Skip to content

Healthcare software built
to protect patient data

We build healthcare software to HIPAA requirements. Patient health information (PHI) is encrypted and kept to the minimum, access is limited by role, every action is recorded and FHIR integrations share only what consent allows. When an auditor asks, the evidence is ready.

To kick off a scoped project
1–2 weeks
Daily overlap with your team
4+ hours
Monthly per squad, no hourly bills
Flat fee
Your code, designs and IP
100%

What's included

What we
build for you

6 capabilities, delivered by one squad. Use what you need now and add more as you grow.

  • 01

    PHI data protection

    Encryption, tokenisation, retention rules and controlled exports for patient data.

    • Encryption with KMS
    • Data minimisation
  • 02

    Access and identity

    Least-privilege access with RBAC and ABAC, plus break-glass access that needs approval and a stated reason.

    • RBAC and ABAC
    • Break-glass workflow
  • 03

    SMART on FHIR and OAuth2 scopes

    Secure data sharing with partners, with consent, scopes and a record of every exchange.

    • Consent and scopes
    • Data lineage
  • 04

    Activity records and evidence

    Structured audit events, logs that can't be altered and evidence packs mapped to your controls.

    • Tamper-evident logs
    • Evidence packs
  • 05

    Threat and incident readiness

    Detection, response playbooks and monitoring tuned for systems that hold PHI.

    • Alerts and detections
    • Incident runbooks
  • 06

    Continuous compliance

    Automated control checks and release gates that flag risky changes before they ship.

    • Automated control checks
    • Release safeguards

Our approach

What usually goes wrong,
and what we do instead

  1. The usual way

    Over-privileged roles, shared accounts and weak boundaries around admin access.

    How we do it

    Least-privilege access by role and attribute (RBAC and ABAC), separate admin access and emergency break-glass access that needs approval.

  2. The usual way

    Logs exist, but they can't prove anything because they can be altered and are hard to search.

    How we do it

    Structured events, tamper-resistant logs and evidence packs mapped to your controls.

  3. The usual way

    FHIR and partner APIs go live without consent rules, scopes or traceability.

    How we do it

    Integrations with consent rules, scopes, data minimisation and a clear record of where data goes.

Architecture

How it's
put together

Each layer has a clear job, so the system is easier to secure, test and extend.

  1. Layer 01

    Intake layer

    Patient and provider data comes in with validation, minimisation and safe defaults.

    • Validation
    • Data minimisation
    • PHI routing
  2. Layer 02

    Data protection

    Encryption, tokenisation, secure storage boundaries and enforced retention.

    • KMS
    • Encryption
    • Retention rules
  3. Layer 03

    Access layer

    RBAC and ABAC, consent scopes, admin boundaries and break-glass workflows.

    • RBAC
    • ABAC
    • Consent scopes
    • Break-glass
  4. Layer 04

    Audit and detection

    Tamper-resistant logs, structured events, alerts and evidence packs for audits and incidents.

    • Immutable audit logs
    • Anomaly alerts
    • Evidence packs

How we deliver

From first review
to live in production

4 phases, each ending with an output you can review.

  1. Step 1: Risk and data-flow review

    Map where PHI flows, where trust boundaries sit, who needs access, which vendors are involved and what evidence your platform must produce.

    Output: HIPAA engineering blueprint

  2. Step 2: Access and protection controls

    Put in least-privilege access, encryption, separate admin access and break-glass workflows.

    Output: Core access and data controls

  3. Step 3: Safe interoperability

    Secure FHIR and partner APIs with consent, scopes, data minimisation and traceability.

    Output: Safe integration layer

  4. Step 4: Audit and incident readiness

    Add structured audit events, tamper-resistant logs, alerts and incident playbooks, so evidence is ready when asked.

    Output: Continuous evidence system

Your team

Who works
on it

Specialists join your squad for this work, alongside a delivery lead who keeps you updated.

  • Healthcare security architect

    Designs the access layer, encryption approach, audit event structure and incident readiness.

    • PHI controls
    • Audit events
    • Incident readiness
  • Identity and access lead

    Builds least-privilege roles, separate admin access, break-glass flows and approval-based access.

    • RBAC and ABAC
    • Just-in-time access
    • Admin boundaries
  • FHIR integration engineer

    Builds secure partner integrations with scopes, consent checks and a record of what data was shared.

    • FHIR
    • Consent
    • Scopes
  • Compliance operations lead

    Runs continuous monitoring, evidence collection, alerting and incident response.

    • Audit
    • Alerts
    • Runbooks

Trust and control

Safe by design,
not by policy alone

  • Policy-enforced access

    Least-privilege access, separate admin rights and break-glass access with approvals.

  • PHI protection by default

    Encryption, data minimisation, enforced retention and controlled exports.

  • Activity records and evidence packs

    Tamper-resistant logs, searchable events and evidence mapped to your controls.

You keep full ownership of the code, configuration and documentation we create, with no vendor lock-in.

Tools and standards

We pick what fits your product and team, not the other way round.

Standards and interoperability
  • HIPAA
  • FHIR
  • SMART on FHIR
Access and encryption
  • OAuth2
  • RBAC
  • ABAC
  • KMS

Results

Related
case studies

More case studies
  • HealthTechSaaS & Software

    Health records: One connected view of each patient

    We connected a regional health provider's separate EHR systems with a shared record format, live data sharing and patient matching across sites. Records became 100% consistent, and response times fell 85%.

    Record consistency
    100%
    Shorter response times
    85%
  • HealthTechSaaS & Software

    Telehealth video: Reliable calls for 2M+ patients

    We rebuilt a global healthcare provider's telehealth video platform on distributed video servers (SFUs) that scale with demand and keep patient data out of the logs. It supports 50k+ concurrent sessions with 99.99% uptime.

    Concurrent sessions
    50k+
    Service uptime
    99.99%
  • HealthTechSaaS & Software

    Healthcare operations: One portal for referrals, records and tasks

    We built a custom operations portal for a healthcare services provider. Referrals, administrative records, documents, internal tasks, status changes and reporting now sit in one workflow.

    Connected experience
    One
    Business visibility
    Live
  • FinTechSaaS & Software

    Algorithmic trading: Automated strategies, with funds kept at the broker

    We built an algorithmic trading platform that connects securely to the user's own brokerage account and runs automated strategies. Paper trading lets users test a strategy first, and a live dashboard shows every trade.

    Non-custodial design
    100%
    Trade execution
    < 45ms

FAQ

Straight
answers

Have a different question? Ask it on a 30-minute call.

Book a call

HIPAA compliance rests on controls that protect patient health information (PHI) and prove it: encryption, least-privilege access, audit logs, data minimisation and retention rules. We build software to HIPAA requirements and produce evidence packs mapped to your controls. Full compliance also depends on your organisation's own policies and processes.

Planning something like this?

Tell us what you need. We'll suggest the right team and a rough quote range, and an NDA is available before you share anything sensitive.