Orion Health Audit API

Audit log access for compliance

Operations 1

GET /audit-logs Orion Health Search audit logs #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/orion-audit-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

orion-health-audit-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Orion Health HIE Audit API
  description: The Orion Health Health Information Exchange (HIE) API enables sharing of patient health information across healthcare organizations. It provides capabilities for patient identity matching, document exchange, consent management, provider directory lookups, and audit logging in compliance with healthcare interoperability standards. The API supports IHE profiles including XDS, XCA, and PDQ.
  version: 1.0.0
  contact:
    name: Orion Health API Support
    email: apisupport@orionhealth.com
    url: https://www.orionhealth.com/support
  license:
    name: Proprietary
    url: https://www.orionhealth.com/terms-of-service
  termsOfService: https://www.orionhealth.com/terms-of-service
servers:
- url: https://api.orionhealth.com/hie
  description: Production HIE Server
- url: https://sandbox.orionhealth.com/hie
  description: Sandbox HIE Server
security:
- oauth2: []
- bearerAuth: []
tags:
- name: Audit
  description: Audit log access for compliance
paths:
  /audit-logs:
    get:
      operationId: searchAuditLogs
      summary: Orion Health Search audit logs
      description: Search audit logs for data access and exchange events within the HIE network for compliance and accountability purposes.
      tags:
      - Audit
      parameters:
      - name: patientId
        in: query
        schema:
          type: string
      - name: userId
        in: query
        schema:
          type: string
      - name: action
        in: query
        schema:
          type: string
          enum:
          - query
          - retrieve
          - submit
          - update
          - consent-change
      - name: dateFrom
        in: query
        schema:
          type: string
          format: date-time
      - name: dateTo
        in: query
        schema:
          type: string
          format: date-time
      - name: outcome
        in: query
        schema:
          type: string
          enum:
          - success
          - failure
          - denied
      - $ref: '#/components/parameters/PageOffset'
      - $ref: '#/components/parameters/PageLimit'
      responses:
        '200':
          description: Audit log entries
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/AuditLogEntry'
                  pagination:
                    $ref: '#/components/schemas/Pagination'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          description: Insufficient permissions for audit access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Pagination:
      type: object
      properties:
        offset:
          type: integer
        limit:
          type: integer
        total:
          type: integer
        hasMore:
          type: boolean
    AuditLogEntry:
      type: object
      properties:
        id:
          type: string
          format: uuid
        timestamp:
          type: string
          format: date-time
        action:
          type: string
          enum:
          - query
          - retrieve
          - submit
          - update
          - consent-change
        outcome:
          type: string
          enum:
          - success
          - failure
          - denied
        patientId:
          type: string
        userId:
          type: string
        userName:
          type: string
        organization:
          type: string
        organizationName:
          type: string
        resourceType:
          type: string
        resourceId:
          type: string
        sourceIp:
          type: string
        details:
          type: string
    Error:
      type: object
      properties:
        code:
          type: string
        message:
          type: string
        details:
          type: array
          items:
            type: object
            properties:
              field:
                type: string
              message:
                type: string
  responses:
    Unauthorized:
      description: Authentication required
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  parameters:
    PageLimit:
      name: limit
      in: query
      description: Maximum number of items to return
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 20
    PageOffset:
      name: offset
      in: query
      description: Number of items to skip
      schema:
        type: integer
        minimum: 0
        default: 0
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://auth.orionhealth.com/oauth2/token
          scopes:
            hie:patient-query: Query patient identity
            hie:document-read: Retrieve documents
            hie:document-write: Submit documents
            hie:consent-read: Read consent directives
            hie:consent-write: Manage consent directives
            hie:provider-read: Query provider directory
            hie:notification-read: Read notifications
            hie:notification-manage: Manage notification subscriptions
            hie:audit-read: Read audit logs
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT