Avaamo Children's Healthcare of Atlanta

Epic proxy authenticationEpic

Knowing who she’s talking to.

Call arrives
1Call
arrives

The incoming phone number is captured and looked up in Epic, bringing back the demographics and any linked proxy accounts.

2Fallback
search

No match on the phone? She collects last name, date of birth and ZIP code, and searches Epic for the record.

3Parent
verified

Identity confirmed against the date of birth and ZIP code on file. Only then is the account authenticated.

4Children
come back

Epic’s RelatedPerson resource returns every proxy account linked to the parent: their children, on their chart.

5Patient
confirmed

The parent names the child and their date of birth; it’s matched to the proxy record before anything proceeds.

Epic
Authenticated
1
Full access0–12 yrs
Policy
Patients under age 13: parents have full access to their child’s MyChart account.
In practice
Schedule, refill and message the care team — the same view the patient would have.
2
Partial access13–17 yrs
Policy
Patients age 13 to 18: teens in this age range may access their own MyChart information with their parent’s or guardian’s consent.
The switch
Parent view downgrades at 13 — sensitive results never reach the proxy.
3
No access18+ yrs
Policy
Patients age 18 and older: patients have full access to their own accounts.
Adult proxy
Parental access disconnects at 18 — restored only by the patient’s grant, or a healthcare power of attorney.

Set by Georgia, applied by policy. “Access to your child’s MyChart account will vary by the age of your child” — Children’s own MyChart proxy policy, enforced on every call. choa.org/patients/mychart

PatientLookup4Find the record

Retrieves the patient’s demographic information from the incoming number, or from the fallback search.

Epic
API type
Epic Private · Class C
First available
February 2023
HTTP method
POST
Web service types
REST, SOAP
User types
Backend systems and non-OAuth 2.0
GetAccountDemographics2018 · fill in the picture

Returns the additional demographics used to verify the caller against what Epic holds on file.

Epic
API type
Epic Private · Class B
Namespace
urn:Epic-com:PatientAccess.2018.Services.Account
First available
February 2023
WSDL file
Epic.PatientAccess.GeneratedServices/Account.svc?wsdl
HTTP method
GET
Web service types
SOAP, REST, REST legacy
OAuth 2.0 user types
Backend systems and non-OAuth 2.0 · clinicians, staff or administrative users · patients
GetPatientIdentifiers2015 · every ID, past and present

Retrieves the patient’s active and historical identifiers, so the right chart is always the one in hand.

Epic
API type
Epic Public
Namespace
urn:Epic-com:Common.2015.Services.Patient
First available
February 2023
WSDL file
Epic.Common.GeneratedServices/Patient.svc?wsdl
HTTP method
POST
Web service types
SOAP, REST, REST legacy
OAuth 2.0 user types
Backend systems and non-OAuth 2.0 · clinicians, staff or administrative users · patients
Note
An active ID must be used in the web service request.
RelatedPerson.SearchFHIR R4 · friends and family · the proxy link

Returns every person with a personal or professional relationship to the patient: parents, guardians, caregivers.

Epic
API type
USCDI
First available
May 2024
HTTP method
GET
Web service types
REST
OAuth 2.0 user types
Backend systems and non-OAuth 2.0 · clinicians, staff or administrative users · patients

All third-party names and logos — Children’s Healthcare of Atlanta, Epic, MyChart, Panviva, Webex by Cisco — are trademarks of their respective owners, shown for identification only. Avaamo is not affiliated with or endorsed by them.