> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clinikehr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List reported medicines

> **Permission:** `medications:read`

List one patient's reported medicines (the confirmed chart, or what this key submitted).

`patient_id` is required. `review_status` picks the view: `confirmed` (default) is the clinic's own list of reported medicines; `pending` is this key's own submissions still waiting for a clinician (and those a clinician rejected); `all` is both. `status` filters by the statement's status. A reported medicine is what the patient says they take; it is not a prescription (see `listPrescriptions`). A restricted patient's statements are never returned. With `Accept: application/fhir+json` the answer is a searchset Bundle of FHIR R4 MedicationStatement resources.



## OpenAPI

````yaml /openapi/ehr-api.v1.yaml get /v1/clinics/{clinic_id}/medication-statements
openapi: 3.1.0
info:
  title: ClinikEHR API
  version: 1.0.0
  description: >-
    Server-to-server REST API for a clinic's own data, reached with a key the
    clinic (or a developer workspace) creates in the developer portal.


    Authenticate every request with `Authorization: Bearer <key>`. Test keys
    reach only your workspace's own synthetic sandbox; live keys reach the
    clinic that created them. Lists wrap their rows as `{ data, has_more,
    next_cursor }`; single resources are returned directly. Errors are
    `application/problem+json` (RFC 9457) with a stable `code`.


    Write requests accept an `Idempotency-Key` header so a retry never repeats a
    change. See the guides for authentication, permissions, pagination, rate
    limits and retries.
servers:
  - url: https://api.clinikehr.com
security:
  - ApiKey: []
paths:
  /v1/clinics/{clinic_id}/medication-statements:
    get:
      tags:
        - Medications
      summary: List reported medicines
      description: >-
        **Permission:** `medications:read`


        List one patient's reported medicines (the confirmed chart, or what this
        key submitted).


        `patient_id` is required. `review_status` picks the view: `confirmed`
        (default) is the clinic's own list of reported medicines; `pending` is
        this key's own submissions still waiting for a clinician (and those a
        clinician rejected); `all` is both. `status` filters by the statement's
        status. A reported medicine is what the patient says they take; it is
        not a prescription (see `listPrescriptions`). A restricted patient's
        statements are never returned. With `Accept: application/fhir+json` the
        answer is a searchset Bundle of FHIR R4 MedicationStatement resources.
      operationId: listMedicationStatements
      parameters:
        - name: clinic_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: patient_id
          in: query
          required: true
          schema:
            type: string
            format: uuid
        - name: review_status
          in: query
          required: false
          schema:
            type: string
            enum:
              - confirmed
              - pending
              - all
            default: confirmed
        - name: status
          in: query
          required: false
          schema:
            type: string
            enum:
              - active
              - completed
              - stopped
              - on_hold
              - not_taken
              - entered_in_error
        - name: updated_since
          in: query
          required: false
          schema:
            type: string
            format: date-time
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 25
        - name: starting_after
          in: query
          required: false
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: OK.
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                  - has_more
                  - next_cursor
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/MedicationStatement'
                  has_more:
                    type: boolean
                  next_cursor:
                    type:
                      - string
                      - 'null'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security:
        - ApiKey: []
components:
  schemas:
    MedicationStatement:
      type: object
      description: >-
        A reported medicine - the patient (or a connected app) says they take
        it. It is NOT a prescription and nothing is dispensed from it. The
        exposed-field allow-list, field by field. `review_status` says where the
        record stands: `confirmed` is on the clinic's chart; `pending` is an
        outside submission still waiting for a clinician (`verification_status:
        unconfirmed`); `rejected` and `withdrawn` are this key's own submissions
        that did not become chart truth. A statement with a recognised RxNorm
        code is used by the clinic's pharmacy interaction checks while it is
        `active`; a free-text or `local` one is listed there as not checked.
      required:
        - id
        - patient_id
        - medication
        - verification_status
        - review_status
      properties:
        id:
          type:
            - string
            - 'null'
          format: uuid
          description: >-
            The statement's id once confirmed; null for a pending create (use
            `submission_id`). A pending update or retraction carries the id of
            the statement it targets.
        patient_id:
          type: string
          format: uuid
        medication:
          $ref: '#/components/schemas/MedicationStatementMedication'
        dosage:
          $ref: '#/components/schemas/MedicationStatementDosage'
        status:
          type:
            - string
            - 'null'
          enum:
            - active
            - completed
            - stopped
            - on_hold
            - not_taken
            - entered_in_error
            - null
          description: Null for a pending update that does not change the status.
        effective:
          $ref: '#/components/schemas/MedicationStatementEffective'
        reason:
          type:
            - string
            - 'null'
        note:
          type:
            - string
            - 'null'
        recorded_by:
          type:
            - string
            - 'null'
          format: uuid
          description: clinic_staff.id of the clinician who recorded or confirmed it.
        source:
          type: string
          enum:
            - clinic
            - api
        origin_assistant_name:
          type:
            - string
            - 'null'
        accepted_by:
          type:
            - string
            - 'null'
          enum:
            - clinic
            - automatic
            - null
          description: >-
            Who put this record on the chart: `clinic` (the clinic's own team,
            or a clinician who confirmed it) or `automatic` (the clinic chose to
            accept this kind of item from this key or connection without review;
            the record is on the chart but no clinician has reviewed it, so
            `verification_status` reads `unconfirmed` until one does). Null
            while the item is still a pending submission.
        reviewed_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >-
            Set when a clinician marked an automatically accepted item reviewed;
            null otherwise.
        reviewed_by_staff_id:
          type:
            - string
            - 'null'
          format: uuid
          description: >-
            clinic_staff.id of the clinician who marked an automatically
            accepted item reviewed; null otherwise.
        verification_status:
          type: string
          enum:
            - confirmed
            - unconfirmed
        review_status:
          type: string
          enum:
            - confirmed
            - pending
            - rejected
            - withdrawn
        submission_id:
          type:
            - string
            - 'null'
          format: uuid
        decision_reason:
          type:
            - string
            - 'null'
          description: >-
            Why a clinician rejected it. Present only when `review_status` is
            `rejected`.
        created_at:
          type:
            - string
            - 'null'
          format: date-time
        updated_at:
          type:
            - string
            - 'null'
          format: date-time
    MedicationStatementMedication:
      type: object
      required:
        - text
      properties:
        text:
          type: string
          description: The medicine as the patient or the sender states it.
        code:
          oneOf:
            - $ref: '#/components/schemas/MedicationCode'
            - type: 'null'
    MedicationStatementDosage:
      type: object
      description: >-
        How the medicine is taken, as stated. Free text; nothing here is an
        order.
      properties:
        text:
          type:
            - string
            - 'null'
        route:
          type:
            - string
            - 'null'
        frequency:
          type:
            - string
            - 'null'
    MedicationStatementEffective:
      type: object
      properties:
        start:
          type:
            - string
            - 'null'
          format: date
        end:
          type:
            - string
            - 'null'
          format: date
    Problem:
      type: object
      description: RFC 9457 application/problem+json.
      required:
        - type
        - title
        - status
        - code
        - request_id
      properties:
        type:
          type: string
          format: uri
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
        code:
          type: string
        request_id:
          type: string
        errors:
          type: array
          items:
            type: object
            required:
              - pointer
              - message
            properties:
              pointer:
                type: string
              message:
                type: string
    MedicationCode:
      type: object
      description: >-
        A coded medicine. `system` is `rxnorm` or `local` (a clinic's or
        sender's own code, never mapped to a standard). An `rxnorm` code is
        accepted only when it is a recognised RxNorm code in the platform's own
        drug data; `display` is the platform's own name for it and is never
        taken from the sender. `display` is null for a `local` code.
      required:
        - system
        - code
      properties:
        system:
          type: string
          enum:
            - rxnorm
            - local
        code:
          type: string
        display:
          type:
            - string
            - 'null'
  responses:
    BadRequest:
      description: >-
        The request failed validation (unknown query parameter, limit out of
        range, malformed body).
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    Unauthorized:
      description: >-
        Missing, malformed, unknown, revoked or expired key, or the wrong
        secret.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    Forbidden:
      description: >-
        The key or connection lacks the required scope, the plan does not
        include this resource, the request came from an address this key's IP
        allow-list does not permit, a TEST-environment workspace key asked for a
        clinic_id other than its own workspace's sandbox (`sandbox_only`), or a
        LIVE workspace key asked for a real clinic while its workspace's
        verification has lapsed (`not_verified`) — the response never names
        which addresses ARE allowed, nor which clinic actually is the sandbox.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    NotFound:
      description: The record is absent, or out of the key's scope — one message for both.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
    TooManyRequests:
      description: Rate limited. See the Retry-After header.
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/Problem'
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: ehr_live_<keyId>_<secret> or ehr_test_<keyId>_<secret>

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.