Skip to main content

Healthcare

Less paperwork, without loosening the audit trail

We build for clinics, hospitals, diagnostics labs and healthtech teams — the integration, AI and record-keeping work that has to pass a privacy review before it goes near a patient.

Talk to us about your project

What actually slows a healthcare build down

The data usually exists. It sits in an EMR that speaks HL7 v2 over a nightly interface, a PACS that speaks DICOM, and a lab feed keyed on LOINC codes nobody has documented since the last upgrade. Most healthcare projects are not blocked by the model — they are blocked by reading the record.

The second blocker is sign-off. A privacy and clinical review will ask who can read what, where the data rests, and what happens when the model is wrong. Teams who leave those questions until launch rebuild. We answer them in week one, and sometimes that is the reason a use case does not proceed.

Capabilities

Where we do the work

A hospital, a diagnostics lab and a healthtech startup share a regulator and almost nothing else, so each of these is scoped on its own terms.

  • EMR and EHR integration

    HL7 v2 messages, FHIR R4 resources, or a nightly sFTP extract when that is genuinely all your vendor exposes. ADT feeds drive the rest.

  • Clinical documentation assistants

    Ambient capture and summarisation that drafts the SOAP note, with the clinician editing and signing before anything is written back to the chart.

  • Imaging pre-screening

    Models that flag studies for priority read against your own DICOM archive, ranked for the radiologist rather than returned as a diagnosis.

  • Intake, triage and scheduling agents

    Booking, reminders and routine pre-visit questions handled in the patient's own channel, with any red-flag symptom routed to a human immediately.

  • Claims and prior authorisation

    X12 837 submission, 835 remittance posting and 278 authorisation requests, with denial reasons parsed and grouped so billing works the pattern, not the queue.

  • Coding and billing reconciliation

    ICD-10 and CPT suggestions surfaced to a coder for confirmation, plus reconciliation of what was billed against what the payer actually remitted.

  • Records and consent on a permissioned chain

    Consent and access recorded on a permissioned ledger: who read which record, when, on whose authorisation. The PHI itself stays in your own store.

  • Pharma and cold-chain traceability

    Serialised units tracked from manufacturer to pharmacy against GS1 and DSCSA expectations, so a recall names a lot number instead of the whole shipment.

  • Telemedicine and patient portals

    Video consults, patient-facing results release under information-blocking rules, and payment collection that keeps card data outside the PHI boundary.

What you get

What you own at the end

Every engagement ends with artefacts you can hand to a privacy officer, an auditor, or the analyst who inherits the interface.

INTEGRATION LAYER
Your EMR, actually connected
The interface mappings, the FHIR resources in use, and what each field means in your instance — including the ones your vendor documents differently from how they behave.
COMPLIANCE PACK
The evidence your review asks for
Data-flow diagrams, an access-control matrix, audit-log design, retention rules, and the BAA position for every processor that touches PHI. Written for your privacy officer, not for us.
EVALUATION SET
Clinical cases and a baseline
De-identified real cases scored before launch, so a model change can be measured rather than trusted. Vendors alter model behaviour without notice, and this is how a clinical team notices first.
OPERATING NOTES
Escalation paths and failure modes
What happens when the model is unsure, when the interface drops overnight, and who gets called. Includes the downtime procedure, because an EMR interface will go down at some point.

How we work

From one workflow to something clinicians use

Timelines below are typical for a first workflow. Compliance sign-off is a real dependency, so it starts in week one instead of surfacing in month four.

  1. Scoping and data access

    1–2 weeks

    We pick one workflow, establish what your EMR actually exposes, and agree what leaves the PHI boundary. Vendor interface access is usually the long pole.

  2. Compliance and design review

    1–2 weeks

    Threat model, data flows, and the human checkpoint on any clinical output. This step changes the design often and occasionally ends the use case, cheaply.

  3. Pilot on real data

    4–8 weeks

    One department, one site, scored against cases your clinicians agreed on beforehand. Shadow mode first, so output is compared for weeks before anyone relies on it.

  4. Rollout and run

    Ongoing

    Second site, monitoring on interface health and model drift, and retuning as payer rules and coding updates land. Someone on your side owns it afterwards.

Is this the right fit for you?

Worth reading before you get in touch — it saves both of us a call.

A good fit if…

  • You run an EMR and can get us interface access
  • A named clinician reviews model output before it counts
  • The workflow repeats daily: intake, coding, claims or results
  • You have a privacy officer or counsel who signs off

Probably not, if…

  • Fixed rules on a fixed workflow — AI Automation fits better
  • You want autonomous diagnosis with no clinician signing the output
  • Records are still on paper — Data Engineering & Analytics comes first
  • You need a certified EHR replacement rather than a layer on top
FAQ

Frequently Asked
Questions

Common questions about building healthcare software.

Yes. For US healthcare clients, we architect systems around HIPAA (and HITECH) requirements: encryption at rest and in transit, audit logging, access controls, BAA-ready infrastructure (AWS, Azure, or GCP), and secure data handling policies. Compliance is scoped upfront.

The most common: clinical documentation assistants (ambient scribing, note summarization), intake and triage chatbots, appointment scheduling agents, medical-image pre-screening (computer vision), and predictive analytics for readmission risk and resource planning. All with human-in-the-loop oversight for anything diagnostic.

Two main cases: tamper-proof patient record audit trails (who accessed what, when), and consent management — patients cryptographically authorize which providers can see which parts of their record. Pharma supply chain (drug traceability, anti-counterfeiting) is a third, often adjacent, use case.

Yes. We build FHIR and HL7 integrations to connect AI tools, patient apps, or blockchain layers to systems like Epic, Cerner, Athenahealth, Practo, and regional EMRs. If your EMR has an API, sFTP, or a data warehouse export, we can read from and write to it.

A focused pilot (e.g., a single AI workflow, a patient portal MVP, or a compliance dashboard) ships in 8–12 weeks. A full-stack healthcare platform with AI, EMR integration, and compliance-grade infrastructure runs 4–8 months. Compliance sign-off adds time; we plan for it from day one.

Have a project in mind?

Fixed price after a paid discovery — no hourly billing. A real engineer reads every enquiry, and we reply within 24 hours.