably. Instructor led HL7 and FHIR courses walk through the specification with hands on labs and give you space to ask the questions that forum threads never quite answer. Microtek Learning offers <a href=\"https:\/\/www.microteklearning.com\/vendor\/health-level-7\/\" target=\"_blank\" rel=\"noreferrer noopener\">HL7 and FHIR training<\/a> built for working IT professionals, with live instructors and lab environments, which is a sensible route if you are making a career move into health IT integration or your team just inherited a FHIR project with a deadline attached. Pairing that witha security credential or a vendor certification rounds out the profile hiring managers in this space look for.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_asked_questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Is_SMART_on_FHIR_a_certification\"><\/span>Is SMART on FHIR a certification?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>No. It is an open technical standard published by HL7. There is no &#8220;SMART certified developer&#8221; credential. What exists are FHIR proficiency exams from HL7, vendor programs from Epic and Oracle Health, and instructor led training courses that teach the standard. On a resume, a portfolio app in a public sandbox often speaks louder than any certificate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Do_I_need_to_be_a_healthcare_expert_to_build_SMART_apps\"><\/span>Do I need to be a healthcare expert to build SMART apps?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>You need working knowledge of web development and OAuth far more than clinical knowledge. That said, the developers who thrive in this space learn enough clinical context to understand why a workflow matters. Knowing what an encounter is, clinically and as a FHIR resource, makes you dramatically more useful.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Does_SMART_on_FHIR_replace_HL7_V2_interfaces\"><\/span>Does SMART on FHIR replace HL7 V2 interfaces?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>No, and it probably will not for years. Hospitals still run thousands of V2 interfaces for lab results, admissions feeds, and billing. SMART on FHIR handles a different job: app integration and user facing data access. Most health systems run both, and professionals who understand both are the safest hire in the room.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Is_SMART_on_FHIR_only_used_in_the_United_States\"><\/span>Is SMART on FHIR only used in the United States?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>The standard is international and adoption is growing globally, but the US has the strongest regulatory mandate through the ONC certification rules. Other countries reference SMART in national programs at varying speeds.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_programming_languages_can_I_use\"><\/span>What programming languages can I use?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>Any language that can make HTTPS calls. Official client libraries exist for JavaScript and Python, and community libraries cover C#, Java, Ruby, and others. The standard itself is language agnostic.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_bottom_line\"><\/span>The bottom line<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>SMART on FHIR is not exotic technology. It is OAuth, REST, and JSON arranged so that health apps can plug into EHRs the way normal apps plug into normal platforms. That ordinariness is its superpower, and it is why the standard went from an academic project to a federal requirement in about a decade.<\/p>\n\n\n\n<p>For anyone building a career in health IT, the practical takeaway is this: FHIR knowledge gets you into the conversation, and SMART on FHIR knowledge lets you ship something. The sandboxes are free, the spec is public, and the demand side of the job market is not slowing down.<\/p>\n\n\n\n<p>If you want structured, instructor led training to get there faster, explore Microtek Learning&#8217;s <a href=\"https:\/\/www.microteklearning.com\/hl7-fundamentals-training\/\" target=\"_blank\" rel=\"noreferrer noopener\">HL7<\/a> and <a href=\"https:\/\/www.microteklearning.com\/fhir-training\/\" target=\"_blank\" rel=\"noreferrer noopener\">FHIR training<\/a> and talk to a training advisor about the path that fits your role.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What SMART on FHIR is, how EHR and standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.<\/p>\n","protected":false},"author":3,"featured_media":2731,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[68],"tags":[],"class_list":["post-2729","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-health-level-7"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SMART on FHIR Explained: Building Apps on Top of EHRs<\/title>\n<meta name=\"description\" content=\"What SMART on FHIR is, how EHR &amp; standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SMART on FHIR Explained: Building Apps on Top of EHRs\" \/>\n<meta property=\"og:description\" content=\"What SMART on FHIR is, how EHR &amp; standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\" \/>\n<meta property=\"og:site_name\" content=\"IT Training Blog \u2013 Certifications, Cloud &amp; Cybersecurity\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-18T17:00:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T17:14:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kelly Bishop\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kelly Bishop\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\"},\"author\":{\"name\":\"Kelly Bishop\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#\/schema\/person\/d80907157e1a8cf279c8c617f6ab8a76\"},\"headline\":\"SMART on FHIR Explained: How Apps Actually Get Built on Top of EHRs\",\"datePublished\":\"2026-08-18T17:00:13+00:00\",\"dateModified\":\"2026-08-18T17:14:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\"},\"wordCount\":2521,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png\",\"articleSection\":[\"Health Level 7\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\",\"url\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\",\"name\":\"SMART on FHIR Explained: Building Apps on Top of EHRs\",\"isPartOf\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png\",\"datePublished\":\"2026-08-18T17:00:13+00:00\",\"dateModified\":\"2026-08-18T17:14:05+00:00\",\"description\":\"What SMART on FHIR is, how EHR & standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage\",\"url\":\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png\",\"contentUrl\":\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png\",\"width\":1080,\"height\":1080,\"caption\":\"SMART on FHIR\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.microteklearning.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SMART on FHIR Explained: How Apps Actually Get Built on Top of EHRs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#website\",\"url\":\"https:\/\/www.microteklearning.com\/blog\/\",\"name\":\"Microtek Learning\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#organization\"},\"alternateName\":\"IT Training Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.microteklearning.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#organization\",\"name\":\"Microtek Learning\",\"url\":\"https:\/\/www.microteklearning.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/02\/PNG.png\",\"contentUrl\":\"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/02\/PNG.png\",\"width\":150,\"height\":40,\"caption\":\"Microtek Learning\"},\"image\":{\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#\/schema\/person\/d80907157e1a8cf279c8c617f6ab8a76\",\"name\":\"Kelly Bishop\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.microteklearning.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f10be4837402a68fa50d01abe779925739429e486a7dc1b5bf9ecadc532e0b67?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f10be4837402a68fa50d01abe779925739429e486a7dc1b5bf9ecadc532e0b67?s=96&d=mm&r=g\",\"caption\":\"Kelly Bishop\"},\"description\":\"Kelly Bishop is a Content Writer at Microtek Learning, specializing in IT certification and technology training content. With 10+ years of experience, she writes on topics spanning Microsoft, PECB, ISACA, EC-Council, and CompTIA certification paths. https:\/\/www.linkedin.com\/in\/kelly-bishop2\/\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/kelly-bishop2\/\"],\"url\":\"https:\/\/www.microteklearning.com\/blog\/author\/kelly-bishop\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SMART on FHIR Explained: Building Apps on Top of EHRs","description":"What SMART on FHIR is, how EHR & standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/","og_locale":"en_US","og_type":"article","og_title":"SMART on FHIR Explained: Building Apps on Top of EHRs","og_description":"What SMART on FHIR is, how EHR & standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.","og_url":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/","og_site_name":"IT Training Blog \u2013 Certifications, Cloud &amp; Cybersecurity","article_published_time":"2026-08-18T17:00:13+00:00","article_modified_time":"2026-08-18T17:14:05+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png","type":"image\/png"}],"author":"Kelly Bishop","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kelly Bishop","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#article","isPartOf":{"@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/"},"author":{"name":"Kelly Bishop","@id":"https:\/\/www.microteklearning.com\/blog\/#\/schema\/person\/d80907157e1a8cf279c8c617f6ab8a76"},"headline":"SMART on FHIR Explained: How Apps Actually Get Built on Top of EHRs","datePublished":"2026-08-18T17:00:13+00:00","dateModified":"2026-08-18T17:14:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/"},"wordCount":2521,"commentCount":0,"publisher":{"@id":"https:\/\/www.microteklearning.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png","articleSection":["Health Level 7"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/","url":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/","name":"SMART on FHIR Explained: Building Apps on Top of EHRs","isPartOf":{"@id":"https:\/\/www.microteklearning.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage"},"image":{"@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png","datePublished":"2026-08-18T17:00:13+00:00","dateModified":"2026-08-18T17:14:05+00:00","description":"What SMART on FHIR is, how EHR & standalone launch flows work, scopes, sandboxes, and how to learn it. A practical guide for health IT pros and developers.","breadcrumb":{"@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#primaryimage","url":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png","contentUrl":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/08\/smart-on-fhir.png","width":1080,"height":1080,"caption":"SMART on FHIR"},{"@type":"BreadcrumbList","@id":"https:\/\/www.microteklearning.com\/blog\/smart-on-fhir-explained\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.microteklearning.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SMART on FHIR Explained: How Apps Actually Get Built on Top of EHRs"}]},{"@type":"WebSite","@id":"https:\/\/www.microteklearning.com\/blog\/#website","url":"https:\/\/www.microteklearning.com\/blog\/","name":"Microtek Learning","description":"","publisher":{"@id":"https:\/\/www.microteklearning.com\/blog\/#organization"},"alternateName":"IT Training Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.microteklearning.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.microteklearning.com\/blog\/#organization","name":"Microtek Learning","url":"https:\/\/www.microteklearning.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microteklearning.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/02\/PNG.png","contentUrl":"https:\/\/www.microteklearning.com\/blog\/wp-content\/uploads\/2026\/02\/PNG.png","width":150,"height":40,"caption":"Microtek Learning"},"image":{"@id":"https:\/\/www.microteklearning.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.microteklearning.com\/blog\/#\/schema\/person\/d80907157e1a8cf279c8c617f6ab8a76","name":"Kelly Bishop","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microteklearning.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f10be4837402a68fa50d01abe779925739429e486a7dc1b5bf9ecadc532e0b67?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f10be4837402a68fa50d01abe779925739429e486a7dc1b5bf9ecadc532e0b67?s=96&d=mm&r=g","caption":"Kelly Bishop"},"description":"Kelly Bishop is a Content Writer at Microtek Learning, specializing in IT certification and technology training content. With 10+ years of experience, she writes on topics spanning Microsoft, PECB, ISACA, EC-Council, and CompTIA certification paths. https:\/\/www.linkedin.com\/in\/kelly-bishop2\/","sameAs":["https:\/\/www.linkedin.com\/in\/kelly-bishop2\/"],"url":"https:\/\/www.microteklearning.com\/blog\/author\/kelly-bishop\/"}]}},"_links":{"self":[{"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/posts\/2729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/comments?post=2729"}],"version-history":[{"count":2,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/posts\/2729\/revisions"}],"predecessor-version":[{"id":2735,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/posts\/2729\/revisions\/2735"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/media\/2731"}],"wp:attachment":[{"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/media?parent=2729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/categories?post=2729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microteklearning.com\/blog\/wp-json\/wp\/v2\/tags?post=2729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}