# Select Medical Holdings > Select Medical Holdings Corporation is one of the largest operators of specialty hospitals and > outpatient rehabilitation clinics in the United States. It is not a software vendor and runs no > commercial developer program, but as a covered healthcare provider on Epic it operates a live > HL7 FHIR R4 patient-access API secured with SMART-on-FHIR OAuth 2.0. Generated by API Evangelist on 2026-08-28 from artifacts in this repository. This file was authored by API Evangelist, not by Select Medical. Select Medical serves no llms.txt of its own (https://www.selectmedical.com/llms.txt returned HTTP 403 from a WAF that answers 403 for every path, including paths that do not exist). ## What is actually callable The one machine-readable API surface is a FHIR R4 server: - Base URL: https://epicproxy.et0948.epichosted.com/FhirProxy/api/FHIR/R4 - Standard: HL7 FHIR R4 (4.0.1) with US Core 6.1.0 profiles - Auth: SMART-on-FHIR OAuth 2.0 — no anonymous access to any clinical data - Registered as "Select Medical" in Epic's public endpoint directory since 2024-11-09 - 59 resource types, 702 declared search parameters, 133 operations A legacy FHIR DSTU2 (1.0.2) endpoint is also still listed active: https://epicproxy.et0948.epichosted.com/FhirProxy/api/FHIR/DSTU2 ## Anonymous discovery endpoints These two return HTTP 200 with no credentials and are the correct starting point: - [CapabilityStatement](https://epicproxy.et0948.epichosted.com/FhirProxy/api/FHIR/R4/metadata): the server's own contract - [SMART configuration](https://epicproxy.et0948.epichosted.com/FhirProxy/api/FHIR/R4/.well-known/smart-configuration): OAuth endpoints and capabilities ## Specifications - [OpenAPI 3.1 (derived from the CapabilityStatement)](openapi/select-medical-holdings-fhir-r4-openapi.yml) - [FHIR R4 CapabilityStatement (verbatim)](fhir/select-medical-holdings-r4-capabilitystatement.json) - [FHIR DSTU2 Conformance (verbatim)](fhir/select-medical-holdings-dstu2-capabilitystatement.json) ## Integration semantics - [Authentication](authentication/select-medical-holdings-authentication.yml): SMART App Launch, PKCE S256, refresh tokens - [OAuth scopes](scopes/select-medical-holdings-scopes.yml): 5 enumerated non-FHIR scopes; resource scopes granted per app - [Conventions](conventions/select-medical-holdings-conventions.yml): pagination, versioning, idempotency, reversibility - [Error catalog](errors/select-medical-holdings-problem-types.yml): FHIR OperationOutcome, not RFC 9457 - [Data model](data-model/select-medical-holdings-data-model.yml): 59 entities, 152 derived relationships - [Conformance](conformance/select-medical-holdings-conformance.yml): FHIR, US Core, SMART, OAuth2, OIDC - [Lifecycle](lifecycle/select-medical-holdings-lifecycle.yml): version history and platform release - [Well-known documents](well-known/select-medical-holdings-well-known.yml): probe results for every host ## What an agent must know before writing Read this before any POST or PUT: - There is NO delete interaction on any of the 59 resource types. - There is NO idempotency key, NO conditional create and NO ETag concurrency control (conditionalCreate, conditionalUpdate and updateCreate are false on every resource). - There is NO $validate operation, so a write cannot be rehearsed. - Therefore a timed-out create CANNOT be safely retried, and a mistaken write CANNOT be undone through the API. Treat every write as permanent and at-most-once. ## What does not exist Recorded so an agent stops looking: - No developer portal, no API documentation site, no pricing, no published rate limits - No api., developer. or developers.selectmedical.com host (all NXDOMAIN) - No MCP server, no A2A agent card, no first-party SDK or CLI, no status page - No security.txt, no bug bounty, no trust center - No changelog, no sandbox, no Postman collection ## Human entry points - [Select Medical](https://www.selectmedical.com) - [MyChart patient portal — sign up](https://mychart.selectmedical.com/MyChart/signup) - [MyChart patient portal — log in](https://mychart.selectmedical.com/MyChart/Authentication/Login) - [Epic public FHIR endpoint directory](https://open.epic.com/Endpoints/R4)