PHI access logging — every patient-scoped read or write appends an AccessEntry (actor, patient, action, timestamp). get_access_log returns the accounting of disclosures, supporting HIPAA…
EHR MCP Server
An Electronic Health Record integration layer for ADK-Rust Enterprise clinical agents. 25 MCP tools spanning the patient chart — demographics, encounters, problems, medications, results, notes, care gaps, quality…
What it gives an agent
A purpose-built capability behind one MCP connection.
The server owns its domain logic and publishes a tool contract an MCP client can discover. ADK-Rust can load that contract into an agent, normalize each schema for the chosen model provider, and keep the connection lifecycle outside the agent’s business logic.
Attributable access — every tool takes an actor; nothing touches a chart anonymously.
Gated clinical writes — medication changes, clinical notes, prior auth, and denial actions require approval in production (requires_approval); reads are read_only.
Minimum necessary — patient search returns only identifying demographics, not the full chart.
FHIR-aligned model — patients, encounters, conditions, medications, allergies, observations, notes map to familiar resource shapes.
Fictitious data only — the built-in sample chart uses invented names/identifiers; no real PHI ships in the crate.
Architecture
How EHR MCP Server fits into an agent system.
The model never needs the implementation details or credentials of the system behind the server. It sees reviewed tool definitions. The MCP client handles discovery and calls, while the server keeps ownership of validation, policy, and communication with its domain system.
ADK-Rust agent
Chooses a capability from the reviewed tool catalog.
MCP client
Discovers schemas, sends calls, and receives typed content.
EHR MCP Server
Validates the request and owns 26 documented tool contracts.
Domain system
Keeps the API, data, credentials, and business rules behind the server.
From the project documentation
The server’s published architecture
Tool catalog
What can an agent ask EHR MCP Server to do?
Each tool has a stable name, a human-readable purpose, and a JSON input contract discovered during MCP initialization. Risk classes come from the project’s registry manifest when one is available.
26 named tools
backend_infoReport the active clinical-read backend (memory or FHIR R4); no PHI
read onlyfind_patientsFind patients by MRN or name (minimum-necessary demographics); logged to PHI access log
read onlyget_patientGet patient demographics and coverage (PHI read)
read onlyget_encountersList a patient's encounters (PHI read)
read onlyget_conditionsGet a patient's problem list (PHI read)
read onlyget_medicationsGet a patient's medication list (PHI read)
read onlyget_allergiesGet a patient's allergies (PHI read)
read onlyget_observationsGet observations/results, optionally by category (PHI read)
read onlyget_notesGet a patient's clinical notes (PHI read)
read onlyadd_medicationAdd a medication to the patient's list (gated clinical write)
internal writeset_medication_statusChange a medication's status (gated clinical write)
internal writeadd_noteAdd (and optionally sign) a clinical note (gated clinical write)
internal writeGovernance
Understand the effect of every tool.
A server connection inherits the authority of its credentials and deployment environment. The declarations below come from this project’s README and MCP registry manifest; your application still decides which tools an agent receives and where approval is required.
- Gated clinical writes — medication changes, clinical notes, prior auth, and denial actions require approval in production (requires_approval); reads are read_only.
MCP surface
What the current documentation declares.
MCP can carry tools, resources, prompts, structured results, progress, cancellation, and long-running work. This record highlights the modern protocol features explicitly mentioned by this repository.
Install and connect
Follow the project’s documented starting point.
Install the server in the environment that owns its credentials and domain access. Add it to your MCP host, verify the discovered tools, and narrow the toolset before giving it to a production agent.
cargo install mcp-ehrlet toolset = McpToolset::from_stdio(
"mcp-ehr",
["mcp-ehr"],
).await?;
let agent = LlmAgentBuilder::new("agent")
.tools(toolset.tools().await?)
.build()?;Commands and configuration are extracted from the public README. Confirm prerequisites, environment variables, and release-specific options in the official documentation before deployment.
Official documentation
Continue with the project maintainers’ source of truth.
This page provides an approachable map of the server. The repository remains authoritative for exact schemas, prerequisites, configuration, examples, tests, releases, and security updates.
Keep exploring
More in industry solutions.
Source record
Release and repository metadata for this catalog entry.
- Version
- 1.1.0
- License
- Apache-2.0
- Tools
- 26
- Revision
- 12ca0934587e
- Updated
- Jun 7, 2026