A healthcare app that handles patient data must be built to the rules of every market it serves: HIPAA in the United States for covered entities and their business associates, GDPR in the EU and UK where health data is a special category, and device regulations if the software diagnoses or treats. The practical requirements are encryption, access controls, audit logs, signed agreements with every vendor that touches the data, and documented processes. A compliant healthcare MVP typically costs $100,000 to $250,000 (€85,000 to €220,000, £75,000 to £185,000) and takes 5 to 8 months.
Prices are in US dollars. Euro and pound figures in parentheses are approximate, rounded conversions. Quotes are issued in the currency of your contract.
Healthcare software carries the strictest rules of any consumer-facing product, for good reasons. Founders who plan for them from the start build compliant products at a modest premium. Founders who discover them after the design is finished rebuild. This guide covers which rules apply, what they mean technically, the medical device question, and a budget. It is general information, not legal advice.
Which rules apply to your product?
| Rule | Where | When it applies | What it mainly requires |
|---|---|---|---|
| HIPAA and HITECH | United States | You are a healthcare provider, health plan or clearinghouse, or you handle protected health information for one | Administrative, physical and technical safeguards, business associate agreements, breach notification |
| GDPR and UK GDPR | EU and UK | You process personal data of people in these regions. Health data is a special category with stricter conditions | Lawful basis, explicit consent or another special-category condition, data minimisation, rights of access and erasure, data protection impact assessment |
| Medical device regulation | US (FDA), EU (MDR), UK (MHRA) and others | The software diagnoses, prevents, monitors or treats a condition, or influences clinical decisions | Classification, quality management system, clinical evaluation, registration or approval before market |
| National health data laws | Varies | Additional rules on where health data may be stored and who may access it | Data residency, local approvals |
Two questions decide most of it. Does the app handle identifiable health information? And does the app make or influence clinical decisions? Yes to the first brings HIPAA or GDPR. Yes to the second brings device regulation, which is a different order of effort and timeline. Wellness and fitness apps that do not claim to diagnose or treat usually sit outside device rules but inside data protection.
What do the rules mean technically?
- Encryption everywhere. Data in transit and at rest, with keys managed separately from the data and rotated.
- Access controls. Role-based, least privilege, with unique accounts for every user and automatic session timeouts. A nurse sees their patients, not every patient.
- Audit logs. Every access to and change of patient data recorded: who, what, when, from where. Tamper-evident and retained for the required period.
- Authentication. Multi-factor for clinical and administrative users, strong authentication for patients.
- Data minimisation. Collect what the product needs and no more. Separate identity from clinical data where possible.
- Backup and availability. Tested backups, recovery procedures and uptime appropriate to how the product is used clinically.
- Secure development. Code review, dependency management, security testing and independent penetration testing before launch.
- Vendor control. Every service that touches patient data, from hosting to email to analytics, must be covered by a business associate agreement in the US or a data processing agreement in the EU, and must be capable of the same safeguards. Many common consumer tools are not.
What else does compliance require beyond the code?
Regulators look at the organisation as much as the software. Expect to need written policies, risk assessments, staff training records, an incident response plan, breach notification procedures and, under GDPR, a data protection impact assessment and possibly a data protection officer. A good development partner delivers the technical documentation that feeds these. A compliance adviser helps you produce the rest.
Which features belong in the first release?
- Secure onboarding for each user type, with identity and consent captured properly.
- The core clinical or care journey, complete: a consultation, a monitoring workflow, a care plan, an appointment.
- Messaging or data sharing between patient and clinician, if it is central, built to the safeguards above rather than through a general-purpose chat service.
- An audit trail visible to administrators.
- A clinician or administrator portal with the access controls that clinical staff expect.
- Patient access to their own data, and export or deletion where the law requires.
Later: integrations with electronic health records and laboratory systems, wearables and devices, e-prescribing, billing and insurance claims, analytics across populations.
What about integrating with clinical systems?
Electronic health records, laboratory systems, imaging and scheduling systems each have their own interfaces, often based on standards such as HL7 and FHIR, and each provider has its own approval process for third-party access. These integrations are valuable and slow. Scope one at most into a first release, and only if the product cannot function without it. Many successful healthcare products launched standalone and integrated once they had adoption to justify the effort on both sides.
What does it cost and how long does it take?
| Scope | Typical cost | Timeline |
|---|---|---|
| Wellness or patient engagement product with personal data but no clinical decisions | $60,000 to $140,000 (€50,000 to €120,000, £44,000 to £105,000) | 4 to 6 months |
| Clinical workflow product with protected health information, audit and clinician portal | $100,000 to $250,000 (€85,000 to €220,000, £75,000 to £185,000) | 5 to 8 months |
| Product subject to medical device regulation, or with EHR integration | $250,000 to $600,000 (€220,000 to €520,000, £185,000 to £445,000) plus regulatory costs | 9 to 18 months |
Compliance advisory, legal review, penetration testing and any device certification are additional. Budget for them from the start.
What mistakes do healthcare founders make?
- Using consumer tools for messaging, storage or analytics that cannot sign the required agreements.
- Discovering the medical device question after the product is built.
- Building for one jurisdiction's rules and then selling into another.
- Treating audit logs as a nice-to-have.
- Underestimating clinician adoption. A secure product that clinicians find slow will be worked around, and the workaround is the breach.
How 7L builds healthcare products
Healthcare is one of our core industries. We have developed secure applications that allow doctors and other healthcare stakeholders to cooperate in managing services and sensitive data, built for HIPAA and HITECH compliance, with cryptography, real-time data, next-generation user experience, custom integrations and service reliability. Compliance is a design input from the first call, and we work alongside your compliance adviser so that the documentation and the software agree. If you are planning a healthcare product, tell us who the users are and what data it handles.
This post is general information, not legal advice. Health data and medical device regulations differ by country and change over time. Engage qualified compliance and legal advisers for each market before building.
Frequently asked questions
Does HIPAA apply to my wellness app?
HIPAA applies to covered entities, meaning providers, plans and clearinghouses, and to their business associates. A consumer wellness app with no connection to a covered entity is typically outside HIPAA, though other privacy laws apply. The moment a provider uses your app with patient data, you are likely a business associate.
Is a symptom checker a medical device?
Often, yes, depending on what it claims and how it influences decisions. Software that suggests a diagnosis or a treatment is likely within device regulation in the EU, UK and US. Software that provides general information is usually not. The wording of the product's claims matters, so get advice before writing them.
Can I use a standard cloud provider for health data?
Yes, the major cloud providers offer configurations and agreements suitable for HIPAA and GDPR health data. The obligation is on you to configure and use them correctly, which is part of what a competent development partner does.
Do I need a data protection impact assessment?
Under GDPR, processing health data at scale almost always requires one. It is a structured document describing the processing, its risks and the mitigations. Your compliance adviser produces it with technical input from the development team.
How do I get access to a hospital's electronic health record system?
Through the vendor's developer programme and the hospital's own approval, which can take months. Start the conversation early, scope the integration narrowly, and do not make the first release depend on it unless the product cannot work without it.