Machine
Integration
Lab analyzers, radiology modalities, and cath-lab systems can post reports to HMIS using per-module API credentials. Lab uploads and order lookup accept the order UUID or the 10-character barcode short code. Radiology and cath-lab still use order UUIDs.
Credentials
Generate client ID and secret under Settings → Machine integration (settings:admin). Rotate secrets when instruments are decommissioned.
Order ID contract
POST bodies must include orderId (UUID of test_orders, radiology_orders, or cath_lab_orders). Unknown or completed orders are rejected.
Endpoints
Lab JSON: /api/v1/lab/machine/reports. Lab HL7 (optional): /api/v1/lab/machine/hl7 with { message }, ORU^R01 applies results when orderId resolves; ADT^A01/A03 and ORM^O01 (NW/CA) default parse+ACK, opt-in write-back via hl7.writeback.* settings + feature hl7_clinical_writeback. Radiology/cathlab: …/machine/reports and optional …/machine/hl7 (ORM scoped; ORU parse-only). Auth via machine credentials, not user sessions. HL7 profile certification is not claimed.
Audit
Successful posts attach reports, update order status, and log clientId/auth method for governance review.
Technical Architecture
| Field | Type | Institutional Role |
|---|---|---|
| orderId | UUID | Existing clinical order the instrument result attaches to. |
| clientId | Varchar | Machine credential identity stored in app settings. |
Note: Sensitive fields use AES-256 field-level encryption where applicable.
Governance & Power
settings:adminlab:viewradiology:viewcathlab:view