FYDO API Security Changes

How the move from Legacy API Keys to HMAC authentication affects your FYDO API integrators, and what to do before enforcement.

FYDO is enhancing security around API usage. The authentication model is changing from Legacy API Keys to a HMAC (Hash-Based Message Authentication Code) model.

There will be a 2-month grace period where the Legacy API Key model will be supported, while hospital API Integrators work towards transitioning to the HMAC method of authentication.

IMPORTANT — From 8 October 2026, only HMAC-authenticated API calls will be accepted. Any calls using Legacy API Keys will fail from this date.

A guide on HMAC integration will be advised shortly in a follow up email to all Facilities identified as having API Users.

What’s Changing

Security screen changes

  • Existing API Keys are now hidden.
  • A key can now be rotated manually, which also gives the old key a 72-hour grace period, so the old key will work for 72 hours, giving integrators time to change to the new key at a time that suits them.

New API Integrators screen

  • All existing API Users from the Security screen automatically have an Integrator ID set up.
  • Under each Integrator, there is now the ability to add a contact email and phone number.
  • All API endpoints are listed, with permissions that can be set to “Allowed” or “Not Allowed” for each user.
  • An IP address allow list is available to restrict API Integrators to specific IP addresses.
  • An HMAC Secret Key can be generated to support the new method of making API calls, which will be replacing the Legacy API Key in 2 months’ time.

API Log screen

  • A new Audit Log screen is available, logging changes made to the API Integrator screen.

Security Screen

Under this screen, you will have a 1-time opportunity to edit any API Usernames that are generic, such as “FYDO User”, so these users can be properly identified by the name only.
A warning screen will prompt you to update any usernames upon the first save.

Settings > Security

If an API Key is lost or forgotten, it will need to be rotated:

  1. Click on the Edit button.
  2. Click on the Rotate API Key (Legacy) button to generate a new API Key.

Rotating a Legacy API Key

  • Copy the API Key shown and click Confirm to save.

The new key is shown once — copy it before confirming

Integrators Screen

All existing API Users that were set up in the Security screen will have an Integrator ID created within the Integrators screen. This ID is used along with the HMAC Secret Key generated on the same screen, which will replace the Legacy API Key for authentication in 2 months.

To access the Integrators screen:

  1. Go to Settings > Integrators, under the API menu.

Settings > API > Integrators

2. Open an Integrator’s settings by clicking on the Integrator.

The Integrators list

3. Within the Integrator screen, you can:

  • Add the contact details (email and phone) of the API Integrator, used for future contact.
  • Generate an HMAC Secret Key, used for authenticating API calls along with the Integrator ID.
  • Set a restriction on IP addresses that are allowed to make API calls to your FYDO database.
  • Set Endpoint Permissions — to either allow or deny access to particular data within FYDO.

Integrator detail — contact details, HMAC Secret, IP allow list and Endpoint Permissions

Note — Existing API users will have permissions all set to “Allowed”, but it is encouraged to set permissions to “Not Allowed” for endpoints the API Integrator doesn’t need.
New API Users created will have all Endpoint Permissions set to “Not Allowed” by default, so will need to be enabled for all required endpoints.

The details of each endpoint are described in the FYDO Wiki here: FYDO API Details – FYDO Wiki

Creating an HMAC Secret Key

The HMAC Secret Key is the new method of authenticating an API Integrator with your FYDO database. This is required along with the Integrator ID.

To create an HMAC Secret Key:

  1. While editing the Integrator screen, click on the Generate Secret Key button.

Generate Secret Key

  • Click Yes to confirm.
  • Click the copy button to copy the key and store it securely, then confirm to save the HMAC Key.

The Secret Key is shown once — copy it before confirming

Regenerating a Lost or Forgotten HMAC Secret Key

  1. Edit the Integrator screen.
  2. Click on the Regenerate Secret Key button, and click Yes to confirm.
  3. Copy the new key and store it securely.

Disabling/Re-enabling an API Integrator

  1. Under the Integrators list, click on the Action function
  2. Click on the “Disable Access” button
  3. Click on Yes to confirm
  4. Once confirmed the Status will show “Inactive” for that Integrator and they will not be able to make any further API calls.

Note- Under the same action function, you can re-enable an Integrator which will give them access also.




Setting Up Email Footers in FYDO

FYDO allows facilities to set up email footers in two ways:

  1. Universal Email Footer — applied as the default email footer for all users.
  2. User-Based Email Footer — applied to an individual user’s emails.

Important Note

If a user has their own user-based email footer set up, this will override the universal email footer.

This means facilities can set up a universal email footer for all users, while still allowing individual users to customise their own footer if required.

In order to utilise any emailing features in FYDO, the user first has to set up the email feature by following the instructions in the below wiki page:

Setting up to Email from FYDO


Part 1: Setting Up a Universal Email Footer

The universal email footer will apply as the default footer for users who have not set up their own individual email footer.

  1. Go to Settings and select System Configuration.
  2. Select the Email Notification tab.
  3. Click Edit.
  4. Enter any text required in the Email Footer field.
  5. Drag and drop, or import by selecting Choose Image, the logo into the Company Logo section, if required. Ensure the file format for the logo meets the requirements displayed on the screen.
  6. Once all relevant information has been entered, click Save for the logo preview to update.

The universal email footer will now be used as the default footer for outgoing emails, unless the individual user sending the email has their own user-based footer set up.


Part 2: Setting Up a User-Based Email Footer

A user-based email footer is set up from the individual user’s profile. This allows each user to have their own email footer and logo if required.

  1. Hover over your User Initials, in the bottom left corner of your screen, and select Edit Profile.
  2. Go to the Email Verification tab.
  3. This is where you will need to verify your email address, if you haven’t already, in order to send emails from FYDO, as per the below instructional wiki page:
    Setting up to Email from FYDO
  4. Navigate to the Email Footer field and enter any text required.
  5. Drag and drop, or import by selecting Choose Image, the logo into the Company Logo section, if required. Ensure the file format for the logo meets the requirements displayed on the screen.
  6. Once all required information has been added, click Save for the logo preview to update.

Emails sent by this user will now include their individual email footer and logo. This user-based footer will override the universal email footer set up in Settings.


Sending an Email to Check the Footer

Once the email footer has been set up, you can test how it appears by sending a document from FYDO. Further instructions on how to send different documents from FYDO via email can be found below:

Emailing Documents from FYDO
Emailing a Hospital Invoice from FYDO




Changing an Eclipse Claim to Paperbase

In some instances, a facility will need to change a claim from ECLIPSE to Paper Base. This may occur if they are required to send it manually, rather than electronically, to the fund.

1.In Claiming Hospital > Not Yet Sent, ensure the required claim is highlighted blue & then right-click on the line

2. Select Episodes

3. Ensure a line from the required invoice is selected & shaded light blue

4. Click on the Invoice Options dropdown

5. Select Invoice Status

6. Use the Type dropdown

7. Select Paperbase

8. Click Save

9. When returning to Not Yet Sent the claim should now show as Paperbase and the user will be able to Mark as Sent.




Clearing Cookies and Cache in Microsoft Edge

There may be times where you are asked to clear your browser cookies and cache when troubleshooting issues within FYDO or Preadmit. Cached data stored within your browser can sometimes cause problems such as pages not loading correctly, old information continuing to display, login issues, or unexpected system behaviour after updates have been applied.

The below steps will guide you through how to clear cookies and cache within Microsoft Edge.

  1. Select the 3 dots menu in the top right corner of Microsoft Edge
  2. Select Delete browsing data
  3. Change the Time range to All time
  4. Tick Cookies and other site data
  5. Tick Cached images and files
  6. Click Clear now



Processing Admissions with Multiple Treating Doctors

As ECLIPSE does not support admissions under multiple doctors, FYDO must be configured and used in the same way.

Patients must therefore be admitted under the primary admitting doctor only, with all admission details recorded within the same episode.

Where multiple procedures are performed by different doctors in different theatre visits, these should be managed using multiple theatre admissions within the episodes Theatre Screen.

The doctor who performed each individual procedure can then be recorded within the Coding screen, which is the only area where procedure-level doctor allocation is supported.

  1. Book the patient into FYDO with the Primary Admitting Doctor listed in the Dr/Surgeon field
  2. If you’d like to document the Secondary Surgeon for completeness of records, they can be entered into the Surgical Assistant field. N.B this field isn’t transmitted electronically via ECLIPSE, and the secondary surgeon cannot be identified in the electronic claim in any way as that isn’t supported.
  3. Patient is Admitted as usual under the Primary Admitting Doctor
  4. If all procedures are performed in the one theatre visit, all Items can be entered together under the First visit to theatre
  5. If the patient requires two visits to theatre to have each procedure performed separately, the Multiple Visit to Theatre dropdown can be utilised to enter the additional visits
  6. Multiple Visits to Theatre will be identified with the Multiple icon

7. The Coding Screen allows for each Procedure Code to be assigned to a specific Surgeon/Dr. This is the only place in FYDO that allows for each doctor to be documented against the procedure code they performed.

All other discharge and billing processes for this episode will function as normal.




Creating a Hospital Quote (IFC)

FYDO allows you to produce an Informed Financial Consent (IFC) for a patient that is not entered into your database.

This feature is particularly helpful in enabling the facility to provide patients with quotes prior to them scheduling their appointment.

To create a hospital quote for a new patient that does not already have an appointment booked in FYDO, navigate to the Patient List screen, selecting Create Hospital IFC

Here, you will need to input the patient and procedure details:

  1. Title
  2. First Name
  3. Surname
  4. Date of birth
  5. Select the patients funding source
  6. Confirm the correct hospital location
  7. Doctor/ surgeon
  8. Date of admission and discharge
  9. Length of time the procedure will be
  10. The type of anesthetic to be used
  11. Enter all required MBS item numbers/ items
  12. Enter all required prosthetics, consumables or other services
  13. Create IFC

Now you have created the IFC, check the patient details and items are correct.

The charges will be populated from the contract fees entered to FYDO for the funding source chosen for this quote.

If you need to add a discount to the hospital fee, you can do this here by entering a % or amount you would like to discount the total fee by.

You can also add a message to the quote by selecting the IFC Message dropdown to select a preset message, or you can create your own by choosing Custom Message.

If there is any information you would like to amend, select Edit IFC.

Once all the information is confirmed as correct, ensure you have the correct Template selected and Save & Print

Your quote will then download ready for you to provide to the patient.

If you need to create a quote for a patient who has a medical record in FYDO but does not have an appointment booked yet, you can do this from the Patient Details screen by selecting the three dots on the top right-hand side of the screen, then selecting IFC Hospital.

This will prepopulate the patients personal and fund details requiring you to only input the planned procedure details:

  1. Confirm the correct hospital location
  2. Doctor/ surgeon
  3. Date of admission and discharge
  4. Length of time the procedure will be
  5. The type of anesthetic to be used
  6. Enter all required MBS item numbers/ items
  7. Enter all required prosthetics, consumables or other services
  8. Create IFC

Once you have confirmed the details are correct, select Save to save this directly to the patients Documents tab, or Save & Print to save directly to the patients Document tab as well as make it available immediately to view and print.




Make Recurring Hospital Appointment

Users can now utilise the Make Recurring feature to add multiple bookings for the same patient on a daily, weekly, monthly or yearly basis. Appointments can even be made on certain days of the week e.g. Mondays, Wednesdays and Fridays. This feature is particularly beneficial for rehab and mental health facilities, where daily admissions are common for specific programs.  

Utilising this feature results in all the appointments being linked, which enables facilities to link program codes to all episodes, allowing FYDO to determine which days to apply step-downs. 

  1. Using the Right-Click menu, select Make Appointment.
  2. Once you have selected your patient, and within the Edit Apt screen, click on Make Recurring.

  1. Recurring Appointments can be configured using flexible Daily, Weekly, Monthly, or Yearly schedules, allowing appointments to repeat at customised intervals (e.g. every 2 days, every 3 weeks, the 1st Monday of each month, or annually on a specific date).
  2. Once you have made your selections, press Save.

Daily Recurring Appointment Example

  1. Appointments in a recurring series also include additional options for Edit Appointments or Delete Appointments, which are:
    – This Appointment
    – This and all following Appointments
    – All Appointments in this series.



Hospital MMA Eclipse Mapping Code

From 1 November 2025, some health funds (e.g. NIB, ARHG) required the use of MMA ECLIPSE mapping codes for certain items. 

Hospitals are now required to submit IHC miscellaneous mapping codes for applicable items, instead of using the standard PX codes. 

Additionally, some items are no longer valid under the latest Prescribed List of Medical Devices and Human Tissue Products – Private Healthcare Australia (PHA) 

What this means for you: 

  • You’ll need to apply the new DR mapping code via the updated menu when working with relevant funds or fund groups.

  • Ensure fees are correctly maintained and aligned with agreed fund-specific rates.



Deleting Digital IFC & HC21 from Preadmit Patient Portal

Log into the Preadmit Hospital Portal

  1. Head to the Signatures tab
  2. Search for the patient you require
  3. Actions > Delete

 




Digital Hospital Informed Financial Consent (IFC)

This fantastic feature allows patients to receive, review, and sign their IFC before arriving at the facility, with the signed document automatically returned to FYDO for staff to view.

Patients will require a Preadmit ID to send the IFC electronically. You can check they have this by finding this icon on the Patient Details screen.

If the patient does not have a Preadmit icon, this means they have not been linked to Preadmit or they do not have a Preadmit Account.

To link a patient to Preadmit, ensure they have a valid email address in the email field and click the three dots in the top right-hand corner to select Get Preadmit ID.

This will perform a check with Preadmit and if the patient has a Preadmit account matching the email listed in FYDO, it will link up with a Preadmit ID.

If a message appears saying No Preadmit ID Found, you will need to instruct the patient to create a Preadmit account as they most likely do not have one. You can also check the Hospital Preadmit Portal to see if they potentially have an account under a different email. If this is the case, you can update their email in FYDO and re-run the check.

Once the patient has a Preadmit ID, you can create the IFC as normal.

On the IFC fees page, there are two buttons that will be automatically ticked if the patient has a Preadmit ID. These buttons are Send IFC to Patient Portal and Send HC21 to Patient Portal. If you want to send the IFC and HC21 to the Patient Portal, ensure these remain ticked. (They will automatically be ticked for all patients with a Preadmit ID. If the patient does not have a Preadmit ID, you will be unable to tick these boxes, they will be greyed out.)

**Once the IFC has been sent to the Patient, it will take you back to the Appointment Screen and give you a message to say it has been successfully sent to Preadmit** 

Once the patient has signed their forms, they will be sent back to FYDO. The forms will automatically allocate themselves to the patients MRN, however, you will need to open the Preadmit Holding Bay in order for the forms to download.  

**You WILL NOT need to link and commit the IFC and HC21, the holding bay just needs to be opened for the forms to download.** 

Once the Preadmit Holding Bay has been opened and the forms have automatically downloaded, they will be present in the Documents tab on the patients file.  

Custom Appointment View 

You also have the ability to add IFC Created and IFC Signed to your Appointment screen by using the custom views. (See below image). These columns will automatically tick based on the actions performed. 

If you would like to set up custom views, please see the wiki for instructions Creating Custom Hospital Views in the Appointments Screen.