shouldiuse.io

VERDICT

Should I use Medplum?

Open-source developer platform / headless EHR built on FHIR - medplum.com

Depends. Buy if you have engineers building a custom healthcare product and need HIPAA-compliant FHIR infrastructure. Avoid if you want ready-to-use EHR software without a dev team.

Confidence

Medium. Based on 30+ public sources: official pages, case studies, security databases, comparison articles, and Reddit threads.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources
  • Security posture

Pricing

$0

Open Source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Startup / GrowthFrom $2,000/mo
EnterpriseCustom

Best for

  • Funded startups building custom healthcare apps
  • Engineering teams needing a FHIR backend
  • Tech-enabled clinics with in-house developers
  • Teams needing HIPAA infra without building from scratch

Not for

  • Clinics wanting an out-of-box EHR — there is no finished product
  • Non-technical founders expecting a ready app
  • Small practices needing just scheduling or billing
  • Teams with no engineers to self-host or integrate

Gotchas - check before you buy

high

Self-hosting the open-source core means you own uptime, HIPAA controls, and patching

high

Active CVE stream — SSRF fixed only in 5.1.14+; pin to latest release

high

OAuth client secret exposure CVE (2026-44506) — rotate secrets if exposed

medium

Entry paid tier ~$2,000/mo; AWS Marketplace listings push 12-month contracts

Pros and cons

Pros

  • Open-source core — self-host free, avoid lock-in
  • Highly programmable EHR built on FHIR standards
  • HIPAA compliance available out of the box
  • Unified auth, access control, storage, integrations in one platform
  • Battle-tested by Ro, Summer Health, Chamber Cardio

Cons

  • Nothing usable without engineers — you build the product
  • Hosted plans start near $2,000/mo
  • Multiple 2025-2026 CVEs require prompt patching
  • Small vendor: ~$1.2M estimated ARR, thin track record

Sources & method

Analyzed 9/21/2026 - 14 sources - HIPAA-compliant platform, but multiple 2025-2026 CVEs (SSRF, OAuth secret exposure, privilege-escalation RCE) demand prompt patching.

official x4review x4security x4news x2
  • CVE-2026-44506: OAuth Client Secret Exposure, High-severity exposure of OAuth client secrets.
  • CVE-2026-49120: Server-Side Request Forgery, SSRF vulnerability in Medplum.
  • Privilege Escalation Leading to RCE, Chained privilege escalation could yield remote code execution.
  • GHSA-w852-7r27-32c6: SSRF before 5.1.14, SSRF fixed in Medplum 5.1.14.

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. Free self-host; $2k/mo hosted beats building EHR
  • Ease of use: 2/5. Developer-only; clinicians and ops staff struggle
  • Feature depth: 5/5. Full FHIR stack: auth, storage, bots, integrations
  • Support quality. No support evidence in sources
  • Security posture: 2/5. Multiple 2025-2026 CVEs despite HIPAA claims
  • $2,000/mo Starting price Hosted plans (Shyft, 2026)
  • Yes Free tier Open-source self-host
  • $1.2M Estimated ARR GetLatka estimate
  • Y Combinator Backing Alumni company

Pricing

Open Source

$0

  • Full platform self-hosted
  • You manage compliance and ops

Startup / Growth

From $2,000/mo

  • Hosted HIPAA platform
  • Support included

Enterprise

Not disclosed

  • Custom terms
  • 12-month contracts via AWS Marketplace

Security

HIPAA-compliant platform, but multiple 2025-2026 CVEs (SSRF, OAuth secret exposure, privilege-escalation RCE) demand prompt patching.

  • CVE-2026-44506: OAuth Client Secret ExposureHigh-severity exposure of OAuth client secrets.⁷
  • CVE-2026-49120: Server-Side Request ForgerySSRF vulnerability in Medplum.⁸
  • Privilege Escalation Leading to RCEChained privilege escalation could yield remote code execution.
  • GHSA-w852-7r27-32c6: SSRF before 5.1.14SSRF fixed in Medplum 5.1.14.⁹

What users say

Developers praise Medplum's programmability and FHIR foundation; non-technical buyers should expect to build, not install.

“we use and recommend medplum”
Reddit, r/healthIT
“Medplum is a highly programmable EHR”
Elion Health

Companies that use it

  • Ro⁶
  • Summer Health
  • Chamber Cardio
  • Titan
  • Ensage
Full analysis

Based on 30+ public sources: official pages, case studies, security databases, comparison articles, and Reddit threads.

Dev platform, not an EHR: great for engineers building HIPAA apps; wrong for clinics wanting off-the-shelf software.

Methodology

Based on 30+ public sources: official pages, case studies, security databases, comparison articles, and Reddit threads.

Sources

  1. Medplum Pricingmedplum.com
    official
  2. news
  3. review
  4. review
  5. review
  6. Ro Case Studymedplum.com
    official
  7. security
  8. security
  9. security
  10. news
  11. official
  12. official
  13. review
  14. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.