Authorisations and logging
Access to health data only for authorised roles, with a log of who viewed or changed which data and when.
Industries · Healthcare
Our healthcare software development covers systems for healthcare providers, patient portals and integrations with electronic medical records - with the level of security that health data requires. We take into account the GDPR, the confidentiality of patient information under Polish law, the obligations of the Polish KSC Act and accessibility requirements, and our penetration testers check every system before it goes live.
01Challenges
Healthcare software processes data that enjoys the strongest protection in law: health data is a special category of personal data, information about patients is confidential, and medical records must be available whenever they are needed for treatment.
That is why, in these projects, non-functional requirements - security, system availability, an audit trail of data access and business continuity - matter as much as features.
We build systems that complement core hospital and clinic systems:
For integrations we use the patterns described on our system integration page, and we build patient apps in the same way as our mobile and web applications.
02Health data
03Integrations
The systems we build for healthcare providers rarely replace the clinic or hospital system - more often they complement it: a patient portal, document workflow, reporting. That is why we design integrations so that health data has a single source of truth and every transfer is recorded in a log.
We test integrations with external systems for security in the same way as APIs - the scope is described on our API penetration testing page.
04NIS2/KSC
Healthcare is a sector listed in Annex 1 to the Polish National Cybersecurity System Act (KSC Act) - medium-sized and large entities in this sector are, as a rule, important or essential entities (Art. 5(1)(1) and (2)(1)-(2) of the KSC Act). The competent authority is the minister responsible for health (Arts. 41 and 41a of the KSC Act).
The obligations include an information security management system, incident reporting and - for essential entities - an audit. The status of independent public healthcare institutions (SP ZOZ) and of hospitals run as companies, the competent authority, the CSIRT and the deadlines are described on our NIS2 and the KSC Act in hospitals page, and you can check the status of your facility with our NIS2 scope checker.
For a software vendor, this means that the healthcare provider will assess the security of the vendor's systems as part of its supply chain. We help the provider demonstrate this with:
05Accessibility
Polish accessibility rules for the public sector, including public healthcare:
Many patients are older people, have visual or hearing impairments, use screen readers or browse on a phone with heavy magnification. We design interfaces to WCAG 2.2 level AA and check them both with tools and manually - as described on our web applications page.
06Security
Access to health data only for authorised roles, with a log of who viewed or changed which data and when.
Encryption in transit and at rest, and backups in the EU with tested restores - records must be available whenever they are needed.
A penetration test of the application and its integrations before launch, with a retest of fixes - as part of our secure by design lifecycle.
The whole process is described on our secure by design page. If a healthcare provider uses systems from other vendors, we can test their security too - see web application penetration testing.
Yes, but under strictly defined rules: under Polish law, the people who maintain a system holding medical records and keep it secure process the data on the basis of the controller's authorisation and are bound by secrecy, also after the patient's death (Art. 24(2)(2) and (3) of the Act on Patient Rights and the Patient Ombudsman). That is why we grant access to named individuals only, on a least-privilege basis and with an event log.
Large-scale processing of health data requires an impact assessment (Art. 35(3)(b) GDPR). We help prepare its technical part - a description of data flows, safeguards and risks - because it follows naturally from the threat model of the system.
We design integrations between healthcare providers' systems and their environment, including the health data flows required by the Polish Act on the Healthcare Information System. Service providers keep electronic medical records and submit medical event data to the Medical Information System (SIM) - in Poland this is often called “integration with P1”, after the platform defined in Art. 7 of the Act. We agree the scope of the integration with the vendor of the clinic or hospital system the provider uses.
Healthcare is a sector of high criticality listed in Annex 1 to the KSC Act, and the status of an entity depends on factors including its size. You will find who the rules cover and which deadlines apply on our NIS2/KSC audit page.
Public healthcare providers in Poland, such as independent public healthcare institutions (SP ZOZ), are subject to the Polish Digital Accessibility Act and to WCAG 2.1 level AA. Whatever the legal obligation, we design interfaces to WCAG 2.2 AA - many patients are older or have impairments.
Compliance · NIS2/KSC
NIS2 audit under the Polish KSC Act: who is in scope, deadlines 3 April 2027 and 3 April 2028, duties, the Art. 15 audit and fines. Gap analysis, pentests.
Custom software · Integration
System integration services: ERP, CRM, MES and WMS connected via APIs, queues or ETL, with monitoring and security based on the OWASP API Security Top 10.
Penetration testing · Web applications
Web application penetration testing to OWASP WSTG v4.2: authentication, permissions, business logic and APIs. A report with evidence, CVSS and a retest.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877