FYDO API Security Changes

How the move from Legacy API Keys to HMAC authentication affects your FYDO API integrators, and what to do before enforcement.

FYDO is enhancing security around API usage. The authentication model is changing from Legacy API Keys to a HMAC (Hash-Based Message Authentication Code) model.

There will be a 2-month grace period where the Legacy API Key model will be supported, while hospital API Integrators work towards transitioning to the HMAC method of authentication.

IMPORTANT — From 8 October 2026, only HMAC-authenticated API calls will be accepted. Any calls using Legacy API Keys will fail from this date.

A guide on HMAC integration will be advised shortly in a follow up email to all Facilities identified as having API Users.

What’s Changing

Security screen changes

  • Existing API Keys are now hidden.
  • A key can now be rotated manually, which also gives the old key a 72-hour grace period, so the old key will work for 72 hours, giving integrators time to change to the new key at a time that suits them.

New API Integrators screen

  • All existing API Users from the Security screen automatically have an Integrator ID set up.
  • Under each Integrator, there is now the ability to add a contact email and phone number.
  • All API endpoints are listed, with permissions that can be set to “Allowed” or “Not Allowed” for each user.
  • An IP address allow list is available to restrict API Integrators to specific IP addresses.
  • An HMAC Secret Key can be generated to support the new method of making API calls, which will be replacing the Legacy API Key in 2 months’ time.

API Log screen

  • A new Audit Log screen is available, logging changes made to the API Integrator screen.

Security Screen

Under this screen, you will have a 1-time opportunity to edit any API Usernames that are generic, such as “FYDO User”, so these users can be properly identified by the name only.
A warning screen will prompt you to update any usernames upon the first save.

Settings > Security

If an API Key is lost or forgotten, it will need to be rotated:

  1. Click on the Edit button.
  2. Click on the Rotate API Key (Legacy) button to generate a new API Key.

Rotating a Legacy API Key

  • Copy the API Key shown and click Confirm to save.

The new key is shown once — copy it before confirming

Integrators Screen

All existing API Users that were set up in the Security screen will have an Integrator ID created within the Integrators screen. This ID is used along with the HMAC Secret Key generated on the same screen, which will replace the Legacy API Key for authentication in 2 months.

To access the Integrators screen:

  1. Go to Settings > Integrators, under the API menu.

Settings > API > Integrators

2. Open an Integrator’s settings by clicking on the Integrator.

The Integrators list

3. Within the Integrator screen, you can:

  • Add the contact details (email and phone) of the API Integrator, used for future contact.
  • Generate an HMAC Secret Key, used for authenticating API calls along with the Integrator ID.
  • Set a restriction on IP addresses that are allowed to make API calls to your FYDO database.
  • Set Endpoint Permissions — to either allow or deny access to particular data within FYDO.

Integrator detail — contact details, HMAC Secret, IP allow list and Endpoint Permissions

Note — Existing API users will have permissions all set to “Allowed”, but it is encouraged to set permissions to “Not Allowed” for endpoints the API Integrator doesn’t need.
New API Users created will have all Endpoint Permissions set to “Not Allowed” by default, so will need to be enabled for all required endpoints.

The details of each endpoint are described in the FYDO Wiki here: FYDO API Details – FYDO Wiki

Creating an HMAC Secret Key

The HMAC Secret Key is the new method of authenticating an API Integrator with your FYDO database. This is required along with the Integrator ID.

To create an HMAC Secret Key:

  1. While editing the Integrator screen, click on the Generate Secret Key button.

Generate Secret Key

  • Click Yes to confirm.
  • Click the copy button to copy the key and store it securely, then confirm to save the HMAC Key.

The Secret Key is shown once — copy it before confirming

Regenerating a Lost or Forgotten HMAC Secret Key

  1. Edit the Integrator screen.
  2. Click on the Regenerate Secret Key button, and click Yes to confirm.
  3. Copy the new key and store it securely.

Disabling/Re-enabling an API Integrator

  1. Under the Integrators list, click on the Action function
  2. Click on the “Disable Access” button
  3. Click on Yes to confirm
  4. Once confirmed the Status will show “Inactive” for that Integrator and they will not be able to make any further API calls.

Note- Under the same action function, you can re-enable an Integrator which will give them access also.




Setting Up Email Footers in FYDO

FYDO allows facilities to set up email footers in two ways:

  1. Universal Email Footer — applied as the default email footer for all users.
  2. User-Based Email Footer — applied to an individual user’s emails.

Important Note

If a user has their own user-based email footer set up, this will override the universal email footer.

This means facilities can set up a universal email footer for all users, while still allowing individual users to customise their own footer if required.

In order to utilise any emailing features in FYDO, the user first has to set up the email feature by following the instructions in the below wiki page:

Setting up to Email from FYDO


Part 1: Setting Up a Universal Email Footer

The universal email footer will apply as the default footer for users who have not set up their own individual email footer.

  1. Go to Settings and select System Configuration.
  2. Select the Email Notification tab.
  3. Click Edit.
  4. Enter any text required in the Email Footer field.
  5. Drag and drop, or import by selecting Choose Image, the logo into the Company Logo section, if required. Ensure the file format for the logo meets the requirements displayed on the screen.
  6. Once all relevant information has been entered, click Save for the logo preview to update.

The universal email footer will now be used as the default footer for outgoing emails, unless the individual user sending the email has their own user-based footer set up.


Part 2: Setting Up a User-Based Email Footer

A user-based email footer is set up from the individual user’s profile. This allows each user to have their own email footer and logo if required.

  1. Hover over your User Initials, in the bottom left corner of your screen, and select Edit Profile.
  2. Go to the Email Verification tab.
  3. This is where you will need to verify your email address, if you haven’t already, in order to send emails from FYDO, as per the below instructional wiki page:
    Setting up to Email from FYDO
  4. Navigate to the Email Footer field and enter any text required.
  5. Drag and drop, or import by selecting Choose Image, the logo into the Company Logo section, if required. Ensure the file format for the logo meets the requirements displayed on the screen.
  6. Once all required information has been added, click Save for the logo preview to update.

Emails sent by this user will now include their individual email footer and logo. This user-based footer will override the universal email footer set up in Settings.


Sending an Email to Check the Footer

Once the email footer has been set up, you can test how it appears by sending a document from FYDO. Further instructions on how to send different documents from FYDO via email can be found below:

Emailing Documents from FYDO
Emailing a Hospital Invoice from FYDO




Clearing Cookies and Cache in Microsoft Edge

There may be times where you are asked to clear your browser cookies and cache when troubleshooting issues within FYDO or Preadmit. Cached data stored within your browser can sometimes cause problems such as pages not loading correctly, old information continuing to display, login issues, or unexpected system behaviour after updates have been applied.

The below steps will guide you through how to clear cookies and cache within Microsoft Edge.

  1. Select the 3 dots menu in the top right corner of Microsoft Edge
  2. Select Delete browsing data
  3. Change the Time range to All time
  4. Tick Cookies and other site data
  5. Tick Cached images and files
  6. Click Clear now



Hospital MMA Eclipse Mapping Code

From 1 November 2025, some health funds (e.g. NIB, ARHG) required the use of MMA ECLIPSE mapping codes for certain items. 

Hospitals are now required to submit IHC miscellaneous mapping codes for applicable items, instead of using the standard PX codes. 

Additionally, some items are no longer valid under the latest Prescribed List of Medical Devices and Human Tissue Products – Private Healthcare Australia (PHA) 

What this means for you: 

  • You’ll need to apply the new DR mapping code via the updated menu when working with relevant funds or fund groups.

  • Ensure fees are correctly maintained and aligned with agreed fund-specific rates.



Deactivating a User

When users no longer require access to FYDO, they can be deactivated in the system.

  1. Select Settings
  2. Click Users

3. Search for the required user and Double Click on their name

4. Click Edit
5. Untick the Active box
6. Click Save

7. Inactive users can always be viewed by utilising the Show Inactive option
8. Inactive users will be identified with an Inactive Status




Adding Procedures and Procedure Defaults (Hospital)

Adding bookings into FYDO is quick and straightforward – particularly when Procedure Notes Defaults are set up correctly.
This feature enables facilities to automatically populate multiple fields on the Edit Appointment Screen based on the selected procedure.
The following instructions will guide you through setting up procedures to streamline the booking process and reduce manual data entry, saving time and minimising the risk of errors.

Go to Settings

Select Procedures

Click Add Procedure

  1. Complete the Procedure Name – This will appear in the Procedure Notes dropdown on the Edit Appointment Screen.
    This is the only mandatory field. You don’t need to default any additional fields unless it suits your facility’s workflow. Simply choose what works best for you!
  2. Select an Anaesthetic Type – Choose the anaesthetic type that applies to the procedure.
  3. Enter the Minutes – This sets the default appointment length for the procedure.
  4. Assign a Doctor– Select the doctor(s) who perform the procedure.
    This ensures the procedure only appears in the Procedure Notes list for relevant doctors, making it easier for staff to select the correct option.
  5. Select the Booking Code 1 – Use this if you’d like to default the primary booking code, especially helpful for sites integrating with an EMR.
  6. Select the Booking Code 2 – Add a secondary booking code if required.
  7. Add Items – As you add each item, a new line will appear to allow entry of multiple items relevant to the procedure.
  8. Add Other Services – If the procedure involves protheses or other quotable services, enter them here. As with items above, a new line will display with each entry, allowing multiple codes to be added as needed.
  9. Click Save.

Procedures will now be listed in the Procedure Notes on the Make and Edit Appointment Screens.
Procedures that are specifically linked to the doctor that is selected, will also be identified.

Once a selection is made, you will notice that all pre-set defaults will populate on the screen. Allowing staff to simply complete ONE field, instead of having to enter the data in to ALL THOSE FIELDS!

For assistance with setting up Procedures to better suit your facilities workflow, contact our friendly support staff:

Email: support@alturahealth.com.au
Phone: (02) 9632 0026




Updating a Username

There may be instances when a user needs to change their name in FYDO. This can be done by the user themselves, by following the steps below.
The only exception is the Subscriber who is unable to change their user name themselves and will need to contact FYDO Support if amendments are required.

  1. Hover over User Profile (Your Initials)
  2. Select Edit Profile

3. While on the User Details tab, select Edit

4. Amend the required First Name or Surname fields
5. Click Save




Re-Order Patient Screen

Users can customise the Patient Screen and display the details that are most relevant to them!

Access to this feature is managed at the User Group level, via Settings > User Groups, by amending the option under Patient for Reorder.

Users with the appropriate access levels can customise the layout of the patient screen by navigating to any patient and selecting Reorder Content from the Menu in the top-right corner.

This allows users to choose which groups of information are visible and hide irrelevant details using the eye icon.

Information groups can also be Reordered by dragging them to the appropriate spot. The layout can be displayed across two columns or condense it into a single column if needed.

Once the desired order has been selected, click Save Order and the view will be displayed whenever the Patient Screen is opened.




Adding or Editing Doctors – Hospital

Adding Doctors or Surgeons to FYDO can be easily done by a user that has the required access level.

1. Navigate to Settings
2. Select Doctors

3. Use the Search field to find a specific doctor
4. To Edit a doctor already entered, simply double click on their line
5. To Add a new doctor select Add Doctor

6. For multi-location databases, you will be required to select the Location that the doctor is to be added to.

7. Minimum details required to add a doctor are First Name, Surname and Speciality.

8. Add in as much information as you would like. Provider numbers can be required for data extract and claiming purposes.
9. Doctors assigned the Speciality of Anaesthetics will be displayed in the Anaesthetist field throughout FYDO and won’t be admitting doctors.
10. All other Specialties (including customised ones, added by the facility) will be included in the Doctor/Surgeon dropdowns in FYDO.

FYDO gives the option to view all the doctor’s expiry dates for AHPRA, Insurance and Credentialing. These dates can by displayed by selecting View > Dates. These dates are colour coded to allow easy identification if they are expiring soon:
Red Date > Expired
Orange Date > Due to expire within the next 3 months
Black Date > Not due to expire for over 3 months

Users are able to export the Doctors List to Excel or PDF if required.




SMS Automation in FYDO

Stay connected with your patients effortlessly with the new Automated SMS feature in FYDO!
This feature allows you to automatically send SMSs to patients before and after their admissions, at timeframes that work for you!
– Need to send patients their admission times? Done.
– Need to remind patients to complete their Admission Form? No problem.
– Want to send a Post-Discharge follow-up or request feedback via a Patient Survey? It’s all possible!

We’re here to help you set up this automation. If you have any questions, don’t hesitate to reach out to our friendly team via email or phone!

Email: support@alturahealth.com.au
Phone: (02) 9632 0026

To start using the Automated SMS feature, here’s what you’ll need to have in place:

  • An SMS Account: You’ll need an SMS account set up in FYDO. If you’re not sure whether you already have one, contact our team.  
  • SMS Templates: You’ll need to set up SMS Templates. Detailed instructions are available on our Adding SMS templates – FYDO Wiki
  • SMS Automation: Once your templates are ready, you’ll need to set up SMS Automation in the FYDO Settings. Let’s walk through that now!

  1. Navigate to Settings
  2. Select SMS Automation

3. Click Add SMS Automation

4. Select the Condition. (We will go into detail on each of the Conditions later in the instructions and explain what field in FYDO governs their status)
5. Select the required Template
6. Select the Number of Days Before or After the episode that you’d like the SMS to be sent
7. Select the Time that you’d like the SMS sent
8. Select the Location for Multi-Location databases. (Single location databases will not need to amend this field)
9. Select the specific Theatre if this Automated SMS is only going to apply to one. Otherwise leave the selection as All Theatres
10. Click Setup Auto SMS

Now we’ll go into detail on the different Condition options available for sending the Automated SMSs.

To Confirm Appointment

This type of SMS automation is triggered by the Confirmed field in the Edit Appointment Screen of each episode. When the Automated SMS Condition is set to To Confirm Appointment this field will be checked before sending, to ensure the message is only sent to appointments that haven’t been confirmed yet.  

This is the only Automated SMS type that will reflect the icon on the Appointments Screen.

For example, the automated SMS feature will check for appointments scheduled in the next two days that haven’t been confirmed. It will send the selected SMS template at 9am.
For the below example, let’s say today is Monday:

  • The system will check all appointments scheduled for Wednesday and send the SMS to those without an entry in the Confirmed field.
  • FYDO will also scan for any late additions to appointments within the two-day window to ensure these patients also receive the SMS.  

Post Discharge

This SMS automation is based on the Discharge Date. Once an episode is discharged, the SMS will be sent at the designated timeframe after the discharge date.
For example, if today is Monday and a patient is discharged at 1pm, they will receive the automated Post Discharge SMS one day after their discharge date. In this case, the SMS will be sent on Tuesday at 9am.  

Admission Form Not Received

This automated SMS is triggered based on the Admission Form Received Check List item. If the checkbox is marked for a patient’s admission, they will not receive the automated SMS. This means the SMS will only be sent to patients who have not yet completed their admission form!

With the check box now automatically ticked when patients completed Online Preadmit Paperwork is committed, following up with patients who still need to complete this task has never been easier!

For the below example, if a patient is booked for Monday, they will receive their Admission Form Not Received reminder on Sunday at 8am, the day before their scheduled admission.

Keep in mind, you can set up multiple SMS Automations! So, if you want to remind patients every day until they submit their admission form, you can easily do that!

And again, we’re here to help you set up this automation. If you would like assistance with getting this feature up and running for your facility, please don’t hesitate to reach out to our friendly team via email or phone!

Email: support@alturahealth.com.auy
Phone: (02) 9632 0026

Let’s look at a demo setup for streamlining patient communication! Automating these SMS reminders can really help improve patient engagement and reduce the administrative burden on staff. Here’s an example of how it can work and why it’s effective:

  1. Online Pre-Admission Form Link (4 days before admission)
    This gives patients a head start in completing their required paperwork. The fact that it only contacts those who haven’t already submitted the form is a great way to avoid unnecessary follow-ups and potential annoyance for patients who are already on top of their forms.
  2. Follow-Up Reminder for Admission Forms (2 days before admission)
    A reminder just before the deadline to submit the form ensures that those who missed the first notification get another nudge, but again, it avoids bothering anyone who’s already completed the form. A gentle follow-up can help improve compliance.  
  3. Pre-Procedure Confirmation (1 day before admission)
    This is crucial for making sure patients are prepared with all the details – admission time, fasting instructions, what to do when they arrive, and appointment confirmation. It helps patients feel more confident and organized the day before their procedure.  
  4. Post-Discharge Check-In (1 day after discharge)
    Checking in on patients after they leave the hospital can show that you care about their recovery, making them feel supported and giving you an opportunity to catch any concerns early.  Helping you meet your post-discharge obligations.
  5. Patient Survey Link (5 days post-discharge)
    Asking for feedback via a patient survey is a great way to gather insights on their experience and identify any areas for improvement. Giving them a little time to settle into their recovery before asking for feedback might result in more thoughtful responses. Automating this follow up ensures all patients are given the opportunity to participate in providing feedback.