---
{
  "title": "Aidbox, Formbox & Payerbox 2608: Streaming Large Binary Files, Voice Agents, and Payer Data Integration",
  "description": "Release 2608 adds large Binary streaming, Cloud SQL IAM authentication, and scoped purge to Aidbox, plus Formbox Voice Agents and a new Payerbox data integration contract.",
  "date": "2026-09-07",
  "author": "Valeria Fursa",
  "reading-time": "5 min read",
  "tags": ["Aidbox", "Forms", "Integrations"],
  "utm-campaign": "release",
  "utm-content": "2608-release"
}
---

> For the complete documentation index, see [llms.txt](https://www.health-samurai.io/llms.txt).
> Use it to discover all available pages before guessing URLs.

---

Release 2608 brings large Binary streaming, Google Cloud SQL IAM authentication, and scoped purge operations to Aidbox. It introduces Formbox Voice Agents for automated patient calls and a Payerbox data contract for inbound integrations, alongside updates to payer interoperability, prior authorization, analytics, and provider directory publishing.

## Large Binary Files and Cloud Deployment

Aidbox can [stream large Binary files](https://www.health-samurai.io/docs/aidbox/api/rest-api/other/binary#streaming-large-files) between a client and external blob storage when offload is configured for the `data` element. It keeps only a small buffer in memory, so files can be larger than the memory available to the instance.

The [`blobNamePrefix`](https://www.health-samurai.io/docs/aidbox/configuration/storage-and-api-configuration/offload-base64binary-to-external-storage) parameter writes offloaded files as `{prefix}/{uuid}`. The prefix can separate environments or tenants in a shared Azure, AWS, or GCP bucket.

[Storage and API configuration](https://www.health-samurai.io/docs/aidbox/configuration/storage-and-api-configuration) can be provisioned through an [init bundle](https://www.health-samurai.io/docs/aidbox/configuration/init-bundle).

The [Cloud SQL Java Connector integration](https://www.health-samurai.io/docs/aidbox/tutorials/other-tutorials/how-to-run-aidbox-with-cloud-sql-java-connector) connects Aidbox to Google Cloud SQL for PostgreSQL through the Cloud SQL JDBC socket factory, with IAM database authentication in place of a stored database password.

## Subscription Event Delivery

Aidbox can copy a request [correlation id into a topic-based subscription notification](https://www.health-samurai.io/docs/aidbox/modules/topic-based-subscriptions/aidbox-topic-based-subscriptions#correlation-id). The header name is configured with `module.topics.correlation-id-header`. NATS destinations receive the value as a native message header.

For Kafka, [`keyByResourceId`](https://www.health-samurai.io/docs/aidbox/tutorials/subscriptions-tutorials/kafka-aidboxtopicdestination) uses the FHIR resource id as the message key. Events for the same resource go to the same partition and keep their order. Webhook destinations remain immutable in general, but the [`endpoint` of a `webhook-at-least-once` destination can be updated](https://www.health-samurai.io/docs/aidbox/tutorials/subscriptions-tutorials/webhook-aidboxtopicdestination#update-the-endpoint) when it is the only changed parameter.

## Data Cleanup and API Behavior

[Organization `$purge`](https://www.health-samurai.io/docs/aidbox/access-control/authorization/scoped-api/organization-based-hierarchical-access-control/organization-purge) deletes selected or all data belonging to an organization and its nested organizations. [Group `$purge`](https://www.health-samurai.io/docs/aidbox/api/bulk-api/group-purge) works at the patient level: it deletes every Patient member of a Group together with the resources in each patient's compartment, either synchronously or asynchronously. Authorization is checked for every member before deletion begins, so a single denial leaves the group unchanged.

Other Aidbox changes:

- Create and update responses return an absolute FHIR `Location` header. Set [`fhir.location-header-compliant-mode`](https://www.health-samurai.io/docs/aidbox/reference/all-settings#fhir.location-header-compliant-mode) to `false` to restore the previous relative form.
- New settings control [search parameter usage statistics](https://www.health-samurai.io/docs/aidbox/deployment-and-maintenance/indexes/search-parameter-usage-stats#configuration). [`fhir.search.param-stats.enabled`](https://www.health-samurai.io/docs/aidbox/reference/all-settings#fhir.search.param-stats.enabled) controls collection, while [`fhir.search.param-stats.flush-interval`](https://www.health-samurai.io/docs/aidbox/reference/all-settings#fhir.search.param-stats.flush-interval) sets how often buffered samples are written to PostgreSQL. Both support hot reload.
- [GraphQL references to contained resources](https://www.health-samurai.io/docs/aidbox/api/graphql-api#contained-references) resolve inline through the `resource` field instead of returning `null`.
- Fixes are included for Aidbox UI, Multibox, and trace delivery through the OTEL connector.

For batch and transaction requests, [`Prefer: return=minimal`](https://www.health-samurai.io/docs/aidbox/api/batch-transaction#control-the-response-size) now returns a response bundle without resource bodies, matching HAPI. Entries retain `response.status`, `location`, `etag`, and `lastModified`; failed entries retain their `OperationOutcome`. Clients that need the previous empty-body behavior should use `Prefer: return=hs-headers-only`. Single-resource endpoints are unchanged.

## Voice Agents and the New Formbox UI

Release 2608 brings two major changes to Formbox. [Voice Agents](https://www.health-samurai.io/docs/formbox/voice-agents) turn existing forms into automated patient voice calls: an agent asks the form's questions, captures the responses, and uses the form's existing content as the basis for the conversation. The [new Formbox UI](https://www.health-samurai.io/docs/formbox/aidbox-forms-interface) is now the default, with a cleaner, more streamlined way to work with forms; the legacy interface remains available for teams that need it.

Formbox also gets several smaller improvements this release: textareas in long forms keep a stable scroll position while users type, dates entered through an embedded iframe renderer are preserved correctly, custom attributes with boolean, integer, and decimal values are handled correctly on save, and larger, more resource-intensive PDF forms can be imported and converted into Questionnaire JSON.

## A Published Data Contract for Payerbox

The [Data Integration Reference](https://www.health-samurai.io/docs/payerbox/data-integration) defines the inbound data contract for Payerbox. It covers 24 [USCDI v3.1 datasets](https://www.health-samurai.io/docs/payerbox/data-integration/uscdi) mapped to US Core 6.1.0 and four [Provider Directory datasets](https://www.health-samurai.io/docs/payerbox/data-integration/provider-directory) mapped to Plan-Net 1.2.0. Each dataset has a downloadable CSV template. Coded columns link to their value sets, such as the [OMB Ethnicity Categories ValueSet](https://healthsamurai.github.io/fhir-valueset-viewer/#url=http://hl7.org/fhir/us/core/ValueSet/omb-ethnicity-category).

Payerbox targets CARIN Blue Button 2.1.0 and PDex Plan-Net 1.2.0, replacing versions 2.0.0 and 1.1.0. CARIN BB 2.1.0 adds the Non-Financial Basis profiles used in Payer-to-Payer and Provider Access exports. Supported versions are listed on the [Implementation Guides](https://www.health-samurai.io/docs/payerbox/api-reference/implementation-guides) page.

## Interoperability and Prior Authorization Updates

For Payer-to-Payer and Provider Access, [`$davinci-data-export`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/davinci-data-export) accepts kick-off parameters on the query string and returns `400` for an inverted `_since` and `_until` window. [`$bulk-member-match`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/bulk-member-match) and [`$provider-member-match`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/provider-member-match) no longer fail when a `MemberBundle` references resources that exist only on the requesting side. The member-match change requires `BOX_FHIR_VALIDATION_SKIP_REFERENCE=true`, as described in the [deployment guide](https://www.health-samurai.io/docs/payerbox/run-payerbox/deploy).

Payerbox rejects updates to a denied prior authorization regardless of how the utilization management system wrote the decision back; the [`Claim/$submit` update flow](https://www.health-samurai.io/docs/payerbox/api-reference/operations/claim-submit#update-flow) describes the behavior. [`$submit-attachment`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/submit-attachment) uses the PAS `PASTempCodes` code system for `supportingInfo.category`. The previous system URL did not exist in the implementation guide and failed terminology validation.

For CRD, [`order-sign`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/cds-hook-order-sign), [`order-dispatch`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/cds-hook-order-dispatch), and [`appointment-book`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/cds-hook-appointment-book) return a Coverage Information system action when coverage cannot be determined. Along with the explanatory card, the action annotates the draft order with `covered=conditional`, `info-needed=OTH`, and a human-readable reason, as required by Da Vinci CRD 2.1.0. [`order-select`](https://www.health-samurai.io/docs/payerbox/api-reference/operations/cds-hook-order-select) remains unchanged and returns the card only.

## PAS Analytics and MPF Publishing

The PAS metrics package, `io.healthsamurai.pas-metrics` 0.1.6, is available for download with an Aidbox Notebook that charts each metric. Package details are available in the [PAS Metrics documentation](https://www.health-samurai.io/docs/payerbox/analytics/pas-metrics).

The MPF provider directory pipeline publishes data by contract year. `InsurancePlan.period` carries the published year, and providers that are not in network during that year are excluded. Network scope is derived from the configured plans on every run: administrators configure `InsurancePlan` ids, and the network `Organization` ids come from each plan's `network[]`. The **Network Organization IDs** setting has been removed, and previously stored values are ignored. The [MPF Publications](https://www.health-samurai.io/docs/payerbox/fhir-app-portal/mpf-publications) documentation describes the updated flow.

## Read the Full Release Notes

This post covers the main changes across the three products. For the complete changelog and configuration details, read the release notes for:

- [Aidbox 2608](https://www.health-samurai.io/docs/aidbox/overview/release-notes#august-2026-latest-2608)
- [Formbox 2608](https://www.health-samurai.io/docs/formbox/release-notes)
- [Payerbox 2608](https://www.health-samurai.io/docs/payerbox/releases#august-2026-2608)
