Home All services
Start a project → Call Now

Healthcare software and security

Keep patient data safe in every system it reaches — not just the record system.

For hospitals, clinics, health-tech companies and telehealth products. Lab feeds, imaging links, claims files and patient apps carry records out of your core system. We build those connections and check their security against the rules that follow the data: HIPAA for US patients, India's DPDP Act and ABDM.

  • Safeguards built into the code
  • Security assessed as a separate service
  • We reply within one working day.
  • HIPAA Security Rule
  • HIPAA Omnibus Rule
  • DPDP Act, 2023
  • DPDP Rules, 2025
  • ABDM
Illustration: a clinic tablet showing a heartbeat line, a patient record folder and a stethoscope beside a server guarded by a slim shield

In brief

Who it's for
Hospitals and clinics, and the health-tech, telehealth and software vendors that handle their patient records.
What gets in the way
Security work often stops at the edge of the record system. By then the records have moved on to labs, viewers, billing vendors and phones, and the law follows them there.
How we help
We build the integrations, APIs and patient apps with the safeguards in the code, and assess their security as a separate service.

Where records travel

Patient data leaves the record system every day.

Each of these connections copies, converts or displays records outside your core system. Securing the record system alone covers only the place where patient data begins.

Lab orders and results

An order leaves with the patient's identity and the clinical reason, and the result comes back to the chart. Every amended result and canceled order passes through the same interface.

Imaging and remote reading

Scans are copied to cloud viewers and outside radiologists. A viewing link that opens without a login, or outlives the report, exposes the images and the patient details stored inside them.

Claims and billing

A claim carries diagnoses, procedures and policy numbers through a billing vendor, and possibly a clearinghouse, to the insurer. Every rejected claim comes back the same way, as another copy.

Reporting and analytics feeds

Scheduled extracts to a reporting warehouse keep every identifier unless the feed strips them. The chart's access rules stay behind in the chart, so each dashboard needs rules of its own.

The interface engine

The middleware that translates messages between systems sees traffic from every connection at once. One administrator account on it can read more patient data than any single application it links.

Vendor remote access

Remote sessions let a vendor's engineers reach a lab or imaging system from outside the hospital. Each session path is a way into your network that stays open until someone closes it.

The rules in plain English

The rules follow the data, not the network diagram.

A hospital can lock down its health record system and still lose patient data through a connection nobody put in scope. The line belongs around the data.

  • HIPAA, for US patients. HHS's business associate rules follow protected health information from the hospital to each vendor handling it on the hospital's behalf, then on to that vendor's subcontractors. A company running a lab interface or billing service is inside those rules once it handles a record, whatever the network diagram shows. Our HIPAA compliance page explains the chain.
  • India's DPDP Act, 2023. The hospital is the Data Fiduciary, the party that decides why and how the data is used, so it answers for what its processors do. Rule 6(1)(f) of the DPDP Rules, 2025 expects security safeguards in each processor contract. These duties commence in May 2027, and our DPDP Act compliance page tracks what is in force before then.
  • ABDM, India's digital health mission. Software that connects to the Ayushman Bharat Digital Mission is integrated in the ABDM sandbox first, and needs functional testing and a security assessment before it goes live. The FAQ below has the detail.

If a customer asks for HITRUST, we can build and document the security controls on your systems that hold electronic patient data. See security controls for ePHI systems.

What this work does not include. We build software and assess its security. We are not an auditor or a certification body: a HITRUST assessment is done by a HITRUST-licensed firm, and nobody can issue a DPDP Act certificate.

Inside the build

What healthcare integration software has to contain.

Each safeguard lives in code or configuration, where an engineer can show it.

We build integration software in React, Next.js, Node, Python and PostgreSQL, with these six safeguards from the start.

  • One credential each. Every interface and every vendor engineer gets its own login, so each record access traces to one system or one person.
  • Only the fields the job needs. A lab sees an order, and a billing vendor sees a claim.
  • Encryption on every outside link. Every connection that leaves your own network is encrypted, including links to vendors you trust.
  • An audit trail no vendor can alter. It shows which connection or person opened which patient's record.
  • Logs that expire. Message archives and error logs are deleted on schedule, so a failed message never becomes a permanent copy of the record.
  • No real patients in testing. Test and staging systems use made-up (synthetic) patients, and production credentials stay out of both.

More on the build side: API development and integration, web and custom software and mobile app development.

Patient apps and telehealth

The patient app is the one integration anyone can reach.

Its users sign in from phones you have never seen, over networks you don't run.

A clinician reaches records through screens and networks the hospital controls. A patient reaches the same records through an API, the interface the app talks to, which every phone with the app can call. So the API, not the screen, has to decide who sees what. We can build these APIs in Node and Python on PostgreSQL, and check that enforcement separately through an API vulnerability assessment.

What the app's API has to enforce

  • Every request checked. Access is checked against the signed-in patient on every record request, not only at login.
  • Deliberate proxy access. Access for a parent or caregiver is granted, limited and revoked on purpose.
  • Sessions that end. Session tokens expire, and stop working at logout or a password change.
  • Quiet notifications. No diagnoses or test results in push notification text.
  • Nothing for trackers. No patient identifiers passed to analytics or crash reporting services.
  • Attempt limits. Login and one-time codes can only be tried a limited number of times.

Find the right help

Start with the situation you are in.

Pick the question closest to yours. Each one leads to the service that answers it.

Adding a connection

Four steps before a new integration carries real patient data.

Each of these gets harder to change once live records are flowing.

  1. Classify the other party

    Work out what the vendor is under each law. Under HIPAA, a business associate or a subcontractor. Under the DPDP Act, a processor for the hospital, or a business with purposes of its own.

  2. Sign before data moves

    Put the business associate agreement or processor contract in place first, with security terms the vendor must pass down to every subcontractor that will touch the records.

  3. Record it in a register

    Write down the fields the feed carries, which way they flow, where the vendor stores them, and who at the vendor hears first when something goes wrong.

  4. Plan the exit

    Decide at the start how the vendor's keys and accounts are revoked when the contract ends, and how its copies are returned or destroyed, with written confirmation.

FAQ

Healthcare integration questions.

Business associates, encryption, the DPDP Act and ABDM. For anything else, ask us directly.

A vendor is a business associate when it creates, receives, maintains or transmits protected health information on the hospital's behalf, such as a company hosting images, building the patient app or keeping backups of the record system. Under HHS's Omnibus Rule, its subcontractors that handle the same data are business associates too, however many layers down. A vendor based outside the United States is covered on the same terms.

A vendor that only carries messages can fall outside HIPAA's business associate rules, but the test is narrow. The conduit exception HHS recognizes covers pure transmission, the way a courier or an internet service provider moves data, and not a service that stores the data, even encrypted data it cannot read. An integration platform that keeps message archives or logs with patient data is storing that data, so it needs an agreement.

HIPAA does not require encryption as a fixed rule today. The HIPAA Security Rule makes encryption at rest and in transit addressable, which means the organization must decide whether it is reasonable and appropriate and document that decision. HHS proposed a Security Rule overhaul on 6 January 2025 that would change this, but it is not law. For a link crossing the public internet, deciding against encryption would be hard to defend.

No. India's Digital Personal Data Protection Act, 2023 creates no special category for health records, so patient data stands on the same footing as other digital personal data. Its safeguard and breach reporting duties commence in May 2027 under notification G.S.R. 843(E). Until then, section 43A of the IT Act and the SPDI Rules, 2011 remain operative, and that same tranche repeals section 43A.

The National Health Authority's brief guide to the Ayushman Bharat Digital Mission and its building blocks, version 1.1, last updated in December 2021, says applications must undergo functional testing and a security assessment before entering production. It also requires every ecosystem partner to comply with NHA's Information Security Policy for External Ecosystem, and it places integration in the ABDM sandbox before any live connection.

Start from the hospital's interfaces rather than its application list. Every outbound feed from the record system points at a vendor, and each vendor has hosting, backups, logs, remote access tools and subcontractors where copies can settle. Ask each vendor to name those places in writing. Exported reports, email attachments and old test databases belong on the list too.

Let's talk

Tell us where your patient data goes.

Bring the list of labs, imaging services, billing vendors and apps that touch your records. Project work is delivered remotely from India during business hours. We reply within one working day.