# Healthcare Software Development | HIPAA & GDPR | Alher Tech

> Custom healthcare software for clinics, hospitals and digital health startups. HL7/FHIR, EHR integrations, HIPAA and GDPR/LOPD compliant.

- Canonical page: https://alhertech.com/en/industries/healthcare-software/
- Site: Alher Tech (custom software, AI agents and SEO engineering, https://alhertech.com/)
- Contact: https://alhertech.com/en/contact/

---

Custom software for clinics, hospital ops teams and digital health companies: HL7/FHIR, HIPAA, GDPR/LOPD, real EHR integrations.

## What Healthcare Software Delivers

- **Built for HIPAA, GDPR and LOPD from day one**: Healthcare buyers are private clinic groups consolidating under one practice management system, hospital innovation units replacing 15-year-old internal tools, and digital health startups building companion apps that need to plug into existing EHRs. The driver is rarely 'we want AI'. It is fragmentation: a clinic running Doctoralia for bookings, a separate billing tool, an HCE that does not talk to either, and staff re-typing patient data three times. We replace that with one system, integrated through HL7/FHIR, that respects RGPD on the EU side and HIPAA when there is US exposure.
- **Real HL7/FHIR integrations, not toy demos**: We have shipped FHIR R4 connectors against Epic, Cerner, Athena, OpenMRS and Spanish HCE systems like SELENE and HCIS. We map ADT messages, lab results, imaging orders and discharge summaries, including the messy real-world parts where extensions and custom Z-segments break naive parsers.
- **Telemedicine that holds up under load**: Video consults built on WebRTC SFUs (mediasoup, LiveKit) with sub-300ms latency, persistent chat, file sharing, e-prescriptions and post-consult notes auto-summarised by an AI scribe. We have run platforms with 800 concurrent consultations on a single cluster.
- **Imaging and DICOM where it matters**: For radiology, pathology and dermatology workflows we plug into PACS via DICOMweb (WADO-RS, STOW-RS), build viewers on Cornerstone3D and pipe studies into AI inference services. CE marking under MDR (UE 2017/745) class IIa pathways is something we have walked clients through.
- **Clinical UX, not enterprise UX**: A nurse on a 12-hour shift will not read tooltips. We design for one-handed use on a tablet, keyboard shortcuts for power users at the front desk, and forms that pre-fill from FHIR resources so nobody re-types a patient ID for the fourth time today.
- **Auditable AI inside the clinical workflow**: Triage assistants, clinical note summarisation and coding suggestions (CIE-10, SNOMED CT), all with explicit confidence scores, source citations and a human-in-the-loop step. We do not let an LLM autonomously diagnose. We let it accelerate the clinician.

## How We Build Your Healthcare Software

- **Clinical workflow shadowing**: Before writing a line of code we sit with the people who will use the software (receptionists, nurses, doctors, billing staff) and time the steps they actually take, not the ones the org chart says they take.
- **Compliance and data flow design**: We map every PHI touchpoint, define the legal basis under GDPR Art. 9, draft the BAA wording for HIPAA scope and align on data retention periods (5 years private clinic, 15 years hospital in Spain).
- **FHIR-first data model**: We design our internal entities so that exporting to FHIR R4 is a one-to-one mapping, not a future migration. This is what makes integrations with EHRs cheap later.
- **Iterative releases with clinical sign-off**: Two-week cycles, every release validated by a clinician on staff. Nothing reaches production until someone who treats patients confirms it does not break their day.
- **Penetration test before go-live**: External penetration test focused on the OWASP API Top 10 and HIPAA technical safeguards. Broken access control on a clinical system is not a bug, it is a regulatory incident.
- **Post-launch clinical support**: On-call rotation during the first 90 days, weekly review of access logs, monthly compliance report: the boring part that keeps you out of the news.

## High-performance stack used by global leaders

React/Next.js/Angular on the frontend and Java 21 + Spring Boot + PostgreSQL 14 on the backend: the same stack that BBVA, ING, and Netflix use for their security and performance.

## Healthcare Software: FAQ

### How much does it cost to build a healthcare software product?

A focused module (a booking + e-consent flow, a telemedicine MVP, a patient portal) typically lands between €25,000 and €60,000. A full clinic management system with EHR integration, billing and prescriptions runs €80,000-€180,000. A regulated medical device companion app under MDR scope starts around €120,000 because of the documentation overhead. We quote per-module after a free discovery call.

### How long does implementation take?

A first production release of a single module takes around 12 weeks. A full platform is delivered in 5-9 months in two-week increments. We do not do big-bang launches in healthcare. Every release is a chance for staff to break it before it breaks them.

### Are you familiar with HIPAA, GDPR and the EU Medical Device Regulation?

Yes. We sign BAAs for HIPAA-covered work, design every system around GDPR Art. 9 and the Spanish LOPD-GDD, and we have walked clients through MDR (Reg. UE 2017/745) class I and class IIa technical files. For US clients we also handle 21 CFR Part 11 audit trails when there is FDA exposure.

### Can you integrate with our EHR?

Almost certainly. We have shipped FHIR R4 and HL7v2 integrations against Epic (App Orchard), Cerner (now Oracle Health), Athenahealth, Meditech, OpenMRS, SELENE and HCIS. If your EHR has any modern interface, we connect to it. If it is a legacy system that only speaks SOAP or flat-file dumps, we have done that too. It is just slower.

### How do you handle data residency and patient privacy?

For Spanish and EU clients, we keep all PHI in EU regions (AWS eu-west-1/eu-central-1, Azure West Europe, OVH if data sovereignty is hard-required). For US clients we keep PHI in US-East/US-West with HIPAA-eligible services only. We never co-mingle EU and US patient data in the same database, and we never let clinical data leave the customer's tenant for analytics without explicit pseudonymisation.

### Can you help us pass an audit?

Yes. We hand over a security and compliance pack that covers audit trail samples, data flow diagrams, RBAC matrix, encryption configuration, backup policy and incident response runbook. Most of our clients use this directly for ENS, ISO 27001 or HITRUST audits without rewriting it.

### Do you build native mobile apps for patients?

When the use case justifies it, yes: React Native for cross-platform, native Swift/Kotlin when we need HealthKit, Google Fit, NFC for insurance cards or background BLE for connected devices. For most patient portals a PWA is enough and saves the App Store review pain.

### What happens to our data if we stop working with you?

You own everything: source code, infrastructure, database, documentation. We deploy on your cloud account from the first sprint, never ours. If we part ways, we hand over credentials and a 30-day support window. No data leaves with us, ever.

### Do you work with clients globally?

Yes. We work fully remote with clients across Spain, Europe, the US and LATAM. Time zones, video calls and live demos at every milestone.
