Skip to content

API reference

Clinical cases

Report progress, message the patient, resolve.

Confirm processing, report clinical progress, send patient-visible messages, and explicitly resolve escalated cases.

Read current external-care progress

GET/v1/clinical-cases/{caseId}/progress

Use this endpoint to reconcile sequence conflicts and confirm the next accepted sequence. Transport delivery and provider processing are intentionally separate fields.

API key. Authorization: Bearer nzh_sb_… in sandbox, nzh_prod_… in production: Authentication.

Parameters

FieldTypeDescription
caseIdRequiredpath · string (uuid)The canonical UUID from the clinical_case.opened webhook. This is not the patient-facing NC-XXXXXXXX reference.
cURL
curl "https://api.nezercare.com/v1/clinical-cases/CASE_ID/progress" \
  --request GET \
  --header "Authorization: Bearer $NEZER_API_KEY"

Responses

StatusMeaning
200Current progress.
400The request is malformed or violates the operation contract.
401The API credential is missing, invalid, expired, or revoked.
403The organization hasn't signed its BAA, so patient features (and API keys) are off. An owner or administrator signs it in Settings; it takes effect at once.
404The resource is not accessible in this credential's environment.
409The idempotency identifier was reused with different content, or an update is out of sequence.

200 body

FieldTypeDescription
caseIdRequiredstring (uuid)
statusRequiredstring
sequenceRequiredintegerAt least 0.
nextSequenceRequiredintegerAt least 1.
confirmationOverdueRequiredboolean
confirmationDueAtstring (date-time) or null
transportDeliveredRequiredboolean
scheduledForstring (date-time) or null
updatedAtstring (date-time)
externalReferencestring or null
200 response
{
  "caseId": "150d31aa-c9ed-4624-b516-8f7f354f0848",
  "status": "awaiting_processing",
  "sequence": 0,
  "nextSequence": 1,
  "confirmationOverdue": false,
  "transportDelivered": true,
  "externalReference": null
}
401 response
{
  "code": "INVALID_API_CREDENTIAL",
  "message": "API credential is invalid."
}
403 response
{
  "code": "BAA_REQUIRED",
  "message": "Sign your BAA to turn on patient features. An owner or administrator can sign it in Settings."
}

Report provider-workflow progress

POST/v1/clinical-cases/{caseId}/updates

The first update must be processed at sequence 1. Later updates may report scheduling, clinician response, patient contact, or final resolution. Use the same updateId and identical body when retrying.

API key. Authorization: Bearer nzh_sb_… in sandbox, nzh_prod_… in production: Authentication.

Parameters

FieldTypeDescription
caseIdRequiredpath · string (uuid)The canonical UUID from the clinical_case.opened webhook. This is not the patient-facing NC-XXXXXXXX reference.

Request body

FieldTypeDescription
updateIdRequiredstring (uuid)
sequenceRequiredinteger1 to 1000000.
statusRequiredstringOne of processed, scheduled, clinician_responded, patient_contacted, resolved.
externalReferenceRequiredstring1–200 characters.
scheduledForstring (date-time)
resolutionOutcomestringOne of patient_contacted, provider_follow_up, medication_adjusted, emergency_referral, no_further_action, other.
resolutionNotestring10–2000 characters.
cURL
curl "https://api.nezercare.com/v1/clinical-cases/CASE_ID/updates" \
  --request POST \
  --header "Authorization: Bearer $NEZER_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{
    "updateId": "d574b886-f658-43dc-a62a-6c66ef74682d",
    "sequence": 1,
    "status": "processed",
    "externalReference": "provider-conversation-001"
  }'
Appointment scheduled
{
  "updateId": "8bb876eb-c77e-4686-b8f0-e4f76333670a",
  "sequence": 2,
  "status": "scheduled",
  "externalReference": "appointment-456",
  "scheduledFor": "2026-09-08T14:30:00-04:00"
}
Case resolved
{
  "updateId": "947ea6c9-cdb3-48d7-874b-bfcd59b54e99",
  "sequence": 3,
  "status": "resolved",
  "externalReference": "provider-conversation-001",
  "resolutionOutcome": "provider_follow_up",
  "resolutionNote": "Clinician reviewed the concern and provided follow-up guidance."
}

Responses

StatusMeaning
200Progress recorded or an identical retry recognized.
400The request is malformed or violates the operation contract.
401The API credential is missing, invalid, expired, or revoked.
403The organization hasn't signed its BAA, so patient features (and API keys) are off. An owner or administrator signs it in Settings; it takes effect at once.
404The resource is not accessible in this credential's environment.
409The idempotency identifier was reused with different content, or an update is out of sequence.

200 body

FieldTypeDescription
caseIdRequiredstring (uuid)
updateIdRequiredstring (uuid)
sequenceRequiredinteger
statusRequiredstring
duplicateRequiredboolean
401 response
{
  "code": "INVALID_API_CREDENTIAL",
  "message": "API credential is invalid."
}
403 response
{
  "code": "BAA_REQUIRED",
  "message": "Sign your BAA to turn on patient features. An owner or administrator can sign it in Settings."
}

Send a message to the patient

POST/v1/clinical-cases/{caseId}/messages

The encrypted message appears in the patient's secure case conversation. Do not put internal clinical notes in this patient-visible field. The patient receives a privacy-safe email without the message body.

API key. Authorization: Bearer nzh_sb_… in sandbox, nzh_prod_… in production: Authentication.

Parameters

FieldTypeDescription
caseIdRequiredpath · string (uuid)The canonical UUID from the clinical_case.opened webhook. This is not the patient-facing NC-XXXXXXXX reference.

Request body

FieldTypeDescription
messageIdRequiredstring (uuid)
messageRequiredstring1–4000 characters.
externalReferenceRequiredstring1–200 characters.
cURL
curl "https://api.nezercare.com/v1/clinical-cases/CASE_ID/messages" \
  --request POST \
  --header "Authorization: Bearer $NEZER_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{
    "messageId": "a321530a-f9fe-4435-8593-38eb75174854",
    "message": "A clinician reviewed your concern. Have your symptoms changed today?",
    "externalReference": "provider-message-456"
  }'

Responses

StatusMeaning
200Message created or an identical retry recognized.
400The request is malformed or violates the operation contract.
401The API credential is missing, invalid, expired, or revoked.
403The organization hasn't signed its BAA, so patient features (and API keys) are off. An owner or administrator signs it in Settings; it takes effect at once.
404The resource is not accessible in this credential's environment.
409The idempotency identifier was reused with different content, or an update is out of sequence.

200 body

FieldTypeDescription
caseIdRequiredstring (uuid)
messageIdRequiredstring (uuid)
duplicateRequiredboolean
createdAtstring (date-time)
401 response
{
  "code": "INVALID_API_CREDENTIAL",
  "message": "API credential is invalid."
}
403 response
{
  "code": "BAA_REQUIRED",
  "message": "Sign your BAA to turn on patient features. An owner or administrator can sign it in Settings."
}