Healthcare software that survives contact with your actual practice

Custom EHR/EMR and practice platforms, patient portals, and HIPAA work that goes past the report and into the code — for care organizations stuck on software that no longer fits, and for HealthTech products that have to be HIPAA-defensible before the next round.

If any of this is where you're stuck

  • Your practice management or EHR system was installed 8–15 years ago. It works just enough to keep the lights on, and every modernization idea dies on "we can't touch it."
  • Your team runs three to six systems that were never meant to share data — EHR, billing, lab portal, imaging, scheduling — and someone re-keys the same information into two of them every day.
  • Patients expect to book, message and pay online. You schedule by phone, and the portal that came with your EHR is the one patients abandon after the first login.
  • Since 2023 your workflow quietly acquired Slack, Google Drive, a transcription tool and an AI assistant. Your EHR vendor's BAA covers none of them, and nobody has looked at what that actually means.
  • You built an MVP with a general dev shop. An investor's technical diligence flagged it as not HIPAA-defensible, and the round is waiting.
  • Your HealthTech product is live with real patients and real uptime commitments, and you need AI in it without sending PHI somewhere it shouldn't go.
  • You have the clinical insight and no technical partner who understands why healthcare architecture is different from any other SaaS.

For practices, clinics and care organizations

Custom EHR/EMR, medical CRM and practice platforms

Off-the-shelf doesn't match how you work — a specialty workflow, an obligation nobody wrote a product for. We build the system that does: records, scheduling, documents, staff, compliance reporting in one place instead of four. Assisted living and homecare, mental health, physical therapy, multi-site groups. For substance-use practices, 42 CFR Part 2 — modeled wrong by most platforms.

Data exchange between systems: Healthcare Interoperability.

Patient portals and patient communication

Online booking, secure messaging, results delivery, intake forms, payments — wired into the system your staff already lives in, so nothing gets re-keyed. Plus the layer most portals skip: an AI assistant trained on your providers, plans and protocols that answers routine traffic and escalates the rest to a human, not a hold queue. Right of access lands in days, not a phone call and a fax — one of OCR's most frequently enforced areas. Anything it learns from is a scoped, disclosed secondary use on de-identified data.

HIPAA review and AI-tool remediation

A hands-on review of how patient data actually moves through your systems — code, database, infrastructure, and every third-party tool that touches PHI — followed by the fixes, not just the findings. Details below.

Legacy modernization and workflow automation

We take over healthcare systems other people wrote, including ones whose vendor is gone, then modernize in place: an integration layer around what works, the highest-pain systems first, no big-bang replacement, no pause in clinical operations. Non-PHI PHP, Laravel or Yii: Legacy Modernization →

What we also build, on request

AI documentation support in your clinical workflow, coding and billing automation between EHR and billing, prior-authorization automation, no-show risk scoring, smart reminders.

Need the data layer — FHIR APIs, SMART on FHIR, EHR-to-EHR exchange, CMS-0057 prior authorization?
That's Healthcare Interoperability →

HIPAA & AI Tools

Your EHR vendor's BAA does not cover the rest of your stack

Between 2023 and 2026 most care organizations added tools faster than anyone reviewed them. A transcription app. A shared drive. A team chat where patient names appear. An AI assistant that drafts letters. Each was a separate decision nobody made deliberately, and the BAA you signed with your EHR vendor covers exactly one of them: theirs.

Two things changed the stakes

Regulatory status reviewed: September 2026.

  • OCR is auditing risk analysis specifically. The Office for Civil Rights has made a missing or inadequate Security Rule risk analysis an enforcement priority — and "we have an EHR vendor" is not a risk analysis. Scope: every system where ePHI lives, not just the clinical one.
  • The Security Rule itself is being rewritten. HHS's proposed update would make today's "addressable" safeguards mandatory: multi-factor authentication, encryption at rest and in transit, annual risk analysis, a system inventory, network segmentation, vulnerability testing. Proposed January 2025, not finalized as of September 2026. None of it is work you'd regret doing early — all of it is already on a cyber-liability underwriter's or an enterprise security questionnaire.

What we actually do here

  • Map every place PHI enters, moves and rests — code, database, infrastructure, backups, logs, every third-party tool in the path, AI included — then tell you which have a BAA, which have a compliant configuration you aren't using, and which must be replaced.
  • Marketing pixels, analytics scripts and chat widgets on your site and portal are the most commonly missed, because nobody thinks of them as "tools." Several can send identifiable health information to a third party with no BAA — a leading source of recent HIPAA litigation.
  • Findings ranked by real risk, in plain language, with a short list of what to fix first — not a 40-page audit nobody reads.
  • Then the fixes, implemented in your systems — the part most compliance consultants hand back to you.

Try it on yourself first: 9 questions about the tools your organization actually uses. It scores your exposure, flags which gaps are the expensive ones, and gives you a scorecard you can forward to whoever signs off on it. Free and self-serve.

HealthTech Products

If you're building the product, not running the clinic

Healthcare architecture is where general development shops discover, usually late, that healthcare is different. PHI in an unencrypted column. Analytics tools processing patient data with no BAA. Audit logging that was never built. None of it is exotic; all of it surfaces at exactly the wrong moment — technical diligence, an enterprise security review, or a customer's first real question about where the data lives.

Three ways teams arrive here

  • HIPAA-defensible MVP

    Clinical insight, no technical partner. PHI handling, BAA-covered infrastructure, access controls and audit logging go in from the first sprint — retrofitting is the expensive version of the same work — plus the diligence pack a fund or enterprise buyer will ask for.

  • Remediation sprint

    The product exists, it works, and it just failed someone's review. We audit against the concerns raised, split findings into must-change and can-wait, and fix them in your codebase. A rebuild is occasionally right and usually not — runway is finite, and most of what gets flagged is weeks, not months.

  • AI into a live product

    Real users, real uptime commitments — and now it needs AI. The risks that matter aren't model quality: PHI leaving through an API call with no BAA, RAG over clinical data with no access-control boundary, AI output shown to a clinician with no human in the loop. Two boundary questions we settle in the architecture review, before the code: whether a clinician-facing feature crosses into clinical decision support or software-as-a-medical-device territory — different rules, different scrutiny, plus nondiscrimination expectations for anything shaping a patient-care decision — and whether patient data training or evaluating the model is a secondary use, which we scope contractually and de-identify by Safe Harbor or expert determination, not by assuming consent covers it. Then we ship behind feature flags.

AI Integration → · Healthcare Interoperability →

Three packages, either track

Care organizations

  • HIPAA & AI-Tool Review

    From $4,500 · 2–4 weeks

    The PHI map — code, database, infrastructure, backups, logs; every third-party tool in the path with its BAA status and configuration; findings ranked by real risk; a prioritized fix list; security-questionnaire answers you can paste.

  • Remediation & Hardening Sprint

    4–8 weeks · quoted after the review

    The fix list implemented — MFA, encryption at rest and in transit, access and same-day offboarding, audit logging, tool replacement or reconfiguration; verified backup and restore, not just "backups exist"; a 24-hour incident-response runbook; the documentation pack for your cyber-liability underwriter or an enterprise questionnaire.

  • System Takeover & Modernization

    Discovery 2–3 weeks · build quoted after discovery

    We read the system you have and document what holds it together and what is safe to change, in what order; then the integration layer, the portal, or the platform itself — scoped after discovery, not before.

HealthTech products

  • Architecture & HIPAA Review

    From $5,500 · 2–3 weeks

    Architecture and PHI-handling review against the concerns actually raised; findings split into must-fix and can-wait; the gap list for your diligence pack.

  • Remediation Sprint

    4–8 weeks · quoted after the review

    Surgical fixes in your codebase; plus the diligence pack — architecture document, PHI data-flow diagram, subprocessor and BAA list, security-questionnaire answers.

  • HIPAA-Defensible MVP or AI Feature Build

    MVP 10–16 weeks; AI feature build 4–8 weeks · quoted after the architecture review

    PHI handling, BAA-covered infrastructure, access controls and audit logging in the architecture from the first sprint; or, for a live product, architecture review first, then implementation behind feature flags.

Every engagement is fixed-scope and fixed-fee; the first on each track is priced above, later stages quoted once we know what's in your systems.

What we've actually shipped

19Years in business
200+Projects delivered
70Clients worldwide
45People on staff

Continuing Medical Education platform

A government-sponsored CME provider needed courses, live events and credit tracking to stay aligned with ACCME and AOA requirements, for physicians who are busy and dispersed.

Result: 12,000+ registered members and 4,000 credits earned on the platform to date.

Read the case study →

Custom LMS for a top-10 pharmaceutical company

A distributed sales force needed product and regulatory knowledge reinforced between live training sessions, without pulling reps out of the field.

Result: a scalable training platform for 300+ sales representatives, with structured reinforcement of knowledge beyond live events.

Read the case study →

Wibbi (ex-Physiotec) home exercise programs

Therapists needed patients to actually understand and follow home exercise instructions, and to sync progress data back into the clinic's own EMR/EHR.

Result: markedly easier to use for therapists and patients, with HEP progress in clear reports and data synced to EMR/EHR systems.

Read the case study →
"They worked hard to understand what the problems were and solve them correctly." Sharon McCormick, Clinical Director, The Listening Centre (EAP) Ltd
  • Healthcare software since 2011. Shipped healthcare products with real PHI: a physiotherapy exercise platform with EMR integrations, a homecare / medical HRMS, assisted living facility software, software for mental health counselors, a CME e-learning platform, and an LMS for a top-10 pharmaceutical company.
  • HIPAA experience is implementation experience, not a badge. We've built systems that handle PHI, worked under BAA, and done the remediation work — the part where someone has to change the code, not just describe the gap.
  • We take over other people's systems. Most of our healthcare work started with a codebase somebody else wrote and, often, a vendor who is no longer around.
  • Fixed scope on audits and first engagements.

Also: Medical HRMS · Assisted Living Facility Software · Software for Mental Health Counselors

Contracting entity is an Estonian company; the engineering team is distributed across Ukraine and the EU. HIPAA imposes no geographic restriction on a business associate, but that's not the whole answer — many state Medicaid contracts and enterprise DPAs do restrict offshore access to PHI. We'll answer the data-residency, subcontractor, BAA and continuity questions in writing before you ask twice; the team has been distributed since 2022, with delivery uninterrupted. And where the cleanest answer is that PHI never reaches Greenice at all, the work happens inside your infrastructure.

Frequently asked questions

Do we have to replace our EHR to work with you?
No. Most of what we do is built around the system you already have. Replacing an EHR is a 6–12 month project at best, longer for a multi-site group, and it disrupts clinical operations while solving only one of your problems — billing, scheduling and everything custom stay exactly where they were.
Our EHR vendor signed a BAA. Aren't we covered?
For their platform, yes. Not for the transcription tool, the shared drive, the team chat, the analytics, or the AI assistant. Those are your responsibility as the covered entity — and where you're not one, your state's rules and your contracts still apply — and they're where most of the exposure has accumulated since 2023.
Is Greenice HIPAA certified?
Nobody is — HHS doesn't recognize any private certification as proof of HIPAA compliance, and neither should your vendor review. What we can give you is implementation experience with PHI, work performed under BAA, and written answers to every question on your security questionnaire.
Do you have SOC 2?
Not currently. It's an audit report from a US CPA firm, not a certification, and we start that process against a specific contract rather than holding one speculatively. For most seed-to-Series-A buyers it isn't a blocker; if it's a blocker for you, tell us early and we'll talk about the timeline honestly.
Do you need access to our real patient data?
Usually not, and we'd rather not. Development and testing run on synthetic or de-identified data. Where production access is genuinely required, it happens inside your infrastructure, under BAA, with logging.
How is this different from a HIPAA compliance consultant?
A consultant produces the report. We produce the report and then change the code, the configuration and the infrastructure that the report is about. If you already have a report, bring it — we'll start from the fix list.
What about FHIR, Epic integrations, CMS-0057 prior authorization?
Same company, different page — that's Healthcare Interoperability. If you're not sure which one you need: if the problem is that two systems won't exchange data, start there. If the problem is that the software doesn't fit how your people work, you're on the right page.
We're a HealthTech startup, not a clinic. Is this for us?
Yes — HIPAA-defensible MVP, remediation before or after a technical review, and AI added to a product that's already live.
Our patient portal makes it slow for patients to get their own records. Is that actually a compliance risk?
Yes — patient right of access is one of OCR's most frequently enforced areas by case count. If your portal makes patients call, fax a form, or wait weeks for records they're entitled to, that's exposure independent of anything else on this page, and it's usually a portal workflow fix, not a system replacement.
We work with mental health and substance-use clients. Does HIPAA cover that?
HIPAA covers it, but substance-use-disorder treatment records carry an additional, stricter regime under 42 CFR Part 2 — consent and re-disclosure rules that go beyond a standard HIPAA authorization. If your organization touches SUD treatment records, that's a separate question from general HIPAA compliance, and we'll flag it specifically in a review.
Is HIPAA the only law we need to worry about?
No. Several states have their own health-privacy statutes that go beyond HIPAA — some cover data HIPAA doesn't reach, and at least one gives individuals a private right of action. Which ones apply depends on where your patients and your organization are; we'll name the specific ones relevant to you in a review rather than assume HIPAA is the ceiling.
We have EU users or patients. Does GDPR apply, and does your location change anything?
If you process personal data of people in the EU, GDPR applies regardless of where the software is built. Greenice's contracting entity is Estonian, inside the EU, which simplifies the DPA and subprocessor conversation rather than complicating it — we'll provide a subprocessor list and sign a DPA as part of onboarding.

Two ways to start

No commitment

Run the HIPAA & AI-tools self-check — 9 questions, a scorecard you can forward. Free and self-serve; booking a call after is optional.

Run the self-check

When you're ready

Book a 30-minute call with a specific agenda — bring one system, one workflow, or one review that flagged you.

Book a 30-minute call

Not sure which one fits? Let's talk.

OR LEAVE YOUR EMAIL AND WE’LL CONTACT YOU WITHIN THE SAME BUSINESS DAY

We reply within one business day, with a person, not a sequence. No newsletter, no drip campaign.