Lab orders and results
An order leaves with the patient's identity and the clinical reason, and the result comes back to the chart. Every amended result and canceled order passes through the same interface.
Healthcare software and security
For hospitals, clinics, health-tech companies and telehealth products. Lab feeds, imaging links, claims files and patient apps carry records out of your core system. We build those connections and check their security against the rules that follow the data: HIPAA for US patients, India's DPDP Act and ABDM.
Where records travel
Each of these connections copies, converts or displays records outside your core system. Securing the record system alone covers only the place where patient data begins.
An order leaves with the patient's identity and the clinical reason, and the result comes back to the chart. Every amended result and canceled order passes through the same interface.
Scans are copied to cloud viewers and outside radiologists. A viewing link that opens without a login, or outlives the report, exposes the images and the patient details stored inside them.
A claim carries diagnoses, procedures and policy numbers through a billing vendor, and possibly a clearinghouse, to the insurer. Every rejected claim comes back the same way, as another copy.
Scheduled extracts to a reporting warehouse keep every identifier unless the feed strips them. The chart's access rules stay behind in the chart, so each dashboard needs rules of its own.
The middleware that translates messages between systems sees traffic from every connection at once. One administrator account on it can read more patient data than any single application it links.
Remote sessions let a vendor's engineers reach a lab or imaging system from outside the hospital. Each session path is a way into your network that stays open until someone closes it.
The rules in plain English
A hospital can lock down its health record system and still lose patient data through a connection nobody put in scope. The line belongs around the data.
If a customer asks for HITRUST, we can build and document the security controls on your systems that hold electronic patient data. See security controls for ePHI systems.
What this work does not include. We build software and assess its security. We are not an auditor or a certification body: a HITRUST assessment is done by a HITRUST-licensed firm, and nobody can issue a DPDP Act certificate.
Inside the build
Each safeguard lives in code or configuration, where an engineer can show it.
We build integration software in React, Next.js, Node, Python and PostgreSQL, with these six safeguards from the start.
More on the build side: API development and integration, web and custom software and mobile app development.
Patient apps and telehealth
Its users sign in from phones you have never seen, over networks you don't run.
A clinician reaches records through screens and networks the hospital controls. A patient reaches the same records through an API, the interface the app talks to, which every phone with the app can call. So the API, not the screen, has to decide who sees what. We can build these APIs in Node and Python on PostgreSQL, and check that enforcement separately through an API vulnerability assessment.
Find the right help
Pick the question closest to yours. Each one leads to the service that answers it.
Adding a connection
Each of these gets harder to change once live records are flowing.
Work out what the vendor is under each law. Under HIPAA, a business associate or a subcontractor. Under the DPDP Act, a processor for the hospital, or a business with purposes of its own.
Put the business associate agreement or processor contract in place first, with security terms the vendor must pass down to every subcontractor that will touch the records.
Write down the fields the feed carries, which way they flow, where the vendor stores them, and who at the vendor hears first when something goes wrong.
Decide at the start how the vendor's keys and accounts are revoked when the contract ends, and how its copies are returned or destroyed, with written confirmation.
FAQ
Business associates, encryption, the DPDP Act and ABDM. For anything else, ask us directly.
A vendor is a business associate when it creates, receives, maintains or transmits protected health information on the hospital's behalf, such as a company hosting images, building the patient app or keeping backups of the record system. Under HHS's Omnibus Rule, its subcontractors that handle the same data are business associates too, however many layers down. A vendor based outside the United States is covered on the same terms.
A vendor that only carries messages can fall outside HIPAA's business associate rules, but the test is narrow. The conduit exception HHS recognizes covers pure transmission, the way a courier or an internet service provider moves data, and not a service that stores the data, even encrypted data it cannot read. An integration platform that keeps message archives or logs with patient data is storing that data, so it needs an agreement.
HIPAA does not require encryption as a fixed rule today. The HIPAA Security Rule makes encryption at rest and in transit addressable, which means the organization must decide whether it is reasonable and appropriate and document that decision. HHS proposed a Security Rule overhaul on 6 January 2025 that would change this, but it is not law. For a link crossing the public internet, deciding against encryption would be hard to defend.
No. India's Digital Personal Data Protection Act, 2023 creates no special category for health records, so patient data stands on the same footing as other digital personal data. Its safeguard and breach reporting duties commence in May 2027 under notification G.S.R. 843(E). Until then, section 43A of the IT Act and the SPDI Rules, 2011 remain operative, and that same tranche repeals section 43A.
The National Health Authority's brief guide to the Ayushman Bharat Digital Mission and its building blocks, version 1.1, last updated in December 2021, says applications must undergo functional testing and a security assessment before entering production. It also requires every ecosystem partner to comply with NHA's Information Security Policy for External Ecosystem, and it places integration in the ABDM sandbox before any live connection.
Start from the hospital's interfaces rather than its application list. Every outbound feed from the record system points at a vendor, and each vendor has hosting, backups, logs, remote access tools and subcontractors where copies can settle. Ask each vendor to name those places in writing. Exported reports, email attachments and old test databases belong on the list too.
Let's talk
Bring the list of labs, imaging services, billing vendors and apps that touch your records. Project work is delivered remotely from India during business hours. We reply within one working day.