Provider Manual · Part IV

Practice setup — integrations

Wire Hero EMR to the outside world: referral/external providers, Stripe, SRFax, SMS, and EPCS for controlled prescribing.

6 sections~13 min read8 screenshots
IV
Part IV · continued

Practice setup — integrations

Wire Hero EMR to the outside world: referral/external providers, Stripe, SRFax, SMS, and EPCS for controlled prescribing.

4.6External providers

Connect every third-party integration from one hub

External Providers is Hero EMR's integration center. Every third-party connection — patient communication, clinical, billing, and personal tools — lives behind a single modal with a sidebar of tabs. Org admins manage the org-wide tabs; individual physicians manage their personal SRFax credentials.

Patient communication

  • Email — outbound sender domain (default mail@heroemr.com) and inbound routing for patient replies.
  • SMS — provider-routed SMS for reminders and inbound replies. See §4.9.
  • Video conferencing — telehealth provider selection and per-physician host mapping. See Part III.
  • Phone agent — inbound phone routing via the Hero Phone Agent.

Clinical integrations

  • SureScripts — platform e-prescribing status and physician directory.
  • Bamboo PDMP — PMP Gateway credentials and Kentucky readiness.
  • RadNet Connect — credentials for the RadNet ordering portal.
  • Labs — Quest credentials and enabled lab compendiums.
  • Imaging visibility — which imaging providers show up at encounter completion.

Billing & payments

  • Stripe — Stripe Connect onboarding for patient payments. See §4.7.
  • Square — Square seller connection for portal payments.
  • Office Ally — Service Center credentials.
  • Office Ally SFTP — SFTP credentials for EDI claim transport.
  • Availity SFTP — SFTP credentials and EDI identifiers for Availity transport.

Personal

  • SRFax — your own SRFax credentials for personal inbound and outbound fax. See §4.8.
  1. Open Admin > External Providers. The modal opens to Email by default. Tabs are grouped in the left sidebar by category.
  2. Pick a tab. Each tab is self-contained — credentials, configuration, and a Verify/Test button. Status badges (Active, Disabled, Needs number, Not configured) tell you what's still missing.
  3. Refresh after external changes. If you change settings at the provider (e.g. add a new Office Ally payer), click Refresh in Hero to re-pull status.
Admin · External Providers modal grouped into Patient Communication, Clinical Integrations, Billing & Payments, and Personal sections with the Email tab open
The sidebar is grouped by category. Every integration lives here — there is no separate per-feature settings page.
Bookmarkable tabs: Each tab supports a deep link via the ?externalProvider=<tab> query string (e.g. ?externalProvider=stripe). Useful when sending a teammate to a specific integration.
4.7Stripe & billing

Connect Stripe and set up billing for card payments, subscriptions, and balances

Stripe is the default payment processor for patient-facing card payments — copays collected at the front desk, cash-pay services, recurring memberships, balances posted from Billing, and card-on-file charges from the portal. Hero uses Stripe Connect, so each practice connects its own Stripe account. Payouts go directly to your bank; Hero never holds funds.

  1. Open Admin > External Providers and pick the Stripe tab (under Billing & payments).
  2. Click Connect with Stripe. You'll be redirected into Stripe Connect's onboarding flow. Stripe asks for business type, EIN/SSN, bank account, and a representative's identity — the same onboarding any Stripe merchant does.
  3. Finish onboarding in Stripe. Stripe verifies your business and your bank. Onboarding can take a few minutes (verified instantly) or a few days (manual review). You'll be redirected back to Hero when Stripe completes.
  4. Confirm Stripe Connect Active. The Stripe tab shows a green status badge with the connected account name (e.g. Dr. Romero's Practice) once Stripe has verified you.
  5. Open the Stripe Dashboard from Hero. Use the Open Stripe Dashboard button to review payouts, disputes, and refunds. Hero shows posted/refunded amounts in Billing, but Stripe is the source of truth for transaction-level detail.
  6. Disconnect to rotate. Use Disconnect if you need to attach a different Stripe account (e.g. merger, EIN change). Existing posted payments stay attributed to the original account; new charges land on the new one.
Stripe tab in External Providers showing the Stripe Connect Active green status banner with the connected account name and an Open Stripe Dashboard button
The Stripe Connect Active banner is the green light for taking card payments. Until you see it, the front-desk card reader and portal payments stay disabled.
Stripe vs. Square: Most practices use Stripe. Hero also supports Square under the Square tab for practices that already have a Square seller account and want to keep their existing in-person card readers. Pick one — they don't run in parallel.

Set up the billing workflow after Stripe is active

Once the Stripe tab shows Stripe Connect Active, finish the billing configuration in Admin > Billing. Subscription-based and hybrid practices should configure their recurring membership model before inviting patients to enroll through the portal.

  1. Open Admin > Billing. The Billing Command Center opens on the Dashboard. Confirm the practice name and revenue model at the top, then use the left sidebar for configuration.
  2. Set the Payment Model. Choose the practice's default model: insurance, cash-pay, subscription/membership, or hybrid. For subscription-based practices, make Stripe the active processor and decide whether patients must keep a card on file.
  3. Build the Service Menu. Add the billable services patients can buy or schedule: monthly membership, annual membership, enrollment fee, HRI assessment, HRI follow-up, lab bundle, or one-time consult. Include the patient-facing name, price, billing frequency, and whether the service is self-pay or insurance-billed.
  4. Create Subscriptions. Define each recurring plan, attach the matching Service Menu item, set monthly or annual cadence, and confirm whether enrollment starts immediately or after the first visit.
  5. Configure Charge Fees. Add one-time fees such as no-show fees, late-cancel fees, enrollment fees, or standalone cash-pay service charges. These can be posted from the chart or collected through the portal once Stripe is active.
  6. Use Payments for verification. Post a small test charge or refund, then confirm it appears in Hero and in the Stripe Dashboard. Stripe remains the transaction-level source of truth for payouts, disputes, and refunds.
  7. Leave claims setup for insurance work. Only configure Claim Submission, Office Ally, Availity, and payer enrollment when the practice is ready to submit insurance claims. A membership launch can start with Stripe, Service Menu, Subscriptions, and Payments first.
Billing Command Center dashboard with operations tabs and configuration tabs for Payment Model, Claim Submission, Collections and Fees, Service Menu, Subscriptions, and Charge Fees
The Billing Command Center keeps payment operations and configuration together. Subscription practices start in Payment Model, Service Menu, and Subscriptions.
Billing Command Center Payments tab showing manual entry, ERA upload, recent payment activity, posted card payments, and refund actions
Use the Payments tab to verify card payments and refunds after Stripe is connected. Posted payments should also be visible in the Stripe Dashboard.
4.8SRFax

Set up SRFax for inbound and outbound fax

SRFax is the fax provider Hero EMR ships with. Use it to send referrals, prescriptions, and records to outside providers, and to receive faxes into the Inbox. Unlike Stripe or Office Ally, SRFax credentials are per user — each physician's SRFax account stays under their personal control — but the fax number you save also writes back to the org/physician fax-on-file fields used by claims and Practice Info.

  1. Create an SRFax account at secure.srfax.com. Pick a plan that includes the volume and number-porting features you need. If you have an existing fax number, ask SRFax to port it.
  2. Grab your credentials. Inside SRFax, go to My Account > Account Summary. Copy your account number (that's your Access ID in Hero) and use your SRFax login password as the API key.
  3. Open Admin > External Providers > SRFax in Hero (it's the only entry under Personal).
  4. Fill in the Credentials card. Enter Access ID, API key, Fax number (E.164 format, e.g. 15551234567), and an optional Sender email (used on the cover-page From line).
  5. Click Verify & save. Hero hits the SRFax API with your credentials to confirm they work. If the fax number you entered differs from the one already stored on the org or physician record, Hero asks whether to overwrite or keep the existing number.
  6. Test by sending a fax. Open a chart, pick Send fax, choose any document, and address it to a known good fax number (your own phone, a service like faxzero.com, or a colleague). Confirm both delivery and inbox receipt.
  7. Disconnect to rotate. The credentials card locks once you're configured. To change them (password rotation, new SRFax account), click Disconnect, then re-enter and re-verify.
HIPAA note: SRFax is HIPAA-compliant and signs a BAA. Make sure your SRFax account is on a HIPAA-enabled plan — the cheapest consumer tier doesn't include the BAA. If you're sending PHI by fax (you are), this matters.

The SRFax tab is the last entry in the sidebar shown in §4.6 External Providers — the same screenshot above shows its position under Personal.

4.9SMS messaging

Turn on SMS for reminders and patient replies

SMS powers appointment reminders, waitlist notifications, and two-way patient threads in the Inbox. The SMS tab in External Providers picks which number SMS comes from and lets you set the auto-reply that fires when an inbound number doesn't match a patient. Configure SMS once at the org level; Scheduling > Patient notifications controls who receives what.

  1. Open Admin > External Providers > SMS. If SMS hasn't been set up, the tab header shows Not configured.
  2. Pick a phone-number source. Three options on the card:
    • Custom number — type a Twilio-provisioned E.164 number (e.g. +15551234567) that you own.
    • Organization phone — reuse the org phone from Practice Info.
    • Phone agent number — share the same number as the Hero Phone Agent (only if the agent is enabled and configured).
  3. Set Inbound auto-replies. Each row covers a specific scenario — No patient match is the most important one. The default tells callers to phone the office; customize it to your tone and after-hours policy.
  4. Click Verify number & configure webhook. Hero confirms the number is reachable, registers an inbound SMS webhook with the carrier, and flips the status to Active.
  5. Toggle Enable organization SMS. The master switch. Patients won't receive SMS at all until this is on, regardless of per-physician reminder policies.
  6. Test from a patient chart. Open any patient with a verified mobile, send a test message from the Inbox, and confirm both delivery and inbound reply routing.
Organization SMS tab with Custom number, Organization phone, and Phone agent number options, an Inbound auto-replies card, and a Verify number & configure webhook button
Pick the number source, set the no-patient-match auto-reply, then verify. Reminder cadence still comes from Scheduling.
10DLC and A2P registration: US carriers require business SMS senders to register their brand and campaign (10DLC). Hero handles the technical wiring, but you'll need to provide your EIN and a sample message during onboarding. Expect 1–2 business days for approval before SMS goes live.
4.10EPCS enrollment

Enroll physicians for controlled-substance e-prescribing

EPCS (Electronic Prescriptions for Controlled Substances) is the DEA-regulated workflow for prescribing Schedule II–V drugs electronically. Each prescribing physician enrolls separately, completes identity proofing, registers two devices for two-factor authentication, and accepts the SureScripts attestation. Once enrolled, the physician can sign controlled prescriptions inside Hero with their second factor. The EPCS modal also configures PDMP (state-mandated controlled-substance database) checks per state.

  1. Open Admin > EPCS Enrollment & Access. The modal opens to the Enrollments tab with a list of in-flight and completed enrollments.
  2. Click + New Enrollment. Pick a physician (must already exist in Physician Management with a valid DEA), confirm their DEA registration, and start the enrollment.
  3. Complete identity proofing. The physician receives an email link to an Identity Proofing (IDP) flow. They confirm personal information against credit-bureau records. This step often trips people up — make sure their name and address exactly match what's on credit/DEA records.
  4. Register two devices. Two-factor is mandatory under DEA rules. Most physicians register their iPhone (TOTP authenticator app) and a Yubikey. Hero supports any TOTP authenticator and FIDO2/WebAuthn keys.
  5. Accept the SureScripts attestation. The physician signs a legal attestation that they understand DEA requirements. This unlocks controlled-substance signing.
  6. Switch to Monitoring for active enrollments. Shows recent EPCS signing activity per physician — useful when compliance or DEA audits ask for a log.
  7. Configure PDMP per state. Each state mandates which substances trigger a PDMP check and how recently. The PDMP tab lets you flip rules (e.g. CA controlled substances, KY HB1, OH OARRS) on or off, and enforce Require PDMP check for controlled prescriptions or Require reason override when a check is skipped.
  8. Review Security Alerts. Hero surfaces unusual signing events (new device, new geo, off-hours) for follow-up. Investigate any alert flagged in red.
EPCS Enrollment modal with sidebar tabs Enrollments, Monitoring, PDMP, and Security Alerts; main pane shows the enrollments table with physician, DEA, status, devices, and requested columns
EPCS is per physician. The sidebar moves between enrollment progress, signing monitoring, per-state PDMP rules, and security alerts.
Plan the timing: Identity proofing + device registration + attestation typically takes a physician 30–60 minutes. Two-factor device delivery (Yubikey) takes 2–5 business days. Start EPCS enrollment a couple of weeks before go-live so you're not waiting on hardware on day one.
4.11Calendar sync

Sync your schedule with Google Calendar or Outlook

Calendar Sync links a clinician’s own Google Calendar or Outlook / Microsoft 365 account to Hero so the EMR schedule and their outside calendar stay aligned — outside commitments block time on the Hero schedule, and (optionally) Hero visits appear on the personal calendar. Unlike the other items on this page, Calendar Sync is per-clinician self-service: every clinician connects their own calendar from the toolbar Settings (gear) → Calendar Sync menu. Admins can also reach the same panel through Admin > External Providers, but there is no org-wide “connect everyone’s calendar” switch — each clinician authorizes their own account.

Two independent directions of sync are available, and they default differently:

Import (default ON)

Pulls busy events from your external calendar and blocks that time on the Hero schedule. It never copies event titles or details into Hero — only the busy/free time. No PHI leaves the EMR.

Export (default OFF)

Pushes your Hero scheduled visits into a dedicated SoaperEMR calendar in your linked account. This carries PHI, so turning it on requires acknowledging a PHI/BAA warning first.

Include full appointment details (PHI)

An optional export toggle. Off, exported events show busy time only. On, they add patient names and visit reasons to the events in your outside calendar.

  1. Open Calendar Sync. Click the toolbar Settings gear and choose Calendar Sync. (Admins can also open Admin > External Providers and pick the Calendar Sync tab.)
  2. Connect a provider. Each provider card — Google Calendar and Outlook / Microsoft 365 — has a Connect button that sends you through that provider’s OAuth consent screen. Sign in with the account you want to sync and approve the requested calendar access; you’re returned to Hero with the card now showing your connected account.
  3. Choose what syncs. On the connected card, Import busy time is on by default. Leave Export visits off unless you want Hero visits on your outside calendar — turning it on opens a PHI/BAA confirmation you must acknowledge. If you enable export, decide whether to also turn on Include full appointment details (PHI); otherwise exported events stay busy-time only.
  4. Keep it in sync. Sync runs automatically in the background once connected. Click Sync now to force an immediate pass, or Refresh to re-read the current connection status. A Reconnect required badge means the authorization expired or was revoked at the provider — click Connect again to re-authorize.
  5. Disconnect when needed. Click Disconnect to stop syncing and unlink the account. Existing blocked time and previously exported events are left as-is; no new sync occurs until you reconnect.
The toolbar Settings gear dropdown open with a Calendar Sync entry listed among the menu options
Calendar Sync is reached per clinician from the toolbar Settings gear — not from an org-wide admin switch.
Calendar Sync panel showing a banner that reads Calendar Sync is not enabled for this environment, with Google Calendar and Outlook / Microsoft 365 provider cards both marked Not configured
Until an administrator enables Calendar Sync and configures the OAuth credentials, the panel shows the not-enabled banner and both provider cards read Not configured — the current state on the demo environment.

Once OAuth is configured, the connected card replaces the Not configured state with your linked account name, the Import busy time / Export visits / Include full appointment details (PHI) toggles, and the Sync now, Refresh, and Disconnect controls. Enabling export raises the PHI/BAA confirmation dialog described above before any visit data is pushed.

Do not: enable Export visits to a personal Gmail or Outlook.com account. Export pushes PHI out of Hero, so it is only appropriate for a Google Workspace or Microsoft 365 account covered by a signed BAA. Personal consumer accounts are not BAA-eligible and must never be used for export. Import (busy time only) carries no PHI and is safe on any account.
Admin prerequisite: Calendar Sync only works after an administrator enables it for the environment and configures the Google / Microsoft OAuth credentials. Until then the panel shows “Calendar Sync is not enabled for this environment” and each provider card reads Not configured, so clinicians can’t connect yet. See §4.6 External Providers for where these integrations are managed.

Need help? Email support@heroemr.com.