A GiraffStack, Inc. Project
System Operational

HEART is your clinical view for Epic. Sign in with your provider credentials to open the chart, review trends, and see the whole patient in one place.

What is HEART
Epic Integration

A SMART on FHIR bolt-on that Hyperspace can embed.

HEART launches from Epic the way any embedded application does. Registered with Epic Vendor Services. No credentials to configure, no data to migrate, no workflow to change.

Launches beside Epic.
Never in place of it.

HEART reads FHIR R4 resources the moment a clinician opens a chart. Patient, Condition, Observation, AllergyIntolerance, Encounter — synthesized into one view organized by care surface, not by resource type.

  • SMART on FHIR R4 · PKCE OAuth 2.0
  • Registered with Epic Vendor Services (Non-Prod + Prod Client IDs)
  • Embeds inside Hyperspace via configurable frame-ancestors
  • 15-minute inactivity kill · session dies on tab close
  • 8-tier role-based access — from LPN (5 min) to Physician (60 min)
Built With Clinicians In Mind

Different roles. Different windows. Same clarity.

HEART's access model was designed around how clinicians actually work — not a generic user-permissions matrix. Session length, elevation windows, and scoped resource sets differ by role.

Attending Physician

"I want the whole trend on one screen — not 40 tabs."

60-min session · Full careteam scope
Surgeon

"Show me pre-op labs, active meds, and the last three encounters. That's the call."

60-min session · Full careteam scope
Nurse Practitioner / PA

"Diagnostic reasoning support without diagnostic claims — that's the line HEART respects."

45-min session · Full careteam scope
Charge RN

"I need to see every patient on the unit at once — not click into each one."

30-min session · Unit-level scope
Radiologist

"Priors and clinical context, side-by-side with the study. Not in another tab."

30-min session · Discipline scope
Registered Nurse

"When vitals shift, I want to see the trend, not just the current reading."

15-min session · Careteam scope
Licensed Practical Nurse

"Quick check on assigned patients. Get in, verify, get back to care."

5-min session · Careteam scope
System Administrator

"Audit trail, elevation logs, access reviews — all in one console. No PHI needed."

Admin only · Zero PHI scope
Compliance Posture

Regulated by construction.
Not by promise.

HEART's architecture is what makes it compliant. Not policy language. Not attestation. The read-only, zero-retention, session-only design closes categories of risk before they're categories.

Federal

HIPAA

Security Rule §164.312 · Privacy Rule §164.502 · Breach Rule §164.400

Aligned
Cures Act

Non-Device CDS

Satisfies all four §3060(a) criteria. Informs, never diagnoses. No FDA 510(k) required.

Aligned
New York

SHIELD Act

GBL §899-bb WISP documented · §899-aa breach notification cascade in place

Aligned
Cloud BAA

AWS BAA + HCLS

Executed base BAA + Healthcare & Life Sciences addendum · us-east-2

Executed
Audit Trail

Object Lock 6yr

COMPLIANCE mode · KMS CMK · CloudTrail data events · tamper-evident by construction

Deployed
Epic Integration

Vendor Services Registered

Non-Production + Production Client IDs issued · SMART on FHIR R4

Registered
In Progress

SOC 2 Type 2

Drata assessment · Q4 2026 target · continuous compliance monitoring

Assessment Q4 2026
Corporate

Delaware C-Corp

GiraffStack, Inc. · 83(b) election filed · fully registered · single officer

Registered

See the trend.
Treat the patient.

HEART is in early provider access. Sign in with your issued credentials, or request access if your institution is evaluating.