# Medplum June 2026 Update

The headline this month: **Medplum achieved [HITRUST certification](/content/blog/hitrust-e1-certification/index.html)**, a validation of our security and compliance program. June was also another busy month of shipping, with 200+ commits from 25+ contributors and nine patch releases — v5.1.14 through v5.1.22.

[Scheduling](/content/docs/scheduling/index.html) saw a lot of activity. The [Provider App](https://provider.medplum.com/) gained a reusable inbox shell, and operation-based claim submission. SMART Health Cards and Links arrived with a QR code scanner, the Enterprise data warehouse export was released, and the AI workspace added configurable model routing. The platform also gained email-based [multi-factor authentication](/content/docs/auth/mfa/index.html), enforceable per project.

All of this continues to drive forward our [2026 roadmap priorities](/content/blog/2026-roadmap/index.html).

## Features

### Scheduling  
Building on May's operation suite, June moved [scheduling](/content/blog/2026-roadmap#scheduling/index.html) to a Beta release and tightened the rules around how appointments are booked:

- **Scheduling API Beta** — The appointment operation suite is now a Beta release, and the older Slot-based alpha implementations have been removed in favor of the appointment-based flow
- **[`$book` alignment enforcement](/content/docs/scheduling/appointment-book/index.html)** — Booking now enforces scheduling alignment, and [`$find`](/content/docs/scheduling/appointment-find/index.html) supports nondivisible alignment times so slots respect configured intervals
- **Planning horizon constraints** — Scheduling operations are now constrained by `Schedule.planningHorizon`, and scheduling parameters can be inherited from the `HealthcareService`
- **Availability defaults** — Availability now defaults to "always" when unset, with the requested time slot included in availability error messages for clearer feedback
- **Provider scheduling flow** — The [Provider App](/content/docs/provider/schedule/index.html) streamlines encounter creation, links `Appointment.slot`, adds an Appointment confirm button, and moves to FullCalendar v7
- **Cancelled-appointment slots** — The schedule view now hides slots tied to cancelled appointments, so a cancellation frees the time back up instead of leaving a stale block

### Provider App  
The [Provider App](/content/blog/2026-roadmap#provider-application/index.html) gained reusable building blocks and revenue-cycle improvements:
- **ResourceBoard inbox shell** — A new React shell that encapsulates inbox logic, providing a reusable foundation for task and worklist views
- **Performing practitioner in care teams** — Care team fields now support a performing practitioner, improving attribution in clinical workflows
- **Operation-based claim submission** — Claim submission now uses a server-side FHIR operation, and the app creates or updates the `Claim` during export or submit, simplifying the [billing](/content/blog/2026-roadmap#revenue-cycle--billing/index.html) integration
- **Patient documents tab** — A dedicated documents tab on the patient view, with inbound faxes now stored as `DocumentReference` resources so they land in the chart alongside other records
- **Medications in the patient summary** — `MedicationStatement` resources appear in the `PatientSummary` component, and both `MedicationStatement` and `DocumentReference` now resolve to readable display strings
- **Self-service registration** — A Register page for the Provider App lets new users sign up directly, with the reCAPTCHA widget hidden in the app shell
- **Navigation polish** — Navbar visual tweaks and a HeaderDropdown refactor, plus fixes to the back button after fax loading and to autoscrolling

### AI  
AI work centered on the [Spaces](/content/docs/provider/spaces/index.html) workspace — the in-app AI assistant in the Provider App — and real-time documentation:
- **Configurable model routing** — [Spaces](/content/docs/provider/spaces#model-selection/index.html) now supports a configurable base URL and a dynamic model list, so deployments can route AI requests through their own gateway to control cost and security
- **AI real-time questionnaire form** and **real-time voice** — A real-time questionnaire form plus [voice input](/content/docs/provider/spaces#voice-input/index.html) improvements that keep the socket active during a session
- **Spaces UX** — Prompt composer UI updates and grouping of each FHIR request with its corresponding response for clearer traceability

The [Spaces documentation](/content/docs/provider/spaces/index.html) covers setup, the agent loop, and how to author the system prompts that drive its behavior.

### Identity, Sharing, and Documents  
- **[Multi-factor authentication](/content/docs/auth/mfa/index.html)** — A new email-based MFA method, plus a project-level `mfaRequired` setting that enforces MFA for every member, with documentation for enabling it
- **External token exchange across project memberships** — Token exchange now works across project memberships, for users who span multiple projects
- **Attachment handling** — Inline attachments in `Patient/$everything`, base64 data support in `<AttachmentDisplay>`, and cursor pagination across patient-everything and multi-type searches
- **Patient invite with RelatedPerson** — The user invite endpoint accepts a `Patient` to support RelatedPerson, enabling caregiver and proxy access

### Enterprise: Data Warehouse and Reliability  
Enterprise scale and infrastructure work made the [analytics](/content/docs/analytics/index.html) export production-ready and hardened the data layer:
- **Data warehouse export controls** — Configuration for which tables to sync, include/exclude filters, restored `ORDER BY`, and DuckDB lifecycle cleanup give data teams precise control over what reaches their lakehouse
- **Transaction-scoped repositories** — Repository connections are now transaction-scoped, with idle-in-transaction time tracked, improving reliability under load
- **FHIRPath Patch** — A [FHIRPath Patch](/content/docs/fhir-datastore/index.html) utility wired into the server for targeted resource updates
- **Project-level SMTP** — Projects can now configure their own SMTP settings for sending email

### Agent and Connectivity  
The on-premise [Agent](/content/docs/agent/index.html) — Medplum's connectivity service for legacy healthcare systems and HL7 interfaces — saw a concentrated round of reliability work this month:
- **Durable HL7 message queue** — The Agent now persists inbound HL7 messages to a durable queue, so messages survive restarts and transient outages instead of living only in memory
- **Resilient `Agent/$upgrade`** — A batch of fixes to the [Agent upgrade flow](/content/docs/agent/upgrade/index.html): no more duplicated messages during an upgrade, a guard that checks for the upgrade artifact before unlinking it, and a documented upgrade bugfix, alongside a new [`Agent/$upgrade` documentation page](/content/docs/agent/upgrade/index.html)
- **Reconnection hardening** — The Agent now reconnects across a range of error states, records the acknowledgement before returning in [acknowledgement-only mode](/content/docs/agent/acknowledgement-modes/index.html), and triggers a clean shutdown before awaiting channel start
- **[`Agent/$reload-config`](/content/docs/agent/reload-config/index.html)** — A documented operation to reload a deployed Agent's configuration without a full restart
- **WebSocket subscription reliability** — A series of fixes recreate [WebSocket subscriptions](/content/docs/subscriptions/index.html) on reconnect, tear down the Redis listener cleanly on shutdown, bind the message listener before subscribing, and send a handshake on connection establishment

## Compliance  
**Medplum achieved [HITRUST certification](/content/blog/hitrust-e1-certification/index.html) this month** — the headline of our [compliance](/content/blog/2026-roadmap#compliance-h1-2026/index.html) track. HITRUST is one of the most rigorous, prescriptive security frameworks in healthcare, and certification gives customers third-party assurance of Medplum's security and compliance program for their own vendor reviews. Several other pieces of the track also moved:
- **[HITRUST documentation](/content/docs/compliance/hitrust/index.html)** — Published HITRUST documentation alongside the certification, and pointed compliance references at the [Medplum Trust Center](https://trust.medplum.com/) (with an updated Vanta Trust Center link)
- **SMART Health Cards and Links** — Support for SMART Health Cards and Links, including a QR code scanner and updates for the CMS "Keep the Card" (KTC) program, giving patients a verifiable, portable record
- **[`Patient/$match`](/content/docs/api/fhir/operations/patient-match/index.html) with CMS criteria** — The patient match operation now follows CMS matching criteria, aligning identity resolution with federal guidance
- **Patient data access fixes** — Corrected [`Patient/$everything`](/content/docs/api/fhir/operations/patient-everything/index.html) pagination links and normalized C-CDA address handling, keeping patient-record exchange complete and standards-conformant
- **Electronic prior authorization** — Continued progress on electronic prior authorization toward the [HTI-4](/content/docs/compliance/hti-4/index.html) requirements ahead of the January 2027 enforcement date

## Documentation  
- **Self-hosting fixes** — Corrections across the Azure, GCP, and Kubernetes self-hosting guides, a Debian package fix that preserves local edits on upgrade and restores the DuckDB native dependency, and production Docker base images pinned to Node 24.18
**Provider App and platform**
- **[Shared Projects](/content/docs/access/index.html)** — New documentation on shared projects
- **[Multi-lingual FHIR support](/content/docs/fhir-datastore/multilingual-support/index.html)** — Docs and a demo app for multi-lingual FHIR support
- **Agentic engineering guide** — A new agentic engineering guide and companion blog post
- **[AI real-time docs](/content/docs/provider/spaces/index.html)** and **Alpha/Beta feature expectations** — Documentation for the AI real-time operation and a guide to what Alpha and Beta feature labels mean

**Integrations**
- **[Electronic prescribing](/content/docs/integration/index.html)** — Expanded e-prescribe documentation, including prescriber profile setup and staging NPI creation
- **[Lab orders](/content/docs/integration/index.html)** — Public docs for lab account number updates
- **[Clearinghouse claim submission](/content/docs/billing/index.html)** — Claim submission documentation for clearinghouse connectivity

## Bug Fixes  
**FHIR and billing**
- Render CMS-1500 Box 24E diagnosis pointers correctly  
- Prevent duplicate resources in `convertToTransactionBundle`  
- Normalize address part text nodes in C-CDA `mapAddresses`

**Server and async**
- Stop polling a cancelled `AsyncJob` by returning 200 from the status endpoint, and add `Accept-Encoding: identity` to token exchange  
- Bound the 401 retry in `MedplumClient` to prevent infinite retry loops  
- Paginate AWS Textract results via `NextToken`  
- Recreate WebSocket subscriptions on reconnect  
- Record the authenticating `ClientApplication` on `AuditEvent.agent[]`

## Releases  
- [**v5.1.14**](https://github.com/medplum/medplum/releases/tag/v5.1.14) — June 1  
- [**v5.1.15**](https://github.com/medplum/medplum/releases/tag/v5.1.15) — June 3  
- [**v5.1.16**](https://github.com/medplum/medplum/releases/tag/v5.1.16) — June 8  
- [**v5.1.17**](https://github.com/medplum/medplum/releases/tag/v5.1.17) — June 9  
- [**v5.1.18**](https://github.com/medplum/medplum/releases/tag/v5.1.18) — June 15  
- [**v5.1.19**](https://github.com/medplum/medplum/releases/tag/v5.1.19) — June 20  
- [**v5.1.20**](https://github.com/medplum/medplum/releases/tag/v5.1.20) — June 20  
- [**v5.1.21**](https://github.com/medplum/medplum/releases/tag/v5.1.21) — June 20  
- [**v5.1.22**](https://github.com/medplum/medplum/releases/tag/v5.1.22) — June 24

## Looking Ahead  
June brought scheduling to Beta, made the Enterprise data warehouse export production-ready with selectable table sync, and added configurable model routing to the AI workspace. SMART Health Cards and Links, operation-based claim submission, and a reusable inbox shell round out a month focused on Provider App depth and platform reliability.
