Most vendors on this list publish BAA availability now. That's no longer what separates them. Four things are: can the agent act as the clinician through SMART on FHIR, does PHI stay out of the platform's storage and logs, can it run inside your or your customer's cloud with your own keys, and what does the audit trail prove.
Healthcare agents need two layers, and most lists blur them. A data and network layer (Redox, Health Gorilla, Particle, Metriport) gets you records from many sources. An action and authorization layer (Scalekit, Nango, Merge, Composio, Arcade) lets your agent call tools as a specific user across EHRs and SaaS apps. Plenty of teams need both.
For SaaS-style agent tool calling with enterprise compliance, Merge and Nango are credible options. For agents that act on EHRs as the clinician, run self-hosted, and keep PHI out of logs, Scalekit is built for that case. For no-code practice workflows, Keragon fits better than any developer platform.
What makes an agent integration platform right for healthcare
General SaaS integration criteria (connector count, framework support, pricing) still apply. Healthcare adds six that decide whether you pass a hospital security review:
EHR authorization model. Does the platform support SMART on FHIR user-context authorization, where the agent acts with the clinician's scopes? Or only Backend Services, where the EHR sees a system account? This decides whether actions are attributable.
Per-user delegation everywhere. The same agent touches the EHR, a payer portal, Gmail, Salesforce Health Cloud and Slack. Each call should run as the user the agent is acting for.
The PHI data path. Are tool-call payloads written to disk, cached, or included in logs? HHS's own guidance says holding encrypted PHI without the key still makes a vendor a business associate. What the platform persists defines your compliance surface.
BAA terms, not just existence. Which plan includes it, and which subprocessors are covered.
Deployment boundary and keys. Managed cloud, your VPC, your customer's cloud, air-gapped. Customer-managed keys (BYOK) for stored credentials.
Audit evidence. Who authorized, which agent, which tool, which scope, and the outcome, exportable to the customer's SIEM without dragging PHI along.
The two layers of healthcare agent integration
Data and network platforms answer "how do I get this patient's records from everywhere?" Action and authorization platforms answer "how does my agent act, as this clinician, across every system they use, with proof?" The list below covers both, labeled.
Comparison at a glance
Platform
Layer
SMART on FHIR (user-context)
HIPAA BAA
Best for
Scalekit AgentKit
Action & auth
Yes (any FHIR server + AdvancedMD)
Yes, Enterprise
Agents acting on EHRs and SaaS as the clinician
Nango
Action & auth + sync
No. Epic via Backend Services only
Enterprise only
Data sync plus tool calling, code-first teams
Merge Agent Handler
Action & auth
Not documented
Yes
Broad certifications, US/EU/APAC hosting
Composio
Action & auth
Not documented
Add-on (Scale); included (Enterprise)
Large tool catalog, fast prototyping
Arcade.dev
Action & auth
Not documented
Not published
Multi-user MCP tool calling
Paragon ActionKit
Action & auth
Not documented
Enterprise
Embedded SaaS integrations with agent actions
Keragon
No-code workflow + MCP
Not documented (30+ EHR integrations via workflow platform)
All plans
Practices and ops teams automating without code
Redox
Data & network
Network model (not per-user delegation)
Yes (confirm)
Many EHRs behind one contract, HL7 v2
"Not documented" means we couldn't find it in the vendor's public docs, not that it doesn't exist. Ask them.
1. Scalekit AgentKit
Layer: Action & authorization
Best for: AI agent products that act on EHR data and SaaS tools as a specific clinician or patient, and need to pass a health-system security review.
Scalekit was built as an authorization and tool-calling runtime for agents from the first release. It has no sync platform underneath. In healthcare, that shows up in four places.
EHR access as the clinician. A generic SMART on FHIR connector takes any EHR's FHIR base URL, discovers the OAuth configuration from the server, and handles the aud parameter and token lifecycle. A pre-built AdvancedMD connector is also available. Every call runs under the authorizing clinician's SMART scopes, so the EHR's audit trail and Scalekit's both name a person, not a bot.
PHI stays out of the platform. Tool-call requests and responses are processed in memory and never written to disk or logs. What Scalekit does store (OAuth tokens, API keys) is AES-256 encrypted with a key unique to each customer, wrapped by a KMS master key. For BAA-signed accounts, only two subprocessors touch customer data — GCP and CockroachDB, both under BAAs. All other subprocessors are disabled.
Deploys inside the boundary. Managed cloud (US or EU residency), your VPC on AWS, GCP or Azure, your customer's infrastructure, or fully air-gapped with offline licensing. The SDKs and APIs are identical across all of them. Both cloud and on-prem Enterprise deployments are HIPAA eligible with a signed BAA.
Scoped tools and audit. Virtual MCP Servers give each agent or role its own tool surface: a chart-prep agent gets read tools, and a write-back agent gets a separate write tool set that your application can put behind an approval step. Scalekit holds the credential state while a call waits. Every call is logged as metadata only (who authorized, which agent, which tool, which scope, status, latency) and streams to Datadog, Splunk or any SIEM. This kind of agent tool observability is essential for healthcare compliance.
Beyond EHRs: 500+ connectors and 20K+ actions, including SaaS apps, healthcare-specific MCP servers, and bring-your-own connectors for internal systems. Ten auth methods, including SMART on FHIR, OAuth 2.0 and 2.1, API keys, and Google domain-wide delegation. On the MCP side, it supports Client ID Metadata Documents for client registration and enterprise-managed authorization through Cross App Access (XAA).
Compliance: SOC 2 Type II, ISO 27001, GDPR, CCPA. HIPAA BAA and custom DPA on Enterprise.
Limitations:
It's not a data network. If you need records aggregated from HIEs or TEFCA, pair it with one of the network platforms below.
It doesn't normalize payloads into a common schema. That's a deliberate choice, because agents reason better on native FHIR, but teams wanting a unified data model should know.
2. Nango
Layer: Action & authorization, plus data sync
Best for: teams whose main need is data synchronization (syncs, webhooks, unified models), with tool calling as a second use case, and who want to own every tool as code.
Nango is a mature integration platform that added agent tool calling through Agent Sessions. It has broad API coverage, OpenTelemetry-native observability, and a source-available runtime you can self-host.
Healthcare posture:
SOC 2 Type II on all plans.
BAA on Enterprise only.
BYOC self-hosting on Enterprise. Nango notes "we currently don't have an EU cloud."
Epic is supported through SMART Backend Services only. Its Epic docs describe one connection per health system with no end-user OAuth redirect. That works for system-level jobs, but actions are attributed to the app, not the clinician.
It also offers athenahealth and Health Gorilla integrations, and publishes a healthcare case study with XY.AI Labs.
Nango vs Scalekit for healthcare agents:
Scalekit
Nango
EHR authorization
SMART on FHIR user-context: acts as the clinician
Epic via Backend Services: acts as the app
Tool bundles
Named, reusable Virtual MCP Servers per agent or role
Toolset JSON sent on each session creation
Encryption keys
Per-customer DEK by default; bring your own KMS key
Platform-managed key
BAA
Enterprise (cloud and on-prem)
Enterprise
Data sync
Not the focus
Core strength
Observability
Metadata events to any SIEM
OpenTelemetry-native
The wider field is also covered in our Nango alternatives comparison. The two can also work together: Nango for bulk sync into your store, Scalekit for real-time per-user actions.
3. Merge Agent Handler
Layer: Action & authorization
Best for: teams that want the broadest certification set and multi-region hosting out of the box.
Certifications: SOC 2 Type II, ISO 27001, HIPAA, GDPR and CCPA, plus a published BAA.
Access and keys: customer-managed keys, and user-scoped access so tool calls run under a registered user's credentials.
Hosting: Enterprise adds single-tenant hosting, EU and APAC residency, VPC peering and "on-premises options."
Logs: tool-call data is kept for 90 days by default. Ask what that data includes if payloads may contain PHI.
Price: the Pro plan starts at $1,000/month.
EHR connectors: we found no EHR or SMART on FHIR support in Merge's public docs.
Best for: fast prototyping across a very large tool catalog.
Compliance options: the BAA is an add-on on Scale and included on Enterprise. Enterprise adds customer-managed keys, zero data retention, IP allowlisting and SSO/SCIM. Log retention is 7 days, 30 days or custom.
Security incident: in May 2026, Composio disclosed a security incident in which an attacker escalated from an internal agentic tool. About 5,001 GitHub connections and 5,241 API keys were potentially exposed. Remediation included envelope encryption and customer-managed KMS. Healthcare security teams will ask about it.
EHR connectors: we found no EHR or SMART on FHIR connectors documented.
Best for: teams standardizing on MCP with multi-user authorization.
Positioning: Arcade's core is per-user authorization for MCP tools. It co-authored the MCP URL Elicitation proposal, and it publishes a series of healthcare MCP guides.
Certification: SOC 2 Type 2.
Deployment: Arcade Cloud, Azure and AWS marketplace offers, Helm on Kubernetes, and a hybrid mode.
BAA: we didn't find one published. Its healthcare guide says Arcade manages "tokens and secrets, not patient data."
EHR connectors: there's no built-in EHR connector. FHIR MCP servers are discussed generically.
Layer: No-code healthcare workflow automation, with MCP
Best for: practices and digital health ops teams automating workflows without engineering.
Compliance: a BAA is included on every plan, and Keragon is SOC 2 Type II.
MCP (beta): Keragon MCP connects Claude, ChatGPT and voice agents to 30+ EHRs (athenahealth, DrChrono, Healthie, AdvancedMD, Tebra, eClinicalWorks) and 300+ tools.
Model: it's workflow-first, not an embeddable developer SDK, and doesn't document per-end-user delegated auth.
Shared responsibility: Keragon's own docs note that "customers govern PHI use across the full workflow."
8. Data and network platforms (pair with an action layer)
These aren't agent tool-calling platforms, but most healthcare agent teams evaluate at least one:
Redox. EHR integration network normalizing HL7 v2, CDA, X12 and FHIR across 12,000+ connected organizations. Its MCP server (June 2026) manages Redox configuration and logs, not patient data.
Health Gorilla. TEFCA QHIN with lab, pharmacy, ADT and network data. HITRUST certified.
Particle Health. National network aggregator across Carequality, CommonWell and eHealth Exchange. HITRUST and SOC 2.
Metriport. Open-source network access and data platform. SOC 2 Type II and HITRUST r2.
Medplum and Aidbox. FHIR servers and platforms. Aidbox's MCP module uses client-credentials access, not per-user delegation.
How they fit with an action layer: use the network to assemble the longitudinal record, and the action layer for everything the agent does as a user: EHR writes through SMART, payer portals, email, CRM and ticketing.
How to choose
Your agent writes to the chart or acts for clinicians → you need SMART on FHIR user-context and metadata-only audit. That rules out Backend-Services-only platforms for the interactive path.
Your enterprise customers require private deployment → shortlist platforms with VPC and customer-infrastructure options and the same API across deployments.
Your main problem is getting records from many sources → start with a network platform, then add an action layer.
You need SaaS tool calling with broad certifications and no EHR actions → Merge or Nango are reasonable.
You're a practice automating ops without engineers → Keragon.
An agent integration platform handles authentication, token storage, scoping and tool execution between an AI agent and the third-party systems it acts on (EHRs, CRMs, email, payer tools), so the agent can call tools as a specific user without holding credentials. In healthcare, it also needs a BAA, controls on where PHI goes, and audit evidence.
Which agent integration platforms sign a HIPAA BAA?
Scalekit (Enterprise), Nango (Enterprise), Merge, Composio (add-on or Enterprise), Paragon (Enterprise) and Keragon (all plans) publish BAA availability. We couldn't find a published BAA for Arcade. Plan gating varies, so confirm which subprocessors the BAA covers.
Which platforms support SMART on FHIR for AI agents?
Scalekit supports SMART on FHIR user-context authorization against any FHIR server, plus a pre-built AdvancedMD connector. Nango supports Epic through SMART Backend Services, which is system-level access. Keragon offers 30+ EHR integrations through its workflow platform but doesn't document SMART on FHIR user-context support. Merge, Composio, Arcade and Paragon don't document SMART on FHIR support.
Is a BAA enough to make an AI agent HIPAA compliant?
No. A BAA is a contract. Compliance also depends on safeguards: minimum-necessary access, audit controls under 45 CFR 164.312(b), encryption, and a complete BAA chain covering every subprocessor, including your LLM provider and tool-calling layer. Model-provider BAAs have feature exclusions (Anthropic's, for example, excludes most MCP and third-party integrations), so the tool layer needs its own coverage.
Do I need Redox or an agent integration platform?
Often both. Redox, Health Gorilla and Particle aggregate and normalize records across many EHRs and networks. Agent integration platforms let the agent act as a specific user across EHRs and SaaS tools, with per-user tokens, scoped tools and audit. Use the network for data assembly and the action layer for writes and cross-app workflows. Understanding access control for multi-tenant AI agents is key when operating across both layers.
Can agent integration platforms be self-hosted for healthcare?
Some can. Scalekit deploys in your VPC, your customer's infrastructure, or air-gapped environments with the same SDKs. Nango offers BYOC on Enterprise. Paragon offers VPC and forward-deployed options. Arcade supports Kubernetes. Merge lists on-premises options on Enterprise. For teams evaluating the build-versus-buy decision on this infrastructure, see our analysis of the hidden cost of building OAuth internally for AI agents.