Atlas / MCP servers / langcare / LangCare FHIR

LangCare FHIRCAUTION

mcp/langcare/langcare-fhir

Enterprise-grade MCP Server for FHIR-based EMRs, designed for robust deployments in agentic AI platforms.

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
67
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/langcare/langcare-mcp-fhir) [](https://github.com/langcare/langcare-mcp-fhir/graphs/contributors) [](https://github.com/langcare/langcare-mcp-fhir/blob/main/LICENSE) [](https://github.com/langcare/langcare-mcp-fhir/blob/main/go.mod)

Enterprise-grade MCP Server for FHIR-based EMRs. Fully written in Go with enterprise-grade security and 4 generic FHIR operations that work with any FHIR R4 resource type. Supports EPIC, Cerner, OpenEMR, GCP Healthcare API, and any generic FHIR R4 server.

Ships with a 40+ Clinical Skills Library — agent-agnostic workflow guides covering medication management, lab interpretation, clinical decision support, documentation, population health, and more. Extend with ✨ New: Claude Managed Agents (9 production-ready clinical AI agents on the Anthropic Managed Agents API), MCP Apps (interactive clinical UIs inside Claude Desktop), a Healthcare Voice Agent (real-time voice AI over FHIR), and a LangCare CLI for agent frameworks that don't speak MCP natively.

langcare.ai

Installation

Install via npm:

npm install -g @langcare/langcare-mcp-fhir

Or use directly without installation:

npx @langcare/langcare-mcp-fhir -config /path/to/config.yaml

##

Read from source at commit 4e04baf32a68OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add langcare-mcp-fhir -- npx -y @langcare/[email protected]
03

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (18)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
internal/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
pipecat-agent/server/prompts/__pycache__/__init__.cpython-313.pyc
__init__.cpython-313.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
pipecat-agent/server/prompts/__pycache__/base_prompt.cpython-313.pyc
base_prompt.cpython-313.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/SECURITY.md:395
client-secret: "your-cerner-client-secret"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
internal/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
internal/apps/dist/.gitkeep.html
.gitkeep.html
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/EPIC-APP-SECURITY.md:396
&client_assertion=eyJhbGciOiJSUzM4NCIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ5b3VyLWNsaWVudC1pZCIsInN1YiI6InlvdXItY2xpZW50LWlkIiwiYXVkIjoiaHR0cHM6Ly9maGlyLmVwaWMuY29tL2ludGVyY29ubmVjdC1maGlyLW9hdXRoL29hdXRoMi90b
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/package.json
@modelcontextprotocol/ext-apps, react, react-dom, @types/react, @types/react-dom, @vitejs/plugin-react, typescript, vite
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/OPENEMR-APP-SECURITY.md:302
4. **POST** to the token endpoint:
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
server
server
Why it matters. 12616290 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
test/README.md:95
=== FULL ACCESS TOKEN ===
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/SECURITY.md:57
**Key Principle**: Clients never directly access FHIR credentials. The MCP server acts as a secure proxy with centralized credential management.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/SECURITY.md:268
4. Exchanges JWT for access token via `client_credentials` grant
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
pipecat-agent/README.md:296
The deploy requires image pull credentials. Create a Docker Hub access token at **Account Settings > Personal access tokens**, then:
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
test/README.md:256
# Load credentials from secrets
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4e04baf32a68full audit observations/trust-audit/mcp-server/langcare__langcare-fhir.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084e04baf32a68CAUTIONB81first audit
05

Questions

What is the LangCare FHIR MCP server?

Enterprise-grade MCP Server for FHIR-based EMRs, designed for robust deployments in agentic AI platforms.

Is LangCare FHIR safe to connect to an agent?

With care. The audit graded it B (81/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does LangCare FHIR need?

It reads ANTHROPIC_API_KEY, CARTESIA_API_KEY, DEEPGRAM_API_KEY, LANGCARE_API_KEY and PIPECAT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LangCare FHIR run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @langcare/langcare-mcp-fhir at 2.5.0.

How current is this page?

The grade is for one exact copy of the source (4e04baf32a68), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement