# Oracle Health (Cerner) — Millennium Platform APIs > Oracle Health, formerly Cerner, operates Millennium — one of the two dominant electronic health record > platforms in the United States. Its public developer surface is HL7 FHIR R4: a multi-tenant, US > Core-conformant FHIR server with SMART on FHIR OAuth 2.0, a SMART Backend Services profile for > population-scale work, Bulk Data Access export, and an open read-only endpoint that needs no > credentials at all. Cerner was acquired by Oracle in June 2022. > > Generated by the API Evangelist enrichment pipeline on 2026-08-14. Oracle Health does not publish an > llms.txt; this file is generated from the provider's own machine-readable documents (the FHIR > CapabilityStatement at /metadata and the SMART discovery document at > /.well-known/smart-configuration, both captured in this repository) plus its public documentation. ## The one thing to know first Millennium is **multi-tenant, with the tenant id in the URL path**. The service root is `https://fhir-ehr.cerner.com/r4/{tenant}/` — not a header, not a subdomain. The authorization server, the scope set and the discovery document are all tenant-scoped too. Nothing is callable until the tenant is resolved with the health system, and a wrong tenant returns `403 Tenant not valid or accessible`. ## Service roots - Production (provider persona): https://fhir-ehr.cerner.com/r4/{tenant} - Production (patient persona): https://fhir-myrecord.cerner.com/r4/{tenant} - Secure sandbox: https://fhir-ehr-code.cerner.com/r4/{tenant} - Open sandbox, read-only, **no authentication**: https://fhir-open.cerner.com/r4/{tenant} - Public sandbox tenant id: `ec2458f2-1e24-41c8-b71b-0e701af7583d` ## APIs - [FHIR R4 API](https://docs.oracle.com/en/industries/health/millennium-platform-apis/mfrap/index.html): 44 resource types. read on 42, search-type on 37, create on 19, patch on 8, update on 7, delete on 1, plus system-level batch. Named operations: Group `$export`, ChargeItem `$credit` and `$modify`, DocumentReference `$docref`, Patient `$health-cards-issue`, Binary CCD generation. - [FHIR R4 Bulk Data Access](https://docs.oracle.com/en/industries/health/millennium-platform-apis/mfbda/index.html): `$export` kick-off, job polling, NDJSON file download, job delete. - [EHR APIs](https://docs.oracle.com/en/industries/health/millennium-platform-apis/mcfap/index.html): proprietary non-FHIR Millennium APIs (allergies, conditions, personnel, messages, nomenclatures). - [FHIR DSTU 2 API](https://docs.oracle.com/en/industries/health/millennium-platform-apis/mfdap/index.html): **no longer supported.** Oracle directs all applications to R4. The documentation is still served. - SMART on FHIR App Launch: EHR launch and standalone launch, with patient/encounter/banner/style context. ## Machine-readable contracts served by the provider - CapabilityStatement (the authoritative contract): https://fhir-open.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/metadata - SMART discovery (auth endpoints + 303 scopes): https://fhir-ehr-code.cerner.com/r4/ec2458f2-1e24-41c8-b71b-0e701af7583d/.well-known/smart-configuration - JWKS: https://authorization.cerner.com/jwk There is **no** OpenAPI, no GraphQL endpoint, no MCP server and no A2A agent card. Oracle Health publishes no first-party SDK for the FHIR API. ## Specs and artifacts in this repository - openapi/cerner-millennium-fhir-r4-openapi.yml — OpenAPI 3.1, 123 operations, derived operation-for-operation from the CapabilityStatement - openapi/cerner-millennium-bulk-data-openapi.yml — OpenAPI 3.1 for Bulk Data Access - conformance/cerner-capability-statement-r4-secure.json — verbatim CapabilityStatement (secure endpoint) - conformance/cerner-capability-statement-r4-open.json — verbatim CapabilityStatement (open endpoint) - conformance/cerner-conformance.yml — 28 standards asserted with evidence - well-known/cerner-smart-configuration.json — verbatim SMART discovery document - well-known/cerner-well-known.yml — the full /.well-known probe, hits and misses - scopes/cerner-scopes.yml — all 303 advertised scopes - authentication/cerner-authentication.yml — SMART on FHIR auth profile - conventions/cerner-conventions.yml — tenancy, paging, concurrency, content negotiation - errors/cerner-problem-types.yml — OperationOutcome catalog - data-model/cerner-data-model.yml — 44 entities, 39 relationships - lifecycle/cerner-lifecycle.yml — versioning, DSTU 2 end of support, open-source archive - sandbox/cerner-sandbox.yml — the open endpoint and how to use it - packages/cerner-packages.yml — first-party libraries and their staleness - skills/ — four agent skills grounded in real operationIds - arazzo/ — three multi-step workflows ## Authentication SMART on FHIR OAuth 2.0. Authorization-code with PKCE (S256) for user-facing apps; client-credentials with `private_key_jwt` (RS384/ES384) for backend services. 303 scopes advertised on the provider persona, 145 on the patient persona, in both SMART v1 (`.read`/`.write`) and SMART v2 granular (`.crus`) forms. Endpoints are per tenant — read them from `/.well-known/smart-configuration`, never hard-code them. ## Runtime semantics an agent must respect - **Most searches require a qualifying parameter** (`_id`, or one of `patient`/`practitioner`/`location`). Without one: `400 No supported search parameters provided`. There is no list-all. - **Paging is opaque.** Follow `Bundle.link[relation=next]`; do not build page URLs. The same resource id can appear on more than one page — de-duplicate by id and keep the latest version. - **There is no idempotency key** and no conditional create/update. A retried POST creates a duplicate. Concurrency is `ETag` + `If-Match` with a documented `409 Conflict` on a stale version. - **JSON only.** A non-JSON `Accept` returns `406` with an empty body, which is easy to mistake for no data. - **Errors are FHIR OperationOutcome**, not RFC 9457 problem+json. - **A missing field is ambiguous.** `DataAbsentReason` `unknown` means not recorded; `masked` means withheld from a patient consumer. Never read a missing field as a clinical negative. - **No rate-limit headers, no published limits, no status page, no public SLA.** ## Documentation - [Oracle Health Developer Program](https://www.oracle.com/health/developer/) - [Millennium Platform APIs — Get Started](https://docs.oracle.com/en/industries/health/millennium-platform-apis/index.html) - [API index](https://docs.oracle.com/en/industries/health/millennium-platform-apis/apis.html) - [Guides](https://docs.oracle.com/en/industries/health/millennium-platform-apis/guides.html) - [R4 overview, error table and pagination](https://docs.oracle.com/en/industries/health/millennium-platform-apis/mfrap/r4_overview.html) - [Service root URLs](https://docs.oracle.com/en/industries/health/millennium-platform-apis/mfrap/srv_root_url.html) ## Gated surfaces Several operationally important pages are not readable without an account, and an integrator should know this before planning: the Authorization Framework guide, SMART Application Provisioning, Multi-Tenant Domains, the FAQ, and "API Access and Fees for Registering an App" all live on `wiki.cerner.com`, which returns **403** anonymously. The Oracle Health Developer Forums — where the FHIR DSTU 2 end-of-support dates are published — also return **403**. Registration fees and quotas therefore cannot be read publicly. ## Company - Website: https://www.cerner.com - Oracle Health: https://www.oracle.com/health/ - Developer program: https://www.oracle.com/health/developer/ - Open source: https://github.com/cerner (**archived 2026-01-06, no longer maintained**) - Security and compliance: https://www.oracle.com/corporate/acquisitions/cerner/security/ (SOC 2, ISO 27001, PCI DSS, HIPAA, FIPS 140)