Well, how fascinating! This week PointClickCare, the largest EHR in the country for skilled nursing facilities (SNFs), sent out communications putting a hard date on the end of browser extensions:
All data extraction facilitated through PCC must occur via authorized pathways that meet PCC’s applicable security, operational, technical, and compliance requirements. As of August 7, 2026, unauthorized data access methods, including browser extensions or other attempts to bypass or weaken security controls, will not be permitted.
If you or a vendor working on your behalf uses a browser extension to access data from PointClickCare, we encourage you to transition to an authorized access method before this date. Please note that browser extensions accessing PointClickCare in this manner infringe PCC's intellectual property rights and are inconsistent with the terms of your Master Subscription Agreement.
Authorized access methods include our USCDI API program, Marketplace, or our Authorized Screen Scraping Program. Vendors wishing to move to one of these data pathways can get started here.
Firstly, hats off to the branding of Authorized Screen Scraping Program (ASSP) here. I cannot wait to say that on calls.
Taking a step back for those who missed it: in the late spring, we saw PointClickCare do something no EHR had done before, formally sanctioning screen scraping as a governed access path, as mentioned in “Headless Healthcare Arrives”. However, the move was met with mixed (and some downright furious) feedback, as analytics vendors who'd built their businesses on PCC’s Data Relay product did the math on screen scraping as a substitute and didn't like the answer.
Three Doors Close, One Door Opens
We now have a bit of a sequel (or two), in that it’s not just Data Relay traffic that needs to move over:
Browser extensions are first up, and they get the hardest treatment in terms of a very aggressive timeline.
The amorphously defined “bots” come later, on a separate deadline PCC has promised in the next few weeks.
Data Relay’s existing authorizations survive until further notice, as noted in the prior update.
Why lead with extensions? It helps to be precise about what a browser extension is, because it behaves differently from the other two.
Data Relay is bulk egress. A database credential, an automated feed, whole populations of resident data flowing to whatever analytics tool the customer pointed at it.
Bots, in the RTMS mold, are server-side automation logging in with a headless browser and querying the UI at volume
A browser extension integration, although more of a cousin to bots, is neither outright. It’s client-side code running inside a real clinician’s authenticated session, in their browser, seeing and doing exactly what the logged-in human sees and does. There’s no separate credential and no outside connection knocking on the door, just a legitimate session that PCC already granted.
Raison d'Extension
Why does a third-party vendor reach for an extension at all? From “The Rise of User Interface Integration”:



