EHR to Google Calendar Sync — Without the PHI
Your providers live in Google Calendar. Your appointments live in your EHR. Orisan Connect pushes EHR appointments onto staff calendars automatically, with a redaction firewall enforced in code that refuses to send any event containing protected health information (PHI).
Note: This integration is export-only by design. Appointments flow from your EHR to Google Calendar — never the other way — so your EHR remains the single source of truth for scheduling.
Technical Overview
- Protocol
- Google Calendar API v3
- Authentication
- OAuth 2.0 consent flow
- Direction
- Export-only (EHR → Calendar)
- Entity Types
- Appointments
- PHI on Calendar
- None — enforced by firewall
Privacy By Default
You control what appears on the calendar
Three redaction levels, one rule: patient names, visit reasons, and clinical notes never reach Google Calendar.
Time Only
Events show a generic busy block — start, end, and nothing else. Maximum privacy for shared calendars.
Minimal
Adds appointment type and patient initials only (like "J.D.") — never a full name, never a reason for visit.
Detailed
Adds provider and visit-type context for internal scheduling. Still redacted: reason, notes, and full names are always blocked.
How It Works
Three steps to calendar sync
Connect
Authorize with Google's standard OAuth consent screen. Orisan Connect requests calendar access only — tokens are encrypted and refreshed automatically.
Configure
Pick the target calendar, choose a redaction level, and set attendee and notification behavior. Privacy-first defaults out of the box.
Sync
New and updated EHR appointments appear on staff calendars automatically. Cancellations clear the calendar too — no manual cleanup.
Key Features
Calendar convenience without the compliance risk
PHI Firewall, Enforced in Code
Google Calendar is not a clinical system, so no Protected Health Information may reach it. Every event passes through a redaction chokepoint that strips names, visit reasons, notes, and locations — then a final guard re-checks the assembled event and refuses to send it if anything slipped through.
Three Redaction Levels
You choose how much non-PHI context appears on each event: a bare busy block, appointment type with patient initials, or internal scheduling detail. The firewall applies at every level.
Proactive Token Refresh
Google OAuth tokens are refreshed automatically before they expire. If a connection does need re-authorization, you're notified before syncs are affected — not after they fail.
Attendee & Notification Controls
Decide which staff calendars receive events, whether Google sends update notifications, and whether patient invites are allowed — patient invites stay off until a compliance acknowledgement is explicitly recorded.
Works With Your EHR
Pair calendar export with your EHR sync
Put appointments where your team already looks
Schedule a demo to see EHR appointments land on a Google Calendar — PHI-free — in real time.