For hospitals
Patient experience that fits your EHR workflows.
NEPA adds a low-friction patient channel for meal preferences, daily check-ins, and confidential feedback — without adding charting work for your clinical teams.
How the integration works
Standards-based, push-only
We use FHIR R4 and SMART Backend Services (authenticated with private_key_jwt). Patient and encounter context arrives through hospital-authorized ADT and approved FHIR channels — push-only, least-privilege.
No reusable credentials, no new chart burden
NEPA issues its own short-lived sessions and does not retain reusable hospital or EHR tokens for routine workflows. Where appropriate, check-ins write back as a QuestionnaireResponse against an EHR-assigned questionnaire.
Dietary preferences, not diet orders
Your EHR remains the source of truth for clinical diet orders. NEPA captures patient preferences and appetite to support — never override — your dietary workflows.
Staff access you control
Pilot staff use app-managed accounts with mandatory MFA and role-based access. Hospital SAML/OIDC SSO and SCIM are supported enterprise upgrades when you're ready.
What your teams get
The patient channel comes with the staff-side tools to run it — built in, not bolted on.
For clinical teams
Daily check-ins, reviewed on rounds
Patients log a quick note on pain, sleep, appetite, and comfort. Your clinical team reviews everything from a single queue during routine rounds — it complements, never replaces, the nurse call button.
Stay context that stays current
Rooms change and patients are discharged. The clinical queue always shows where a patient is now, with an audited, privacy-gated way to locate them in your EHR when they are not where you expect.
For dietary teams
Cutoff times your kitchen controls
Set meal order cutoff times per meal, with per-unit overrides when one ward runs on a different clock. Dietary staff can adjust their own cutoffs without waiting on an administrator.
Printable tray cards
Turn a patient's digital meal preferences into a printed tray card — a drop-in replacement for the paper preference sheet, with patient identity shown only as your hospital configures it.
For administrators & IT
Staff invites with the right role
Invite staff by email with the right role from day one — no shared logins, no manual account setup.
EHR sign-in, admin-approved
For hospitals using EHR-launched sign-in, clinicians open NEPA from inside the EHR and an admin simply confirms their role on first sign-in. No separate invite needed, no extra passwords to manage.
Audit history for every account
Every admin action and sign-in event for a staff member, in one chronological view — ready for your next access review.
Guided onboarding, not a ticket queue
A setup wizard walks your team through connecting your EHR and building your staff roster, with a live progress tracker at every step.
Cryptographically verifiable requests
We publish our signing keys using the JWKS standard, so your EHR can verify every request we make — no shared secrets to rotate.
Accessibility & language
Works with keyboard and screen reader
Built and automatically tested to work with a keyboard alone or a screen reader — skip links, labeled forms, visible focus, and readable tables throughout.
WCAG 2.2 AA, documented
A self-assessed WCAG 2.2 Level AA conformance statement, evaluated across the full application, is available on request for your accessibility procurement review.
Français (Canada)
The interface is available in Quebec French — every screen, every role — with clinical and consent wording now undergoing professional French review.
L'application complète en français québécois — chaque écran, chaque rôle.
Times you can trust
Every time on screen is either your hospital's local time or clearly labeled with its zone — from meal cutoffs to audit trails, never an ambiguous timestamp.
Security & compliance posture
- Hosted on HIPAA-targeted AWS infrastructure, encrypted in transit and at rest.
- A Business Associate Agreement (BAA) is signed with every hospital customer.
- Append-only audit logging with database-level role separation.
- Patient data is never sold, used for advertising, or used for unrelated research.
NEPA is an early-stage product. Formal third-party certifications (e.g. SOC 2, HITRUST) are on our roadmap and not yet in place; we're glad to discuss our current controls and timeline.
Inquire
Tell us about your hospital and EHR environment. We'll follow up to talk through a pilot.