# Medical Records API — Extraction & Webhooks

> Medical records API with REST case creation, CRM token exchange, and webhooks — plus per-case metering, so processing cost can be billed back to the file.

Canonical page: https://medrecords.ai/product/medical-data-api/

---
NewWe now read the actual MRI and CT imaging — not just the radiologist's 1-page report. [See how →](https://medrecords.ai/product/imaging/)
[Home](https://medrecords.ai/) ›[Product](https://medrecords.ai/product/) › — Medical Data API & Analytics
MEDICAL RECORDS API

## Build case creation into your own systems.

Medical records API access builds case creation into your own systems: a REST API for the whole case lifecycle, CRM token exchange, and webhooks that push events to you instead of polling. Per-case usage metering lets processing cost be billed back to the file, and the same cited, audit-grade output arrives machine to machine.

[Test a file ](https://medrecords.ai/test-a-file/?src=product-medical-data-api)
 [Book a demo](https://medrecords.ai/demo/)
[Talk to us about API access ](https://medrecords.ai/contact/)
Create a case · REST
 201 Created
POST /v1/cases
{
"external_ref": "IME-4812",
"claimant": "Adams, Timothy",
"matter": "right knee",
"documents": 342 // pages, 2 packets
}
Webhook events
case.created
 delivered
case.processing.complete
 delivered
report.ready
 pending
REST · Webhooks · SFTP · Token exchange
Create cases, receive events, and deliver cited reports machine to machine — **metered per case for bill-back** .

### A REST API for the whole case lifecycle.

Create a case from your intake system, push documents to it, and pull back structured output — chronology events, extracted entities, finished reports — as JSON or files. Your team keeps working in the tools they already have; the extraction engine runs behind them.

Programmatic case creation and document upload
Structured, citation-carrying JSON out — not a black box
Endpoints
POST — /v1/cases — create a case
POST — /v1/cases/{id}/documents — upload records
GET — /v1/cases/{id}/chronology — cited events
GET — /v1/cases/{id}/reports — finished output
GET — /v1/usage?case={id} — metering
Scoped keys, HTTPS only, **every call logged** to the case audit trail.
Webhook delivery
 signed payloads
{ "event": "report.ready",
"case": "IME-4812",
"report": "summary_cited.docx",
"citations": "preserved" }
→ Your claims system
 webhook
→ Your document store
 SFTP
→ Your matter management
 API pull

### Events push to you. No polling.

Register an endpoint, subscribe to the events you care about, and your systems stay current on their own: case created, processing complete, report ready. Finished reports deliver by API or SFTP with citations preserved in the payload — machine delivery, same evidentiary standard.

Signed webhook payloads with retry on failure
Report delivery via API pull or SFTP drop

### Token exchange your CRM already understands.

Your CRM or case-management system swaps its server credential for a scoped, short-lived Medrecords AI token — no shared passwords, no service account with god-mode. Access maps to the same case-level permissions your users already have, and every call is metered against the case that made it.

Scoped, short-lived tokens; case-level permissions
Usage exports per case, per client, or per period
Usage metering · bill-back
 per case
Case — Pages processed — Bill to
IME-4812
 342
 matter
Batch · 2 packets
 metered on ingest
 client
Reports generated
 itemized
 carrier
Exports your finance team can reconcile — **cost follows the case** .
Payload · chronology event
{ "event": "Progress Note",
"finding": "improving since 4/02",
"citation": {
"page": 412,
"source": "Pinnacle Ortho & Spine" } }
If a fact leaves the platform, its citation leaves with it.
The standard

### Citations survive the API boundary.

Every extracted fact in every payload carries its page anchor and source document, so what lands in your claims system is as audit-grade and legally defensible as what a reviewer sees in the workspace. Integration doesn't dilute the evidence — and every API call is logged to the case's chain of custody.

[See Verifiable AI Citations ](https://medrecords.ai/product/citations/)

### From your intake system to a cited report.

3 steps, and none of them involve a human re-keying case data.

01
Provision access
Scoped API keys or CRM token exchange, mapped to your existing case-level permissions.

02
Integrate the loop
Create cases and push documents over REST; subscribe to webhooks so results come back on their own.

03
Meter and bill back
Pull per-case usage exports and pass processing cost through to the matter, client, or carrier.

### Who integrates it.

Teams with systems of record that shouldn't grow a manual upload step.

[
TPAs & case management
Case creation wired to intake; per-case metering billed back to each carrier client.

For TPAs
 ](https://medrecords.ai/solutions/tpas/)
 [
Insurance carriers
Claims data webhooks feed the claims platform; adjusters never leave their queue.

For carriers
 ](https://medrecords.ai/solutions/insurance-carriers/)
 [
Law firms
Matter management stays the source of truth; cited work product flows back into it.

For law firms
 ](https://medrecords.ai/solutions/law-firms/)
FAQ

### The medical records API, answered.

Create cases programmatically, upload documents to them, and pull back the structured outputs — chronology events, extracted entities, and finished reports — as JSON or files. Anything your team does in the workspace, your intake system can trigger over HTTPS.

You register an endpoint and subscribe to events such as case created, processing complete, and report ready. When the event fires, we POST a signed payload to your endpoint so your claims or matter system updates itself — no polling.

A server-to-server token exchange that lets your CRM or case-management system act on behalf of its own users without sharing passwords. Your system swaps its credential for a scoped, short-lived Medrecords AI token, so access maps to the same case-level permissions your users already have.

Every page processed and report generated is metered against the case it belongs to. Usage exports roll up per case, per client, or per period, so a firm can pass processing cost through to the matter and a TPA can bill it back to the carrier — figures your finance team can reconcile.

Yes. Finished reports and structured data can be delivered to your systems via the API or SFTP drop, with the citations preserved in the payload — every extracted fact still carries its page anchor and source document.

### Related capabilities

[
Audit Trail & Chain of Custody
Every API call, ingest, and export in one immutable, exportable log.

Explore
 ](https://medrecords.ai/product/audit-trail-chain-of-custody/)
 [
Custom Report Builder
The templated reports your integration delivers — jurisdiction- and line-specific.

Explore
 ](https://medrecords.ai/product/custom-report-builder/)
 [
Automated Claims Triage
Bulk-process claim portfolios via the same pipeline your API calls reach.

Explore
 ](https://medrecords.ai/product/automated-claims-triage/)

### Wire the record pipeline into your stack.

Test a file to see the output your systems would receive, or talk to us about API access, sandbox keys, and integration scoping. Handled under our BAA; never used to train a model.

[Test a file ](https://medrecords.ai/test-a-file/?src=product-medical-data-api)
 [Book a demo](https://medrecords.ai/demo/)
[Talk to us about API access →](https://medrecords.ai/contact/)
 [All capabilities →](https://medrecords.ai/product/)
