LangCare FHIRCAUTION
Enterprise-grade MCP Server for FHIR-based EMRs, designed for robust deployments in agentic AI platforms.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/langcare/langcare-mcp-fhir) [](https://github.com/langcare/langcare-mcp-fhir/graphs/contributors) [](https://github.com/langcare/langcare-mcp-fhir/blob/main/LICENSE) [](https://github.com/langcare/langcare-mcp-fhir/blob/main/go.mod)
Enterprise-grade MCP Server for FHIR-based EMRs. Fully written in Go with enterprise-grade security and 4 generic FHIR operations that work with any FHIR R4 resource type. Supports EPIC, Cerner, OpenEMR, GCP Healthcare API, and any generic FHIR R4 server.
Ships with a 40+ Clinical Skills Library — agent-agnostic workflow guides covering medication management, lab interpretation, clinical decision support, documentation, population health, and more. Extend with ✨ New: Claude Managed Agents (9 production-ready clinical AI agents on the Anthropic Managed Agents API), MCP Apps (interactive clinical UIs inside Claude Desktop), a Healthcare Voice Agent (real-time voice AI over FHIR), and a LangCare CLI for agent frameworks that don't speak MCP natively.
langcare.ai
Installation
Install via npm:
npm install -g @langcare/langcare-mcp-fhir
Or use directly without installation:
npx @langcare/langcare-mcp-fhir -config /path/to/config.yaml
##
4e04baf32a68OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add langcare-mcp-fhir -- npx -y @langcare/[email protected]
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (18)
.DS_Store
.DS_Store
__init__.cpython-313.pyc
base_prompt.cpython-313.pyc
client-secret: "your-cerner-client-secret"
.DS_Store
.DS_Store
.gitkeep.html
&client_assertion=eyJhbGciOiJSUzM4NCIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJ5b3VyLWNsaWVudC1pZCIsInN1YiI6InlvdXItY2xpZW50LWlkIiwiYXVkIjoiaHR0cHM6Ly9maGlyLmVwaWMuY29tL2ludGVyY29ubmVjdC1maGlyLW9hdXRoL29hdXRoMi90b
@modelcontextprotocol/ext-apps, react, react-dom, @types/react, @types/react-dom, @vitejs/plugin-react, typescript, vite
4. **POST** to the token endpoint:
server
=== FULL ACCESS TOKEN ===
**Key Principle**: Clients never directly access FHIR credentials. The MCP server acts as a secure proxy with centralized credential management.
4. Exchanges JWT for access token via `client_credentials` grant
The deploy requires image pull credentials. Create a Docker Hub access token at **Account Settings > Personal access tokens**, then:
# Load credentials from secrets
Gates applied: no_behavioural_pass.
4e04baf32a68full audit observations/trust-audit/mcp-server/langcare__langcare-fhir.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4e04baf32a68 | CAUTION | B | 81 | first audit |
Questions
What is the LangCare FHIR MCP server?
Enterprise-grade MCP Server for FHIR-based EMRs, designed for robust deployments in agentic AI platforms.
Is LangCare FHIR safe to connect to an agent?
With care. The audit graded it B (81/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does LangCare FHIR need?
It reads ANTHROPIC_API_KEY, CARTESIA_API_KEY, DEEPGRAM_API_KEY, LANGCARE_API_KEY and PIPECAT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does LangCare FHIR run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @langcare/langcare-mcp-fhir at 2.5.0.
How current is this page?
The grade is for one exact copy of the source (4e04baf32a68), read on 2026-10-08. The repository is watched and re-audited when it changes.