Healthcare · HIPAA
HIPAA compliant software development for products that handle patient data
If your product stores, processes or transmits protected health information, HIPAA is not a checklist at the end. It shapes the architecture. We build healthcare software to the Security Rule's technical safeguards, sign a Business Associate Agreement, and give your compliance team the evidence they need.

Short answer
HIPAA compliant software development means building health applications so that protected health information (PHI) is encrypted, access-controlled, audit-logged and handled under a Business Associate Agreement. Innovation Insight builds telehealth, patient portal, practice management and health data systems to the HIPAA Security Rule's technical safeguards, hosted in your HIPAA-eligible cloud account. Compliance is documented with you, not claimed by us alone.
What HIPAA requires from software
HIPAA applies to covered entities such as providers and insurers, and to business associates, which includes any software vendor that handles PHI on their behalf. The Security Rule sets administrative, physical and technical safeguards. Software teams are mostly responsible for the technical safeguards, and for supporting the administrative ones with logs and documentation.
An important nuance: there is no official HIPAA certification for software. Compliance is a property of the whole system, the organisation and its processes. What a development partner can do is build to the safeguards, provide evidence, and sign a Business Associate Agreement (BAA) that makes the obligations contractual.
Technical safeguards mapped to what we build
| HIPAA safeguard | What we implement |
|---|---|
| Access control (unique user IDs, emergency access, automatic logoff, encryption) | Role-based access, per-user identities, MFA, session timeouts, break-glass access with logging, encryption of PHI at rest |
| Audit controls | Immutable audit log of every read, write and export of PHI, with who, what, when and from where |
| Integrity | Checksums and versioning on records, signed API requests, tamper-evident logs |
| Person or entity authentication | Strong authentication, MFA, SSO with your identity provider, device policies |
| Transmission security | TLS 1.2+ everywhere, encrypted messaging and file transfer, no PHI in URLs or logs |
| Contingency planning (supporting) | Encrypted, tested backups, documented recovery procedures, defined recovery objectives |
| Breach notification (supporting) | Monitoring and alerting that surfaces suspicious access within hours, incident runbooks |
Hosting and the BAA chain
PHI must sit with providers that will sign a BAA. AWS, Azure and Google Cloud all offer HIPAA-eligible services under their BAAs, and we build only on those services, inside your own cloud account. Third-party services that touch PHI, such as email, SMS, video or analytics, are chosen from vendors that also sign BAAs, or PHI is kept out of them. We sign a BAA with you as your business associate.
What we build for healthcare
- Telehealth: video consultations, scheduling, e-prescribing integrations and secure messaging.
- Patient portals and apps: results, appointments, forms, payments and reminders.
- Practice and clinic management: scheduling, billing, documentation and reporting.
- EHR and FHIR integrations: HL7 v2 feeds and FHIR APIs with contract tests so upstream changes do not break care.
- Remote patient monitoring: device data ingestion, alerts and clinician dashboards.
- Health data analytics: de-identified reporting and research datasets.
How a HIPAA project runs differently
- Data mapping in discovery: where PHI enters, lives and leaves, and which vendors touch it.
- Threat model and architecture review before code, signed off by your compliance lead.
- Secure development: code review on every change, dependency and secret scanning, no PHI in development environments.
- Security testing: automated checks every release and a third-party penetration test before go-live.
- Evidence pack: architecture diagrams, control descriptions, log samples and policies for your risk assessment.
- Operations: monitoring, access reviews and incident response with 24-hour notification to you.
Cost
HIPAA adds roughly 15 to 25 percent to a comparable non-regulated build, mostly in audit logging, access control, testing and documentation. A patient-facing MVP typically runs $30k to $60k; a telehealth or practice management platform $80k to $200k or more. Engineers are $25 to $49 per hour, and discovery produces a fixed estimate.
| Project | Typical range | Timeline |
|---|---|---|
| Patient app or portal MVP | $30k to $60k | 10 to 16 weeks |
| Telehealth platform | $80k to $200k+ | 5 to 9 months |
| EHR/FHIR integration | $15k to $40k | 4 to 10 weeks |
| Security and compliance hardening of an existing product | $12k to $40k | 3 to 8 weeks |
Working with us from the US and Europe
Most of our healthcare clients are in the United States and the EU. For EU clients, GDPR applies alongside or instead of HIPAA and we add a data processing agreement and EU-region hosting. Our engineers work in your time zone for stand-ups and reviews, and your PHI never leaves your cloud account. Innovation Insight has delivered regulated healthcare and fintech systems from Lahore and Sialkot since 2019; references are shared under NDA.
A worked example: a patient portal
A multi-site clinic group wants patients to book appointments, see results, message clinicians and pay bills. The portal integrates with the group's EHR through FHIR. PHI stays in the group's AWS account under AWS's BAA; email and SMS go through providers that sign BAAs, with no PHI in message bodies. Every view of a result is audit-logged, sessions time out, and access reviews run quarterly.
| Phase | Weeks | Cost |
|---|---|---|
| Discovery, data mapping and threat model | 2 | $8,000 |
| Design and patient-facing web app | 5 | $18,000 |
| FHIR integration, messaging, payments | 4 | $16,000 |
| Security testing, penetration test, evidence pack | 2 | $8,000 |
| Pilot at one site, rollout | 2 | $6,000 |
| Total | 15 | about $56,000 |
The administrative side, and how we support it
HIPAA's administrative safeguards, risk analysis, workforce training, contingency planning and sanctions, belong to the covered entity, but software makes them workable or not. We provide the artefacts your risk analysis needs: data flow diagrams, control descriptions, access lists and log samples. We train our own engineers on HIPAA annually, and we operate under your policies when we have access to systems that contain PHI.
Common mistakes in healthcare software
- PHI in URLs, query strings, analytics events or application logs.
- Using consumer messaging or video tools without a BAA.
- Development and test environments seeded with real patient data.
- Audit logs that record writes but not reads.
- Shared accounts for clinic staff, which defeat access control and audit trails.
- Backups that are encrypted but never tested for restore.
Telehealth, remote monitoring and mobile
Video visits need a BAA-covered video provider, waiting-room and consent flows, and recording policies. Remote patient monitoring adds device data ingestion, thresholds and clinician alerts, plus a plan for what happens when a device goes silent. Patient mobile apps add biometric login, secure local storage and jailbreak detection. We have built all three and design them together so a patient's experience is consistent across web and mobile.
Beyond HIPAA: GDPR, SOC 2 and state laws
US clients increasingly also face state privacy laws and buyer demands for SOC 2. EU clients work under GDPR, where health data is a special category. The controls overlap heavily, so we build to the strictest applicable set once: encryption, access control, logging, data minimisation and documented processes. SOC 2 control evidence is available on request, and ISO 27001 certification is in progress across the company.
Getting started on a HIPAA project
- Discovery call under NDA to understand the product, the PHI involved and your compliance owner.
- Two-week discovery sprint: data mapping, threat model, architecture outline, prototype and a fixed estimate.
- BAA signed and cloud accounts set up in your name before any PHI is touched.
- Sprint delivery with security testing every release and a penetration test before go-live.
- Evidence pack delivered for your risk assessment, then a maintenance or dedicated-team retainer.
Innovation Insight's healthcare engineers have built patient-facing, clinician-facing and integration systems for providers and health-tech companies in the United States and Europe. The healthcare industry page describes the broader practice; this page is for teams whose first question is compliance.
Documents we provide during vendor review
- Information security policy summary and access control procedure.
- Architecture diagram with PHI data flows and hosting boundaries.
- Description of technical safeguards mapped to the Security Rule.
- Sample audit log entries and retention settings.
- Incident response plan summary with notification timelines.
- Penetration test summary and remediation status for hosted systems.
Next step
Tell us what you're building and get a written estimate.
A senior engineer replies within one business day. NDA on request.
Products we've shipped, and what happened next.
Case studies written from the technical documentation of each project: the stack, the scale and the outcome.
Questions we get asked a lot.
Is Innovation Insight HIPAA certified?
There is no official HIPAA certification for vendors. We build to the Security Rule's technical safeguards, sign a Business Associate Agreement and provide the evidence your risk assessment needs.
Where is patient data stored?
In your own HIPAA-eligible cloud account on AWS, Azure or Google Cloud, in the region you choose. We do not copy PHI to our systems.
Do you sign a BAA?
Yes, before any access to PHI.
Can you integrate with our EHR?
Yes, through FHIR APIs or HL7 v2 feeds, with contract tests so upstream changes do not silently break the product.
How much extra does HIPAA add to a project?
Typically 15 to 25 percent over a comparable non-regulated build, mostly in logging, access control, testing and documentation.
Do you also handle GDPR for EU health clients?
Yes. A data processing agreement with Standard Contractual Clauses and EU-region hosting are standard for EU engagements.


