← All Industries

Healthcare and digital health

Healthcare Software Development

Health software gets killed by the compliance surface, not the feature list: PHI isolation, immutable audit trails, EHR integration, and a European regulatory clock that now runs to 2031. We have not built a hospital EHR and we will not pretend otherwise. What we have built is Arhivix, an AES-256 encrypted document platform now running inside 500+ companies, EcoBikeNet, an EU co-financed mobile and web application for a provincial government body, and the HIPAA, GDPR, and EHDS architecture research this page is built from.

The problem

Where healthcare teams get stuck.

Compliance is an architecture decision, not a final sprint

Field-level encryption, attribute-based access control, break-glass procedures, and append-only audit logs retained for six years are not features you bolt on before launch. They decide your data model, your tenancy strategy, and which third-party services you are legally allowed to call at all.

The bar is about to move. HHS has proposed making every Security Rule specification mandatory, with encryption at rest and in transit, multi-factor authentication, a maintained asset inventory and network map, and written procedures to restore critical systems within 72 hours. Teams retrofitting that into a live platform are looking at a rewrite, not a patch.

EHR integration is where good telehealth products stall

FHIR is the standard and it still does not make integration easy. Every vendor implements the same resource differently, SMART on FHIR authorization varies by platform, EHR APIs rate-limit and time out, and bulk operations need batch processing with long polling or webhooks.

Underneath that sits data quality. Allergies recorded as free text, lab results with no LOINC codes, prescriptions carried as national drug codes with no SNOMED CT bridge. On a real integration the mapping and terminology work is the majority of the effort, not the API surface.

Remote monitoring dies of alert fatigue before it dies of bugs

The ingestion problem is solvable: Bluetooth drops, readings arrive out of order after a connectivity gap, network retries create duplicates, and the patient companion app has to buffer locally and reconcile on sync. That is engineering.

The failure mode that kills adoption is clinical. Static thresholds fire on every reading outside a generic band, clinicians stop reading the queue, and a real deterioration gets missed. Personalized baselines, trend-based rules, priority tiers, and unacknowledged-alert escalation are what make the product usable, and they have to be designed with the clinical team, not guessed.

One feature can turn your platform into a medical device

A system that collects, displays, and transmits patient data usually sits outside Software as a Medical Device territory. Add "alert when this blood pressure trend suggests a medication adjustment" or an AI arrhythmia flag and you have very likely changed regulatory product.

That single line pulls in risk management under ISO 14971, a quality management system, design history files, clinical evaluation, and a premarket pathway. Budgets set before that boundary is mapped are the ones that blow up in month nine.

What we build

How we solve it.

Compliance

The rules that shape the build.

HIPAA, and the Security Rule overhaul in the pipeline

Today the Security Rule requires administrative, physical, and technical safeguards: unique user identification, automatic logoff, encryption, and audit controls over every touch of ePHI, with documentation retained six years and breach notification within 60 days. If you process PHI on behalf of a provider or payer you are a business associate, directly liable, and you need a signed BAA with every covered entity and every subprocessor in your stack.

The proposed update removes the "addressable" escape hatch and makes the specifications mandatory. The HHS fact sheet lists multi-factor authentication, encryption at rest and in transit, a technology asset inventory and network map reviewed at least every 12 months, vulnerability assessments every six months, annual penetration testing, annual compliance audits, and 72 hour restoration procedures. The comment period closed on 7 March 2025 and the final rule has slipped: the OMB agenda now shows a July 2027 target for final action. Our advice is to build to the proposal now, because every item on that list is cheaper as a design decision than as a remediation project.

Read the deep dive: Healthcare Software 2026: HIPAA & GDPR Compliance

EHDS: the EU clock is already running

Regulation (EU) 2025/327, the European Health Data Space, entered into force on 26 March 2025. Implementing acts are due by March 2027. From March 2029, patient summaries, ePrescriptions, and eDispensations must be exchangeable across member states and the secondary use regime applies to most data categories. Medical images, laboratory results, discharge reports, and the remaining secondary use categories follow in March 2031.

If you hold health data above the SME threshold you are a data holder, and that is an engineering obligation, not a policy one. It means a FHIR facade carrying EEHRxF profiles over your existing system of record, a dataset metadata catalogue a Health Data Access Body can evaluate, a pseudonymization service that runs per permit under a permit-scoped key, an append-only audit ledger retained ten years, and opt-out handling checked at cohort build time. EHDS is federated: there is no central EU database, which means the work lands on you.

Read the deep dive: EHDS Secondary Use: Architecture for Health Data Access in 2026

SaMD: FDA, EU MDR, and the AI Act stacked on top

The FDA grades Software as a Medical Device by risk: general wellness and plain data display at the low end, clinical decision support requiring 510(k) notification in the middle, autonomous diagnostic or treatment decisions requiring premarket approval at the top. Most remote monitoring platforms with any interpretive layer land in the middle tier. In the EU, software that diagnoses, prevents, monitors, predicts, or treats is a medical device under the MDR, with clinical evaluation, conformity assessment, post-market surveillance, and CE marking.

The AI Act adds a third layer rather than replacing either. Article 6 classifies an AI system as high-risk when it is a safety component of a product covered by the Annex I harmonisation legislation, which includes the medical device rules, and that product requires third-party conformity assessment. Practical consequence: the same model behind a wellness feature and behind a clinical alert are two different regulatory objects. We map that boundary in discovery and, where the business case allows, design the first release to stay on the cheaper side of it.

Read the deep dive: Telehealth Platform Development: Building HIPAA-Compliant Remote Patient Monitoring Systems

GDPR Article 9, DPIAs, and where the data physically sits

In the EU, health data is a special category. Article 9 prohibits processing it outright unless a specific exception applies: explicit consent, provision of health or social care under a professional bound by secrecy, public interest in public health, or scientific research under Article 89 safeguards. Legitimate interest is not on that list, which quietly invalidates a lot of analytics architecture imported from other verticals.

Around that sit the operational obligations: a Data Protection Impact Assessment is mandatory for large-scale health data processing, breaches go to the supervisory authority within 72 hours rather than the 60 days HIPAA allows, erasure rights have to be reconciled with medical record retention law, and transfers out of the EU need a lawful mechanism. If you serve both markets, design to the stricter rule per obligation instead of picking one regime. Building for HIPAA first and adding GDPR later is the most common and most expensive sequencing mistake in this sector.

Read the deep dive: Healthcare Software 2026: HIPAA & GDPR Compliance

Proof

Products we have shipped.

None of these are healthcare clients, and we are not going to imply otherwise. This is the adjacent work the page rests on: encrypted and audited document handling at scale, an EU co-financed public sector build, and AI shipped against an enterprise security bar.

FAQ

Common questions.

Let's talk

Bring us the regulation that is blocking your roadmap.

A free 30 minute call with the people who would do the work. Tell us your target markets, the EHR you have to live with, and the compliance question that keeps stalling the plan, and you will get an honest read on scope, sequence, and cost. We reply within 24 hours, and if we are the wrong team for it we will tell you on the call.

Book a Free Consultation