Back to BlogIndustry Guides

Building HealthTech Software: HIPAA, GDPR, FHIR and What We Can Prove

Rupak Amin

Founder & Lead Engineer, RAITHub

13 min read

Building health software means designing access control, read logging, consent and audit trails from the first spec, with a compliance partner setting the rules. RAITHub has built a healthcare scheduling app for a client, but it has not shipped a regulated health product, and this guide says so first. Its other evidence is domain-neutral: row-level security, append-only audit logs and test-gated releases on live platforms.

This page gives accurate general context on HIPAA, GDPR and HL7 FHIR, what a patient portal needs, and how to run a health project, and it separates what RAITHub can show you from what it cannot. If you are looking for a team to build a health product, the service page is HealthTech software development.

Has RAITHub built a healthcare product?

RAITHub has built a healthcare scheduling app for a client. It has not shipped a regulated health product, and none of the case studies on its work page is a health product.

The HealthTech service page has no case study for the same reason. What RAITHub does have is evidence of the engineering controls that health products depend on, most of it built for other industries. That evidence is useful, but it is not the same as regulated health experience, and you should weigh it that way.

What engineering evidence does RAITHub have that applies to health products?

Access control, tamper-evident audit logging, tested data isolation and release discipline, on platforms that are live today. None of it was built for health data.

What a health product needsEvidence RAITHub can showWhat is still missing for health
Least-privilege accessSundor Skin: role-based access for staff and row-level security in PostgreSQLRoles modelled on clinical workflows, such as clinician, care team and patient proxy
A tamper-evident record of changesSundor Skin: an append-only, hash-chained audit logLogging of reads of health records, not only changes, with retention set by your compliance partner
Proof that one user cannot see another's dataSundor Skin: a 21-case IDOR security suite among 530+ automated testsTest cases written against your specific patient and provider relationships
Releases that cannot skip testsCI-gated suites: 750+ tests on TheSkinProof (the founder's own marketplace), 530+ on Sundor SkinValidation evidence your regulator or customers may ask for
EncryptionA design requirement on every project: TLS in transit and encryption at rest, as described on the security pageKey management, backup and vendor choices reviewed against your obligations

Row-level security matters because it enforces access in the database, not only in application code. On Sundor Skin, buyer data sits behind row-level security policies, so a bug in one screen should not be able to expose another buyer's records, and the IDOR suite tests exactly that. The Sundor Skin case study has the detail.

Which health data regulations might apply to your product?

It depends on who you are, where your users are and what data you handle. In the US the usual starting point is HIPAA; in the EU it is GDPR, which treats health data as special-category data.

Not legal or compliance advice. The summaries below are general. Whether a law applies to your product, and what it requires, is a question for a qualified compliance professional or lawyer in each market you serve.

HIPAA (United States)

The HIPAA rules apply to covered entities (health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions) and to their business associates, as set out in 45 CFR 160.102. A business associate is, broadly, a vendor that handles protected health information (PHI) on a covered entity's behalf.

Before a covered entity discloses PHI to a business associate, it must obtain satisfactory assurances that the information will be safeguarded, documented in a written contract or agreement: 45 CFR 164.502(e). That document is usually called a Business Associate Agreement (BAA). If your product handles PHI for US providers or plans, expect to sign BAAs with your customers, and check which vendors in your own stack will sign one with you.

GDPR (European Union)

GDPR defines data concerning health as personal data about a person's physical or mental health, including the provision of health care services, that reveals information about their health status (Article 4(15)). It is a special category of personal data: Article 9 prohibits processing it unless one of the conditions in that article applies.

Everywhere else

Many countries and US states have their own health-privacy and data-protection laws. Do not assume HIPAA or GDPR is the whole picture for your market.

FrameworkApplies to (in general)What it usually means for engineering
HIPAAUS covered entities and their business associatesBAAs with customers and vendors; access controls, audit controls and transmission security for PHI
GDPRProcessing of personal data within GDPR's territorial scope, with extra conditions for health dataA lawful basis and an Article 9 condition; data minimisation; support for data-subject rights
Local lawsDepends on the country or stateData residency, consent and breach-notification rules, confirmed by local counsel

What does "HIPAA compliant app development" actually mean?

An app cannot be HIPAA compliant by itself. Compliance is an obligation on the organisation, covering policies, training, agreements and safeguards; software can support it or undermine it.

A vendor who says "we build HIPAA-compliant apps" is describing engineering that supports your compliance programme, not a certificate the app carries. The practical questions are narrower: where PHI is stored and who can read it, whether every access is logged, whether each vendor in the chain will sign a BAA, and how you would detect and report a breach.

What is HL7 FHIR, and does RAITHub integrate with it?

FHIR is HL7's standard for exchanging healthcare information electronically. RAITHub has not shipped a FHIR integration; it has built and contract-tested REST APIs, which is adjacent experience, not equivalent.

HL7 describes FHIR as built from resources: every piece of exchangeable content, such as a patient or an observation, is defined as a resource. Integration work usually means mapping your data model to those resources, handling the specific profiles and version your partner system supports, and treating the external system as unreliable: it can be slow, return partial data or change. Confirm the FHIR version and profiles with the EHR vendor before estimating.

What does a patient portal need beyond a normal web app?

Stricter identity, finer-grained access, logging of who viewed what, and careful handling of people acting for someone else.

  • Identity: strong authentication and account recovery that cannot be socially engineered easily.
  • Proxy access: parents, carers and guardians who act for a patient, with limits you can explain.
  • Read logging: an audit record when a health record is viewed, not only when it changes.
  • Consent: recorded, versioned and revocable, with the product respecting a withdrawal.
  • Messaging and documents: kept out of email and push-notification text where they could leak.

What drives the cost is mostly this list: every proxy relationship, consent type and integration adds design and test work, and an EHR integration is usually the largest single item.

How should you run a health software project?

With a named compliance reviewer in the room from the spec stage, a threat model before code, and audit logging built on day one rather than added later.

StageWhat a health project adds
Before you hireAn honest fit check: has the team shipped what your buyers or regulator will ask about?
SpecificationYour compliance reviewer signs off data flows and vendors; a threat model identifies where health data lives and who can reach it
BuildAccess-isolation tests for every patient-facing query; audit logging from the first feature
Launch and handoverAn incident runbook that your compliance reviewer has read

Name one person, internal or external, who owns compliance decisions and can say yes or no. RAITHub will build to their requirements and flag risks it sees, but it will not be that person. RAITHub's phases are in how RAITHub delivers software, the testing method in how RAITHub tests, and how quotes work on the pricing page.

What it costs to build health software in 2026

Knack's August 2026 guide puts a basic patient-facing app (intake forms, scheduling, a simple portal) at $40,000–$80,000 and a full EHR-integrated platform at $150,000–$300,000 or more, with HIPAA-specific engineering adding 20–30% to the base build. Those are market figures, not RAITHub quotes. RAITHub publishes no rates; it gives a written fixed-scope estimate after a free 15-minute technical audit.

Health software costs more than an ordinary app with the same screens, for reasons specific to health data:

  • Read logging. Recording every view of a health record, not only every change, touches every patient-facing query and needs its own tests and retention rules.
  • Vendors that will sign a BAA. If you handle PHI for US customers, your hosting, email, analytics, error tracking and any AI provider may need to sign a Business Associate Agreement. That narrows the tools you can use, and some vendors offer a BAA only on higher-priced plans.
  • EHR and FHIR integration. Mapping to FHIR resources, the partner's profiles and version, and their app-approval process. Usually the largest single line.
  • Proxy access and consent. Every parent, carer or guardian relationship and every consent type adds states, screens and test cases.
  • Your compliance reviewer's time. Spec sign-off, vendor review and incident runbooks are real hours, budgeted by you, not by the developer.
  • Retrofitting. Knack estimates that adding these controls after launch costs 40–80% of the original build, which is why they belong in the first spec.
ScopeTypical market range (2026)What drives it
Basic patient-facing app$40,000–$80,000Intake forms, scheduling, a simple portal, audit logging from day one
Mid-complexity health app$80,000–$150,000Several roles, messaging, proxy access, consent management
EHR-integrated platform$150,000–$300,000+EHR integration, clinical workflows, reporting
One Epic or Cerner integration$20,000–$40,000 on its ownFHIR version and profiles, vendor approval, mapping and testing
HIPAA-specific engineeringAdds 20–30% to the base buildAccess controls, audit and read logging, encryption, BAA-eligible vendors
Maintenance, mid-sized product$15,000–$30,000 a yearPatching, vendor changes, audits of access and logs

All figures are from Knack's HIPAA-compliant app cost guide (August 2026). RAITHub's estimate lists access control, read logging, consent and each integration as separate lines with written assumptions. An EHR or FHIR integration would be new work for RAITHub, and the estimate says so rather than pricing it as familiar ground.

Why RAITHub for health software, and for which projects

Only for a specific kind of project: a team with its own compliance reviewer, building something like scheduling, intake or a portal, that values audit-first engineering and is comfortable being among RAITHub's first health projects. RAITHub is a founder-led software studio, founded in 2024 in Dhaka, Bangladesh, working with clients worldwide.

  • A healthcare scheduling app, built for a client. That is RAITHub's health work to date. It is not a regulated product, and there is no published health case study.
  • The controls, proven elsewhere. Row-level security, a hash-chained audit log and a 21-case IDOR suite on Sundor Skin; CI-gated suites of 750+ tests on TheSkinProof and 530+ on Sundor Skin. None of it was built for health data.
  • A plain fit answer. The free audit ends with a written memo that says whether RAITHub should build your product or whether you should hire a specialist.
  • Two ways to engage. A fixed-scope build, or a dedicated team for ongoing work. You own the code through a present-assignment IP clause, and an NDA is signed before any detailed discussion.

When RAITHub isn't the right fit

Hire a specialist health-software firm if you need a vendor with shipped regulated health products, a certified vendor, or a team that will own your compliance. Ask any firm you shortlist for a reference client whose product handles the same kind of data as yours.

  • You need proven regulated health delivery today. If your buyers, investors or regulator expect a vendor that has shipped a regulated health product, RAITHub has not; the closest it has is a healthcare scheduling app built for a client.
  • You are building software that may be regulated as a medical device. That needs a quality system and regulatory expertise RAITHub does not offer.
  • You need a SOC 2 or ISO 27001 certified vendor. RAITHub is not certified; see the security page.
  • You have no compliance partner and want the developer to fill that role. RAITHub will not interpret HIPAA or GDPR for your business.
  • You need a live EHR integration fast. A team that has already integrated with your target EHR will get there with fewer surprises.
  • You want developers placed inside your team under your own management. RAITHub offers fixed-scope builds and dedicated teams, not staff augmentation.

How do you start a conversation about a health product?

The HealthTech service page sets out what RAITHub builds. To talk it through, book the free 15-minute technical audit. Do not send patient data or PHI in the first message.

Describe the product, who the users are, which markets you serve and who your compliance reviewer is. You will get a written audit memo either way, including a plain answer on whether RAITHub is the right fit.

Last reviewed: 28 September 2026.

Frequently asked questions

Has RAITHub built a HIPAA-regulated product?

No. RAITHub has built a healthcare scheduling app for a client, but it has not shipped a regulated healthcare product. Its other relevant evidence is domain-neutral: row-level security, a hash-chained audit log and a 21-case IDOR security suite on Sundor Skin, and CI-gated test suites on live platforms.

Will RAITHub sign a Business Associate Agreement?

Whether a BAA is needed, and on what terms, depends on your project and should be decided with your compliance adviser. Raise it on the first call, before any PHI is shared.

Who does HIPAA apply to?

HIPAA applies to covered entities, which are health plans, health care clearinghouses and health care providers who transmit health information electronically in covered transactions, and to their business associates.

Is health data special under GDPR?

Yes. GDPR treats data concerning health as a special category of personal data. Article 9 prohibits processing it unless one of the conditions in that article applies.

What is FHIR?

HL7 FHIR is a standard for exchanging healthcare information electronically, built from resources such as patients and observations. RAITHub has not yet shipped a FHIR integration.

Can an app be HIPAA compliant on its own?

No. HIPAA compliance is an organisational obligation covering policies, agreements, training and safeguards. Software can support it, for example with access controls and audit logs, but cannot provide it alone.

How much does it cost to build a health app that handles PHI?

Knack's August 2026 guide puts a basic patient-facing app at $40,000–$80,000, mid-complexity apps at $80,000–$150,000 and EHR-integrated platforms at $150,000–$300,000 or more, with HIPAA-specific engineering adding 20–30%. These are market figures; RAITHub gives a written fixed-scope estimate after a free 15-minute audit.

Do I need a compliance partner to build a health product?

If your product handles health data, yes. Name one person, internal or external, who decides what the law requires of your business and signs off data flows and vendors. The developer builds to those requirements; it should not be the one interpreting them.

HealthTechHow to build health softwareHIPAAGDPRFHIRPatient portal developmentAudit logging

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.