Integrations and API

Integration starts with a precise data contract.

For each data flow, we define field meanings, sources, units, access rights and error handling in advance.

The public API is not yet open. A test environment is available as part of a pilot.

01
Purpose

Who needs the data, and for which process.

Required
02
Contract

Schema, units, identifiers and versions.

Project-specific
03
Access

Roles, consents, tenant and processing period.

Project-specific
04
Monitoring

Errors, retries, audit and stop criteria.

Before launch

Integration options

Choose the channel according to risk and data volume

Data scope, security and operational readiness are confirmed separately for each channel.

Documents Initial use case

  • secure upload;
  • a limited set of formats;
  • recognition with verification;
  • links to the source and version.

API and events Project-specific

  • REST API;
  • webhooks;
  • idempotent operations;
  • versioned schemas.

Medical data exchange On request

  • FHIR / HL7 under an agreed profile;
  • SFTP;
  • CSV / XML;
  • mapping of terminology and units.

Data contract

BIOS accepts a verifiable fact, not just a value

A minimum contract must make clear what was transmitted, its source, when it was recorded, its units and the basis for processing it.

01 / Identifier

A stable link to the record

Association with a person or episode without silently mixing records.

02 / Provenance

Source and time

Organisation, document, device, author and precise event time.

03 / Value

Code, unit and range

A value is interpreted only together with its term, unit and applicable reference range.

04 / Version

A correction preserves the previous version

A correction creates a new version and retains its link to the previous one.

05 / Access

Purpose and basis for access

Data transfer is limited by the use case, role, consent and duration.

06 / Quality

Errors remain visible

An unknown field, duplicate or conflict does not automatically become a medical fact.

Integration stages

From the first conversation to stable operation

Each stage begins only after the previous one has been checked.

01

Use case

Purpose, users, owners and scope.

02

Mapping

Sources, fields, terminology and quality.

03

Security

Access, transfer, storage and incident response.

04

Pilot

A limited data flow, test data and success criteria.

05

Operation

Monitoring, versions, support and a decision on scaling.

Responsibilities

Responsibilities are defined alongside the data contract

An integration is not complete until the parties know who is responsible for the source, field mapping, access and failure response.

Shared model

Integration risks are documented before launch

Medical data must retain its meaning and provenance. The recipient of the result and its review status must also be defined in advance.

01

Partner

Source quality, lawful transfer and notification of changes.

02

BIOS

Ingestion, contract validation, data provenance and controlled processing.

03

Clinic

Clinical rules, staff permissions and medical review.

04

Joint responsibility

Incidents, schema changes, stop criteria and scaling.

Technical readiness

What you can request now

Materials are provided after the use case is defined. Real medical data is not shared at the initial stage.

Start with a single data flow.

A source, a contract, security and a measurable result.