Practice setup — integrations
Wire Hero EMR to the outside world: referral/external providers, Stripe, SRFax, SMS, and EPCS for controlled prescribing.
Practice setup — integrations
Wire Hero EMR to the outside world: referral/external providers, Stripe, SRFax, SMS, and EPCS for controlled prescribing.
Connect every third-party integration from one hub
External Providers is Hero EMR's integration center. Every third-party connection — patient communication, clinical, billing, and personal tools — lives behind a single modal with a sidebar of tabs. Org admins manage the org-wide tabs; individual physicians manage their personal SRFax credentials.
Patient communication
- Email — outbound sender domain (default
mail@heroemr.com) and inbound routing for patient replies. - SMS — provider-routed SMS for reminders and inbound replies. See §4.9.
- Video conferencing — telehealth provider selection and per-physician host mapping. See Part III.
- Phone agent — inbound phone routing via the Hero Phone Agent.
Clinical integrations
- SureScripts — platform e-prescribing status and physician directory.
- Bamboo PDMP — PMP Gateway credentials and Kentucky readiness.
- RadNet Connect — credentials for the RadNet ordering portal.
- Labs — Quest credentials and enabled lab compendiums.
- Imaging visibility — which imaging providers show up at encounter completion.
Billing & payments
- Stripe — Stripe Connect onboarding for patient payments. See §4.7.
- Square — Square seller connection for portal payments.
- Office Ally — Service Center credentials.
- Office Ally SFTP — SFTP credentials for EDI claim transport.
- Availity SFTP — SFTP credentials and EDI identifiers for Availity transport.
Personal
- SRFax — your own SRFax credentials for personal inbound and outbound fax. See §4.8.
- Open
Admin > External Providers. The modal opens to Email by default. Tabs are grouped in the left sidebar by category. - Pick a tab. Each tab is self-contained — credentials, configuration, and a Verify/Test button. Status badges (Active, Disabled, Needs number, Not configured) tell you what's still missing.
- Refresh after external changes. If you change settings at the provider (e.g. add a new Office Ally payer), click Refresh in Hero to re-pull status.
?externalProvider=<tab> query string (e.g. ?externalProvider=stripe). Useful when sending a teammate to a specific integration.
Connect Stripe and set up billing for card payments, subscriptions, and balances
Stripe is the default payment processor for patient-facing card payments — copays collected at the front desk, cash-pay services, recurring memberships, balances posted from Billing, and card-on-file charges from the portal. Hero uses Stripe Connect, so each practice connects its own Stripe account. Payouts go directly to your bank; Hero never holds funds.
- Open
Admin > External Providersand pick the Stripe tab (under Billing & payments). - Click Connect with Stripe. You'll be redirected into Stripe Connect's onboarding flow. Stripe asks for business type, EIN/SSN, bank account, and a representative's identity — the same onboarding any Stripe merchant does.
- Finish onboarding in Stripe. Stripe verifies your business and your bank. Onboarding can take a few minutes (verified instantly) or a few days (manual review). You'll be redirected back to Hero when Stripe completes.
- Confirm Stripe Connect Active. The Stripe tab shows a green status badge with the connected account name (e.g. Dr. Romero's Practice) once Stripe has verified you.
- Open the Stripe Dashboard from Hero. Use the Open Stripe Dashboard button to review payouts, disputes, and refunds. Hero shows posted/refunded amounts in Billing, but Stripe is the source of truth for transaction-level detail.
- Disconnect to rotate. Use Disconnect if you need to attach a different Stripe account (e.g. merger, EIN change). Existing posted payments stay attributed to the original account; new charges land on the new one.
Set up the billing workflow after Stripe is active
Once the Stripe tab shows Stripe Connect Active, finish the billing configuration in Admin > Billing. Subscription-based and hybrid practices should configure their recurring membership model before inviting patients to enroll through the portal.
- Open
Admin > Billing. The Billing Command Center opens on the Dashboard. Confirm the practice name and revenue model at the top, then use the left sidebar for configuration. - Set the Payment Model. Choose the practice's default model: insurance, cash-pay, subscription/membership, or hybrid. For subscription-based practices, make Stripe the active processor and decide whether patients must keep a card on file.
- Build the Service Menu. Add the billable services patients can buy or schedule: monthly membership, annual membership, enrollment fee, HRI assessment, HRI follow-up, lab bundle, or one-time consult. Include the patient-facing name, price, billing frequency, and whether the service is self-pay or insurance-billed.
- Create Subscriptions. Define each recurring plan, attach the matching Service Menu item, set monthly or annual cadence, and confirm whether enrollment starts immediately or after the first visit.
- Configure Charge Fees. Add one-time fees such as no-show fees, late-cancel fees, enrollment fees, or standalone cash-pay service charges. These can be posted from the chart or collected through the portal once Stripe is active.
- Use Payments for verification. Post a small test charge or refund, then confirm it appears in Hero and in the Stripe Dashboard. Stripe remains the transaction-level source of truth for payouts, disputes, and refunds.
- Leave claims setup for insurance work. Only configure Claim Submission, Office Ally, Availity, and payer enrollment when the practice is ready to submit insurance claims. A membership launch can start with Stripe, Service Menu, Subscriptions, and Payments first.
Set up SRFax for inbound and outbound fax
SRFax is the fax provider Hero EMR ships with. Use it to send referrals, prescriptions, and records to outside providers, and to receive faxes into the Inbox. Unlike Stripe or Office Ally, SRFax credentials are per user — each physician's SRFax account stays under their personal control — but the fax number you save also writes back to the org/physician fax-on-file fields used by claims and Practice Info.
- Create an SRFax account at secure.srfax.com. Pick a plan that includes the volume and number-porting features you need. If you have an existing fax number, ask SRFax to port it.
- Grab your credentials. Inside SRFax, go to My Account > Account Summary. Copy your account number (that's your Access ID in Hero) and use your SRFax login password as the API key.
- Open
Admin > External Providers > SRFaxin Hero (it's the only entry under Personal). - Fill in the Credentials card. Enter Access ID, API key, Fax number (E.164 format, e.g.
15551234567), and an optional Sender email (used on the cover-page From line). - Click Verify & save. Hero hits the SRFax API with your credentials to confirm they work. If the fax number you entered differs from the one already stored on the org or physician record, Hero asks whether to overwrite or keep the existing number.
- Test by sending a fax. Open a chart, pick Send fax, choose any document, and address it to a known good fax number (your own phone, a service like faxzero.com, or a colleague). Confirm both delivery and inbox receipt.
- Disconnect to rotate. The credentials card locks once you're configured. To change them (password rotation, new SRFax account), click Disconnect, then re-enter and re-verify.
The SRFax tab is the last entry in the sidebar shown in §4.6 External Providers — the same screenshot above shows its position under Personal.
Turn on SMS for reminders and patient replies
SMS powers appointment reminders, waitlist notifications, and two-way patient threads in the Inbox. The SMS tab in External Providers picks which number SMS comes from and lets you set the auto-reply that fires when an inbound number doesn't match a patient. Configure SMS once at the org level; Scheduling > Patient notifications controls who receives what.
- Open
Admin > External Providers > SMS. If SMS hasn't been set up, the tab header shows Not configured. - Pick a phone-number source. Three options on the card:
- Custom number — type a Twilio-provisioned E.164 number (e.g.
+15551234567) that you own. - Organization phone — reuse the org phone from Practice Info.
- Phone agent number — share the same number as the Hero Phone Agent (only if the agent is enabled and configured).
- Custom number — type a Twilio-provisioned E.164 number (e.g.
- Set Inbound auto-replies. Each row covers a specific scenario — No patient match is the most important one. The default tells callers to phone the office; customize it to your tone and after-hours policy.
- Click Verify number & configure webhook. Hero confirms the number is reachable, registers an inbound SMS webhook with the carrier, and flips the status to Active.
- Toggle Enable organization SMS. The master switch. Patients won't receive SMS at all until this is on, regardless of per-physician reminder policies.
- Test from a patient chart. Open any patient with a verified mobile, send a test message from the Inbox, and confirm both delivery and inbound reply routing.
Enroll physicians for controlled-substance e-prescribing
EPCS (Electronic Prescriptions for Controlled Substances) is the DEA-regulated workflow for prescribing Schedule II–V drugs electronically. Each prescribing physician enrolls separately, completes identity proofing, registers two devices for two-factor authentication, and accepts the SureScripts attestation. Once enrolled, the physician can sign controlled prescriptions inside Hero with their second factor. The EPCS modal also configures PDMP (state-mandated controlled-substance database) checks per state.
- Open
Admin > EPCS Enrollment & Access. The modal opens to the Enrollments tab with a list of in-flight and completed enrollments. - Click + New Enrollment. Pick a physician (must already exist in Physician Management with a valid DEA), confirm their DEA registration, and start the enrollment.
- Complete identity proofing. The physician receives an email link to an Identity Proofing (IDP) flow. They confirm personal information against credit-bureau records. This step often trips people up — make sure their name and address exactly match what's on credit/DEA records.
- Register two devices. Two-factor is mandatory under DEA rules. Most physicians register their iPhone (TOTP authenticator app) and a Yubikey. Hero supports any TOTP authenticator and FIDO2/WebAuthn keys.
- Accept the SureScripts attestation. The physician signs a legal attestation that they understand DEA requirements. This unlocks controlled-substance signing.
- Switch to Monitoring for active enrollments. Shows recent EPCS signing activity per physician — useful when compliance or DEA audits ask for a log.
- Configure PDMP per state. Each state mandates which substances trigger a PDMP check and how recently. The PDMP tab lets you flip rules (e.g. CA controlled substances, KY HB1, OH OARRS) on or off, and enforce Require PDMP check for controlled prescriptions or Require reason override when a check is skipped.
- Review Security Alerts. Hero surfaces unusual signing events (new device, new geo, off-hours) for follow-up. Investigate any alert flagged in red.
Sync your schedule with Google Calendar or Outlook
Calendar Sync links a clinician’s own Google Calendar or Outlook / Microsoft 365 account to Hero so the EMR schedule and their outside calendar stay aligned — outside commitments block time on the Hero schedule, and (optionally) Hero visits appear on the personal calendar. Unlike the other items on this page, Calendar Sync is per-clinician self-service: every clinician connects their own calendar from the toolbar Settings (gear) → Calendar Sync menu. Admins can also reach the same panel through Admin > External Providers, but there is no org-wide “connect everyone’s calendar” switch — each clinician authorizes their own account.
Two independent directions of sync are available, and they default differently:
Import (default ON)
Pulls busy events from your external calendar and blocks that time on the Hero schedule. It never copies event titles or details into Hero — only the busy/free time. No PHI leaves the EMR.
Export (default OFF)
Pushes your Hero scheduled visits into a dedicated SoaperEMR calendar in your linked account. This carries PHI, so turning it on requires acknowledging a PHI/BAA warning first.
Include full appointment details (PHI)
An optional export toggle. Off, exported events show busy time only. On, they add patient names and visit reasons to the events in your outside calendar.
- Open Calendar Sync. Click the toolbar
Settingsgear and chooseCalendar Sync. (Admins can also openAdmin > External Providersand pick the Calendar Sync tab.) - Connect a provider. Each provider card — Google Calendar and Outlook / Microsoft 365 — has a
Connectbutton that sends you through that provider’s OAuth consent screen. Sign in with the account you want to sync and approve the requested calendar access; you’re returned to Hero with the card now showing your connected account. - Choose what syncs. On the connected card, Import busy time is on by default. Leave Export visits off unless you want Hero visits on your outside calendar — turning it on opens a PHI/BAA confirmation you must acknowledge. If you enable export, decide whether to also turn on Include full appointment details (PHI); otherwise exported events stay busy-time only.
- Keep it in sync. Sync runs automatically in the background once connected. Click
Sync nowto force an immediate pass, orRefreshto re-read the current connection status. A Reconnect required badge means the authorization expired or was revoked at the provider — clickConnectagain to re-authorize. - Disconnect when needed. Click
Disconnectto stop syncing and unlink the account. Existing blocked time and previously exported events are left as-is; no new sync occurs until you reconnect.
Settings gear — not from an org-wide admin switch.
Once OAuth is configured, the connected card replaces the Not configured state with your linked account name, the Import busy time / Export visits / Include full appointment details (PHI) toggles, and the Sync now, Refresh, and Disconnect controls. Enabling export raises the PHI/BAA confirmation dialog described above before any visit data is pushed.
Need help? Email support@heroemr.com.