AI-powered workflows that save time and surface decision-ready information within your EHR workflows, not outside them. Discover what’s possible.

 

What’s changing with data access-and what it means for you.

As the healthcare data landscape evolves, we’re consolidating third-party access into secure, legally compliant, authorized channels. This page has everything you need to understand about what’s changing and what, if anything, to do next.

You continue to have access to your data, and you decide who you share it with subject to applicable law and your agreements with PointClickCare. What’s changing is how third parties connect to our platform: through authorized, secure channels.

What’s changing

Our priority is to keep your data secure as security risks grow more sophisticated, AI accelerates how data moves, and regulatory scrutiny tightens.

Vendor access moves to approved pathways

Third-party access now flows through secure, authorized channels.

Data Relay and Custom Extracts

These tools remain yours to use. PCC no longer facilitates vendor access this way.

New, expanded pathways are available

Authorized screen scraping and expanded API access gives vendors secure, scalable ways to connect.

Your data rights are unchanged

You retain the right to access, use, and exchange your data, subject to applicable law and your agreements with PCC. You can still self-manage, copy, and route data within your own secure environment.

Why we’re making these changes

Protecting your data and keeping your operations running are our highest priorities. Healthcare data is one of the most valuable targets there are, and AI is rapidly multiplying the ways it can be accessed. When access isn’t governed, it becomes very hard to tell an authorized vendor apart from a bad actor. Consolidating access into secure, governed channels closes that gap.

Clearer visibility into who’s reaching your data

Secure, auditable pathways provide a clear view of who is accessing your data and how. Today, ungoverned access can look the same to us as a threat actor.

Keeping systems stable for care delivery

Unmanaged, high-volume automated access strains the systems your teams rely on every day, and governing this traffic keeps the platform stable.

More ways to connect, not fewer

We’re adding pathways, including authorized screen scraping—the first program of its kind. We continue investing in USCDI-based APIs, interoperability standards, and 500+ integrated partners.

Approved vs. not-approved vendor access

A quick reference for you and your vendors on what’s supported today.

API programs

Robust API access and formal integration programs through the PCC Marketplace and USCDI Connector programs.

Authorized screen scraping

Formally reviewed, approved, and operated within PCC’s governance framework, with appropriate security and monitoring controls.

Self-managed

You may continue to self-manage, copy, and route your own data within your own external secure environment.

Unauthorized methods

Unsanctioned screen scraping, bots, browser extensions, or credential sharing. Vendors using these methods will need to transition to an approved pathway.

Your next steps

For most customers, little or nothing changes day to day. If you work with third-party vendors, here’s how to stay ahead of it.

You have every right to share your data. When you do, we encourage you to confirm how each vendor will access, use, store, and protect that data on your behalf:

  • Which method do they use to access PCC today?
  • What data are they accessing, and where is it stored?
  • How is it used, and is patient consent in place?

Vendors using an unauthorized method should submit our integrations form to reach the Partnerships team, who will review their needs and support onboarding to an approved pathway.

Submit a request

Frequently asked questions

No. You retain the right to access, use, and exchange data, subject to applicable law and your agreements with PCC. You can continue to self-manage, copy, and route your data to third-party vendors within your own external secure environment. What’s changing is that third-party access—someone accessing data who does not create it nor have a treating relationship with a patient—to our platform now happens through authorized, secure pathways.

These updates do not change your rights under applicable law or your agreements with PCC. These updates govern how third parties connect to the PointClickCare platform—through authorized pathways that meet our security, compliance, and technical requirements—so that access is secure and accountable for everyone on the platform.

Our priority is to minimize disruption. Existing approved workflows continue during the transition, subject to future notice. We work directly with vendors to make sure approved pathways are in place, and we’ll provide advance notice and transition support where reasonably practicable if any adjustments are needed.

All data extraction facilitated through PCC must occur via authorized pathways that meet our security, operational, technical, and compliance requirements. Unauthorized methods—unsanctioned screen scraping, bots, browser extensions, and credential sharing—are not permitted. Custom Extracts and Data Relay are not approved for third-party vendor access, and as of March 20, 2026, we’re no longer accepting new Letters of Authorization for Data Relay. Existing arrangements continue to be supported until further notice.

Protecting your data and keeping your operations secure and uninterrupted are our highest priorities. As security risks, AI innovation, and regulatory scrutiny increase, consolidating third-party access into secure, modern, governed channels strengthens platform security, supports compliance and interoperability, and reduces system strain.

Yes. There are no current plans to change customer use of Custom Extracts for your own internal systems. Requests where the intent is to share data with a vendor will be redirected to approved, authorized vendor integration channels.

Authorized screen scraping is an optional service we built in response to demand for data that isn’t accessible by other means—vendors aren’t obligated to use it. For those who choose it, the fee reflects the costs of providing secure, monitored access at scale, including the infrastructure, monitoring, and governance needed to support automated activity that can draw more heavily on our systems than normal human use. Pricing is applied consistently across vendors using this option.

We work directly with you and the vendor to find an authorized pathway that meets their needs. If unauthorized activity continues, it may be throttled to protect platform security and performance, but we work hard to transition vendors well before it comes to that.

Today we support USCDI v3 standards with our USCDI Connector program and offer secure, scalable integration across more than 25 categories via our Marketplace. We’re continuously expanding our interoperability capabilities and will share updates as enhanced API features become available.

Still have questions?

Your account team is your first point of contact for questions. Vendors should reach out via our integrations form.

Contact your account team