Appointment booking between agents
How a person's agent could find and book a medical, dental, auto or salon appointment with the provider's agent, using FHIR scheduling where it exists.
Booking an appointment is a matching problem: the person has constraints (days, times, location, reason), and the provider has a calendar with rules about what fits where. Today the person or their agent reads a booking widget or calls the front desk. A direct agent-to-agent exchange would pass the constraints and the open slots as data, and end with a confirmed booking both sides can see.
How it works today
Phone. The front desk answers when staff are free. Missed calls are missed bookings, and after-hours callers leave messages.
Online booking. Clinics, garages and salons embed a widget from their practice-management or booking software. Each vendor has its own screens and rules, and an agent that wants to use them has to automate a browser.
Healthcare has a standard for the data. HL7 FHIR defines a Schedule (whose calendar), a Slot (a bookable interval with a status of free, busy, busy-unavailable, busy-tentative or entered-in-error), and an Appointment (the booking itself). In FHIR R4, an Appointment moves through statuses including proposed, pending, booked, arrived, fulfilled, cancelled, noshow and waitlist. SMART Scheduling Links builds on this: providers publish their open slots as FHIR data that third-party tools can search, then send the patient to the provider’s own portal through a deep link to finish booking. The booking step stays on the provider’s side.
Health privacy rules apply to the request. In the US, an appointment and its reason are protected health information. HIPAA’s verification standard (45 CFR 164.514(h)) requires a covered entity to verify the identity and authority of a person requesting protected health information if it does not already know them. In Ontario, the Personal Health Information Protection Act, 2004 lets a capable individual authorize another person to act for them (s. 23), with substitute decision-makers for people who cannot.
Auto repair shops and salons have no shared scheduling standard. Their rules are commercial: deposits, cancellation windows, no-show fees.
The agent-to-agent version
Illustrative. A patient’s agent asks a dental office’s agent for a cleaning next week, mornings only.
- The agent sends the request: service type, date range, time window, existing patient ID.
- The office’s agent returns open slots as FHIR
Slotresources in a data part, with the task inTASK_STATE_INPUT_REQUIREDwaiting for a choice. - The agent picks a slot within the patient’s constraints and confirms.
- The office’s agent books it and returns the FHIR
Appointmentwith statusbookedas an artifact, then completes the task.
Step 2, the office’s response:
{
"jsonrpc": "2.0",
"id": "req-appt-1",
"result": {
"task": {
"id": "task-appt-52",
"contextId": "ctx-appt-8",
"status": {
"state": "TASK_STATE_INPUT_REQUIRED",
"message": {
"messageId": "msg-appt-02",
"role": "ROLE_AGENT",
"taskId": "task-appt-52",
"contextId": "ctx-appt-8",
"parts": [
{ "text": "Two hygiene slots are open next week before noon. Reply with a slot id." },
{
"data": {
"resourceType": "Bundle",
"type": "searchset",
"entry": [
{
"resource": {
"resourceType": "Slot",
"id": "slot-3391",
"schedule": { "reference": "Schedule/hygiene-chair-2" },
"status": "free",
"start": "2026-10-06T09:00:00-04:00",
"end": "2026-10-06T10:00:00-04:00"
}
},
{
"resource": {
"resourceType": "Slot",
"id": "slot-3407",
"schedule": { "reference": "Schedule/hygiene-chair-2" },
"status": "free",
"start": "2026-10-08T10:30:00-04:00",
"end": "2026-10-08T11:30:00-04:00"
}
}
]
},
"mediaType": "application/fhir+json"
}
]
},
"timestamp": "2026-09-26T13:40:00Z"
}
}
}
}
For a garage or salon the pattern is the same with a simpler payload: service, duration, price estimate, and the cancellation terms that apply.
What has to be true
Identity. The office needs to know which agent is calling and which patient it represents. Name plus date of birth is what front desks accept by phone; it is weak proof for an automated caller. An existing patient ID linked through the office’s patient portal is stronger.
Authority. For health appointments, the provider must be satisfied the agent acts with the patient’s authority before disclosing anything, including whether the person is a patient at all. The patient’s authorization should be limited to scheduling: book, move or cancel appointments, with no access to records or billing.
Minimum disclosure. The request should carry the reason for the visit only at the level the scheduler needs to pick the right slot type. “Cleaning” is enough; symptoms are not needed to book one.
Record. Both sides need the booked time, the cancellation policy the agent accepted, and any deposit or no-show terms. A reminder or change later should reference the same appointment ID.
Holds. Agents can hold several slots while their user decides. Providers need hold expiry, or agents will block calendars.
Where Emissar fits
- Resolve (in development): the patient’s agent usually starts from a phone number on a website or a sign. Resolve maps that number to a verified agent endpoint if the office has one, instead of dialing.
- Front Door (open to design partners): a hosted A2A endpoint in front of the office’s existing scheduling system.
- Verify (in development): checks the calling agent before any patient information is shared.
- Mandate (spec in progress): proof the patient authorized scheduling, and only scheduling.
- Ledger (spec in progress): a signed record of the booking and the terms accepted.
- Handoff (in development): symptoms that suggest urgency go to a person.
Open questions
- Will scheduling vendors expose FHIR Slot and Appointment through an agent endpoint, or keep booking inside their portals as SMART Scheduling Links does?
- How long should an agent be allowed to hold a slot before it is released?
- Who decides when a request is urgent enough to leave the booking flow, and how does the provider’s agent signal that?
- For minors and people with substitute decision-makers, how does the office confirm the agent’s principal is the right person?
Questions
- Does the patient's agent need to speak FHIR?
- It helps. A2A carries the conversation and the task state; FHIR defines what a slot and an appointment are. A data part can carry FHIR JSON with the application/fhir+json media type, so a scheduling system that already exposes FHIR Slot and Appointment resources does not need a new format.
- Is booking a doctor's appointment covered by HIPAA?
- For a US covered entity, an appointment and its reason are protected health information. Before disclosing it to someone it does not know, the provider must verify that person's identity and authority under 45 CFR 164.514(h). An agent acting for a patient is such a requester.
Sources
- HL7 FHIR R4: Appointment resource (accessed )
- HL7 FHIR R4: Slot resource (accessed )
- SMART Scheduling Links (smart-on-fhir) (accessed )
- 45 CFR 164.514: Other requirements relating to uses and disclosures of protected health information (eCFR) (accessed )
- Ontario Personal Health Information Protection Act, 2004 (e-Laws) (accessed )
- A2A Protocol Specification (accessed )