Healthcare
Less paperwork, without loosening the audit trail
We build for clinics, hospitals, diagnostics labs and healthtech teams — the integration, AI and record-keeping work that has to pass a privacy review before it goes near a patient.
Talk to us about your projectWhat actually slows a healthcare build down
The data usually exists. It sits in an EMR that speaks HL7 v2 over a nightly interface, a PACS that speaks DICOM, and a lab feed keyed on LOINC codes nobody has documented since the last upgrade. Most healthcare projects are not blocked by the model — they are blocked by reading the record.
The second blocker is sign-off. A privacy and clinical review will ask who can read what, where the data rests, and what happens when the model is wrong. Teams who leave those questions until launch rebuild. We answer them in week one, and sometimes that is the reason a use case does not proceed.
Capabilities
Where we do the work
A hospital, a diagnostics lab and a healthtech startup share a regulator and almost nothing else, so each of these is scoped on its own terms.
EMR and EHR integration
HL7 v2 messages, FHIR R4 resources, or a nightly sFTP extract when that is genuinely all your vendor exposes. ADT feeds drive the rest.
Clinical documentation assistants
Ambient capture and summarisation that drafts the SOAP note, with the clinician editing and signing before anything is written back to the chart.
Imaging pre-screening
Models that flag studies for priority read against your own DICOM archive, ranked for the radiologist rather than returned as a diagnosis.
Intake, triage and scheduling agents
Booking, reminders and routine pre-visit questions handled in the patient's own channel, with any red-flag symptom routed to a human immediately.
Claims and prior authorisation
X12 837 submission, 835 remittance posting and 278 authorisation requests, with denial reasons parsed and grouped so billing works the pattern, not the queue.
Coding and billing reconciliation
ICD-10 and CPT suggestions surfaced to a coder for confirmation, plus reconciliation of what was billed against what the payer actually remitted.
Records and consent on a permissioned chain
Consent and access recorded on a permissioned ledger: who read which record, when, on whose authorisation. The PHI itself stays in your own store.
Pharma and cold-chain traceability
Serialised units tracked from manufacturer to pharmacy against GS1 and DSCSA expectations, so a recall names a lot number instead of the whole shipment.
Telemedicine and patient portals
Video consults, patient-facing results release under information-blocking rules, and payment collection that keeps card data outside the PHI boundary.
What you get
What you own at the end
Every engagement ends with artefacts you can hand to a privacy officer, an auditor, or the analyst who inherits the interface.
- INTEGRATION LAYER
- Your EMR, actually connected
- The interface mappings, the FHIR resources in use, and what each field means in your instance — including the ones your vendor documents differently from how they behave.
- COMPLIANCE PACK
- The evidence your review asks for
- Data-flow diagrams, an access-control matrix, audit-log design, retention rules, and the BAA position for every processor that touches PHI. Written for your privacy officer, not for us.
- EVALUATION SET
- Clinical cases and a baseline
- De-identified real cases scored before launch, so a model change can be measured rather than trusted. Vendors alter model behaviour without notice, and this is how a clinical team notices first.
- OPERATING NOTES
- Escalation paths and failure modes
- What happens when the model is unsure, when the interface drops overnight, and who gets called. Includes the downtime procedure, because an EMR interface will go down at some point.
How we work
From one workflow to something clinicians use
Timelines below are typical for a first workflow. Compliance sign-off is a real dependency, so it starts in week one instead of surfacing in month four.
Scoping and data access
1–2 weeksWe pick one workflow, establish what your EMR actually exposes, and agree what leaves the PHI boundary. Vendor interface access is usually the long pole.
Compliance and design review
1–2 weeksThreat model, data flows, and the human checkpoint on any clinical output. This step changes the design often and occasionally ends the use case, cheaply.
Pilot on real data
4–8 weeksOne department, one site, scored against cases your clinicians agreed on beforehand. Shadow mode first, so output is compared for weeks before anyone relies on it.
Rollout and run
OngoingSecond site, monitoring on interface health and model drift, and retuning as payer rules and coding updates land. Someone on your side owns it afterwards.
Is this the right fit for you?
Worth reading before you get in touch — it saves both of us a call.
A good fit if…
- You run an EMR and can get us interface access
- A named clinician reviews model output before it counts
- The workflow repeats daily: intake, coding, claims or results
- You have a privacy officer or counsel who signs off
Probably not, if…
- Fixed rules on a fixed workflow — AI Automation fits better
- You want autonomous diagnosis with no clinician signing the output
- Records are still on paper — Data Engineering & Analytics comes first
- You need a certified EHR replacement rather than a layer on top
Frequently Asked
Questions
Common questions about building healthcare software.
Yes. For US healthcare clients, we architect systems around HIPAA (and HITECH) requirements: encryption at rest and in transit, audit logging, access controls, BAA-ready infrastructure (AWS, Azure, or GCP), and secure data handling policies. Compliance is scoped upfront.
The most common: clinical documentation assistants (ambient scribing, note summarization), intake and triage chatbots, appointment scheduling agents, medical-image pre-screening (computer vision), and predictive analytics for readmission risk and resource planning. All with human-in-the-loop oversight for anything diagnostic.
Two main cases: tamper-proof patient record audit trails (who accessed what, when), and consent management — patients cryptographically authorize which providers can see which parts of their record. Pharma supply chain (drug traceability, anti-counterfeiting) is a third, often adjacent, use case.
Yes. We build FHIR and HL7 integrations to connect AI tools, patient apps, or blockchain layers to systems like Epic, Cerner, Athenahealth, Practo, and regional EMRs. If your EMR has an API, sFTP, or a data warehouse export, we can read from and write to it.
A focused pilot (e.g., a single AI workflow, a patient portal MVP, or a compliance dashboard) ships in 8–12 weeks. A full-stack healthcare platform with AI, EMR integration, and compliance-grade infrastructure runs 4–8 months. Compliance sign-off adds time; we plan for it from day one.
Have a project in mind?
Fixed price after a paid discovery — no hourly billing. A real engineer reads every enquiry, and we reply within 24 hours.








