Complete EHI export
Archive format 2.0 · layout schema v1 · published specification prepared September 13, 2026.
This format supports electronic health information export under 45 CFR §170.315(b)(10). Certification is in progress. Anyone can read the downloaded files without ChartVoyant software.
Frozen layout schema v1 · Synthetic ONC test-tenant sample ZIP
Request and download
A clinician or practice administrator can use the complete-record action at visit sign-off or in the chart’s ⋯ menu. Confirm the request and optionally record a reason. The completed export appears in Inbox → EHI exports.
Practice Settings → Data offers Export all EHI to a practice administrator. Confirmation uses that person's enrolled second factor: a code from an authenticator app, or a code ChartVoyant sends to their email or mobile. The owner console’s office panel uses the owner's authenticator app. Population membership includes all retained patient rows, including soft-deleted charts, at request time. The worker produces one ZIP per patient and a manifest with authenticated download links.
Downloads require an active session belonging to the requester. Links expire 24 hours after completion. Cancelling an export invalidates its links. The request, native/FHIR reads, completion and each download are recorded in the tenant’s hash-chained audit log. Source files that are unavailable or fail integrity verification cause the job to fail rather than produce a completed partial archive.
ZIP layout
records/patients.json
records/clinical_notes.json
records/record_versions.json
records/…all linked native tables….json
fhir/Patient.ndjson
fhir/…resource type….ndjson
documents/{storedObjectId}/{original filename}
manifest.json
schema.json
README.md
| Files | Schema and meaning |
|---|---|
records/*.json | One UTF-8 JSON array per native table. Objects retain column names, identifiers and relationship keys. The included schema.json lists each column and its PostgreSQL data type. Null is JSON null; timestamps are ISO 8601; binary values use {"$binary":"base64"}; large integers are decimal strings. |
fhir/*.ndjson | One FHIR R4 resource per line, using the API’s shared US Core 6.1 mappers. Empty supported classes produce empty files. Provenance retains recorder/agent/target evidence. Native records that cannot satisfy a profile remain in records/ and their available originals in documents/. |
documents/ | Original bytes, grouped by stored-object identifier to avoid filename collisions. manifest.json records the original filename and SHA-256. Path separators and control characters are replaced for safe extraction. Older uploads may retain only a sanitized storage filename; filenameSource identifies this. No file format conversion is performed. |
manifest.json | Format/schema version, tenant and patient identifiers, requesting actor, extraction start/end, per-file rows/bytes/SHA-256, and excluded tables with reasons. A population manifest instead lists patient ZIP filenames, SHA-256 summaries and signed URLs; an authenticated session is still required to retrieve each URL. |
schema.json | Frozen v1 container/encoding contract plus the exact native table columns in that export. Database columns can evolve without changing these encodings; a breaking layout or encoding change requires a new schema version. |
Native record coverage
The export includes linked demographics, notes and all retained versions, transcripts and segments, intake forms/responses, procedures and safety checks/outcomes, cases/events, chart-linked chat messages and thread metadata, faxes, SMS, emails, claims/lines/remittances/adjustments, payments/statements/balances, prior authorization, consents/signature requests, appointment history, audit history and portal-account metadata. Directory rows referenced by those records are included without following them to another patient’s chart.
Patient identity is authoritative when resolving relationships. Multiple valid paths are unioned. Unlinked practice conversations and tables with no relationship to the patient are identified as excluded. Password hashes, OTP secrets, tokens and encrypted signing keys are not EHI and are replaced with a redaction marker, including inside retained snapshots; clinical signatures and audit-chain hashes remain.
Code systems and interpretation
FHIR codings carry their system URI and code, including SNOMED CT, LOINC, RxNorm, ICD-10-CM, CPT/HCPCS, CVX, UCUM, CDC race/ethnicity and HL7 administrative code systems where recorded. Native JSON preserves the original coded objects and local status values; it does not infer missing codes. Interpret a code with its recorded system/version, not its display label alone.
Integrity and timing
Archives use standard ZIP64 with stored entries and CRC32 descriptors, supporting files larger than 4 GiB without assembling the archive in memory. Verify each extracted file against its manifest SHA-256. Extraction occurs while the practice may continue working; start/end bound the read interval and do not promise a database-wide point-in-time snapshot. Historical versions remain available in records/record_versions.json. A patient’s audit subset preserves original chain hashes but may have gaps where unrelated events occurred; verification of the complete tenant chain requires the tenant audit log.
The clinical importer recognizes legacy format 1.0 (data/*.ndjson) and complete format 2.0 (records/*.json). Importing clinical records still uses review and confirmation; it does not recreate users, billing ledgers or historical audit-chain identity.