TEFCA Out-of-Network Anticoagulant Discovered
Patient received Apixaban 5 MG (Eliquis) at Northwestern ER on 2026-06-28. This medication is not listed in local Meditech Expanse records.
Vitals & Lab Trends (FHIR Observation)
Active Problems & Conditions (FHIR Condition)
| Condition | SNOMED / ICD-10 | Onset | Source System |
|---|
Prescriptions & Orders (FHIR MedicationRequest)
| Medication | Dosage & Instructions | Status | Prescriber |
|---|
Allergies & Intolerances (FHIR AllergyIntolerance)
| Substance | Reaction | Severity | Source |
|---|
TEFCA Individual Access Services (IAS) 4-Step Exchange Simulator
Identity Status: Unverified (NIST IAL1)
1
Identity Verification (IAL2)
2
MPI Patient Discovery
3
Document Query (XCA)
4
Record Reconciliation
Nationwide Qualified Health Information Networks (QHINs)
OAuth 2.0 PKCE Session Verified & Active
Active Bearer token granted for patient context. Token exchange complete.
Meditech Greenfield vs Epic — Key SMART-on-FHIR Differences
⚠️ client_secret + PKCE — BOTH required
Meditech token POST must include
client_secret AND code_verifier simultaneously. Epic allows one or the other.⏱️ Auth Code TTL: 60 seconds (signed JWT)
Authorization codes are signed JWTs with a strict 60-second TTL. Epic uses opaque codes with a longer window. You must exchange immediately.
🔑 No Self-Service Developer Portal
Credentials are NOT self-provisioned. client_id + client_secret delivered via secure 1Password share link after Meditech application review (vs Epic's instant developer.epic.com registration).
🧑💻 Sandbox Identity = Your Google SSO
Greenfield sandbox uses the developer's registered Google account as the patient context. No separate test patients (unlike Epic's "Jason Argonaut" accounts). The patient
sub is your Google sub.🌐 Shared Single-Tenant Sandbox
One FHIR base URL for all Greenfield developers:
greenfield-prod-apis.meditech.com/v2/uscore/STU6. Epic has per-organization sandbox instances.📋 SMART Well-Known Config
greenfield-prod-apis.meditech.com/v2/uscore/STU6/.well-known/smart-configuration
Meditech Greenfield OAuth 2.0 PKCE Authorization Details
Configured Client Parameters
Current Bearer Token Payload
Token Exchange cURL — client_secret + code_verifier (both required for Meditech)
🏥 Meditech
SMART-on-FHIR OAuth 2.0 Launch Launcher
PKCE Authorization Code Grant Sequence — Meditech Expanse
Target Application & Patient Identity:
MyHealthONE Patient Portal (Client ID: greenfield-f5-demo-client-2024)
Patient Context: Jane Harmon (MT ID: MT-patient-001)
Select OAuth Authorization Mode:
FHIR R4 Raw JSON Resource Inspector
Generated cURL Request:
Clinical AI Copilot — F5 AI Gateway Inline Security & PHI Redaction Proxy
Open Secondary AI Chat Route ↗
Demonstrates how F5 AI Gateway acts as an inline security proxy between clinical web portals and LLM providers (OpenAI, Anthropic, AWS Bedrock). F5 inspects prompts in real-time, redacts Protected Health Information (PHI/PII), blocks prompt injection attacks, and enforces HIPAA compliance.
AI Execution Engine Mode:
Active: Dispatching real HTTP POST requests to F5 AI Gateway
API Route:
Model Catalog:
Auth Header:
Sample SE Demo Prompts (Click chip to populate prompt):
✅ Allowed — PHI redacted inline by F5 before reaching LLM | 🚫 Blocked — CalypsoAI HIPAA guardrail enforcement
Interactive Clinical AI Chatbot
F5 AI Proxy: Active
Clinical AI Copilot (Meditech Expanse): Welcome to MyHealthONE’s AI-assisted clinical portal. All queries are processed inline through F5 AI Gateway for PHI redaction before reaching the LLM. Try the 💡 chips for live PHI redaction demos, or the 🚫 chips to see CalypsoAI HIPAA guardrail enforcement.
F5 AI Gateway Security Inspector
INLINE PROXY
1. Raw User Prompt (Contains Sensitive PHI):
Select or type a prompt to inspect inline redaction...
2. F5 AI Gateway Transformed Prompt (PHI Redacted):
Awaiting prompt execution...
3. F5 AI Security Metrics & Policy Enforcement:
HIPAA PHI / Guardrail Policy:
ENFORCED
PHI Items / Policy Tripped:
0 items
Prompt Injection Defense:
PASSED
Upstream LLM Provider:
llama3.2 via F5 AIGW
Healthcare Multi-Agent Traffic & Bypass Orchestration Engine
F5 Protection: FULL (0 Bypasses)
Sub-Agents: 5 Connected
Analyze component traffic impact across the multi-agent pipeline. Toggle switches below to simulate bypassing security guardrails or sub-agents to compare Latency Saved vs. Security & Compliance Risk in real time.
⚡ Component Traffic Impact & Bypass Simulation Panel
Toggle switches to simulate bypassing traffic components
1. F5 AI Security Gateway (Input Rail)
(PHI Redaction & OWASP Injection Check)
Latency Impact: +180ms
2. Clinical Safety Sub-Agent
(Pharmacology & Drug Interaction Review)
Latency Impact: +220ms
3. F5 AI Security Gateway (Output Rail)
(Response Guardrails & Token Sanitization)
Latency Impact: +90ms
Canned SE Demo Scenarios
1-CLICK DEMO
🟢 Legitimate Clinical Prompts
🚨 Malicious & Adversarial Prompts
Active Prompt Input Payload:
System Traffic Flow & Agent Node DAG
IDLE — READY
🌐 Real-Time Traffic Routing Pipeline Map
STATUS: PROTECTED (FULL RAIL)
1. Clinician / Portal Interface
IDLE
Dispatches clinical request & parameters
Awaiting execution...
2. F5 AI Security Gateway (Input Rail)
IDLE
PHI Redaction • Prompt Injection Check • OAuth JWT Scopes
Inspection pending...
3. Clinical Multi-Agent Orchestrator
IDLE
Decomposes task & routes to sub-agents
Routing queue clear...
FHIR R4 Agent
Meditech Greenfield
TEFCA IAS Agent
QHIN Network
Safety Agent
Drug Knowledge
4. F5 AI Security Gateway (Output Rail)
IDLE
Response Guardrails • HIPAA De-identification Compliance
Output inspection pending...
Synthesized Clinical Response
READY
Click Execute Multi-Agent Workflow above to run live orchestration.
F5 Inspection & Execution Log
REAL-TIME TRACE
Inline Guardrail Inspection
Latency: 0ms
PHI Masked Items:
0 items
Prompt Injection Status:
PASSED
OAuth Scope Grants:
patient/*.read
Agent Hops Dispatched:
0 hops
Chronological Agent Execution Trace:
00:00.000
System Ready
Multi-agent orchestrator initialized. Select a scenario and click execute.