ROVQIX builds websites, patient portals and internal tools for healthcare organisations, with role-based access control, audit logging, minimal data exposure and WCAG 2.2 AA accessibility. We build the technical controls HIPAA and similar frameworks expect and are explicit about where policy and audit work sits outside engineering.
Healthcare software fails in two directions: too locked down to use, or too open to be defensible. The work is finding the version clinicians will actually adopt that still holds up under review.
Accessibility standard
Every record access
Role-based access
Signed where applicable
Role-based permissions enforced at the data layer, so what a user can see is a property of the query, not the interface.
A record of who accessed or changed what, retained per your policy and queryable when someone asks.
Appointments, documents, forms and secure messaging, designed for people who are unwell and in a hurry.
WCAG 2.2 AA including keyboard operation, contrast and screen reader testing — a legal and practical necessity here.
Collect only what is needed, expose only what a role requires, and delete on a defined retention schedule.
Connecting practice management, scheduling and records systems where documented interfaces exist.
We build the technical safeguards; administrative and physical safeguards, policies and formal certification sit with you and your compliance advisors.
| We handle | You or your advisors handle |
|---|---|
| Access control and authentication | Workforce training and policies |
| Audit logging and monitoring | Risk assessment documentation |
| Encryption in transit and at rest | Physical safeguards |
| Minimum-necessary data exposure | Business associate management |
| Secure development practices | Formal certification and audit |
| Infrastructure in compliant regions | Breach notification procedures |
Your users are disproportionately likely to have a disability, be older, be using assistive technology, or be trying to complete a task while unwell or distressed. An inaccessible healthcare site excludes exactly the people it exists to serve, and it carries clear legal exposure in most jurisdictions.
Where the engagement involves protected health information, yes. We also scope access so that in many projects we never need to touch live patient data at all, using seeded or anonymised datasets instead.
Where a documented API or integration interface exists, yes. Feasibility is confirmed during discovery before you commit to a build — some legacy systems genuinely cannot be integrated with cleanly.
We do not copy production data to development environments. Work uses seeded or anonymised datasets, and any production access is via named, scoped, audited accounts.
We implement the technical safeguards the Security Rule describes. Compliance as a whole includes administrative and physical safeguards and documentation that sit with your organisation. We will map clearly which parts we deliver.
Indicative ranges in USD. Every engagement is quoted to a written scope before work starts, so the number you approve is the number you pay.
$3,500 – $9,000
4–7 weeks
Best for: Providers needing a credible, accessible site
$18,000 – $60,000
10–20 weeks
Best for: Secure patient-facing functionality
from $1,200 / month
Ongoing
Best for: Systems patients depend on
How we think about this work, in more depth.
Healthcare
A 30-minute call, then a written proposal with scope, price and timeline within two to three working days. No retainer required to get a real number, and no obligation if the answer is that we are not the right fit.