Sector · Healthcare

Appointment portal for clients. Custom-built, GDPR-secure, integrated with your EHR.

We build patient portals that fit how things actually work in your practice or institution. Online appointment booking, smart reminders, video consultations, pre-visit questionnaires and direct access to the record, with DigiD, FHIR and NEN 7510 built in from the first sprint.

ForGPs & Health Centres
ForPhysiotherapy & allied health
ForMental health & psychology
ForDental & audiology
ForHospital outpatient clinics

Primary and secondary healthcare in the Netherlands in figures.

~5.000
GP practices in the Netherlands
~7.000
Physiotherapy practices
~280
Hospital sites & clinics
17,9M
Residents entitled to digital access to their records

Source: NIVEL Cijferbasis 2024, CBS population counter, Nictiz MedMij Annual Report 2024.

Standard portals are built for an average practice.

Most healthcare providers work with a patient portal that comes as a by-product of their EHR: an appointments module in Medicom, a my-environment in HiX, a widget from MijnQuarant. The basics work (booking an appointment, receiving a confirmation), but once the practice wants more than that, it gets stuck because the portal was not designed for your care line.

A GP practice wants open-slot scheduling for follow-up consultations but telephone triage for acute complaints. A physiotherapist wants pre-visit questionnaires so the first fifteen minutes in the treatment room aren't spent on a paper intake form. A mental health provider wants video consultations alongside face-to-face, with the same record context. A hospital outpatient clinic wants multidisciplinary appointments where radiology, the surgeon and the intake nurse are all scheduled on the same day.

A custom appointment portal solves that: the flow for each care line is exactly what it needs to be, the patient arrives prepared for the consultation, and your secretariat no longer spends time on phone calls that could have been done in two taps. For the broader technical context of healthcare apps, see our page on custom healthcare software development.

Experience tells us that the value of a proprietary portal is not only in efficiency; it is also in client satisfaction and continuity of care. A client who can book an appointment online when the practice is closed, a parent who books for two children at once, a chronic patient who gets a repeat consultation the same afternoon after requesting a repeat prescription: these small differences are what a practice builds its reputation on in the neighbourhood. For multi-location care providers, there is an added benefit: a single portal that works across all sites prevents each location from building its own channel, which would later need to be migrated or consolidated.

A portal that suits every care pathway.

A dedicated flow, dedicated integrations and dedicated privacy requirements for each discipline. Under each tab is an outline of what we typically build, not a one-size-fits-all template, but a shared technical foundation.

GP care

The largest volume of traffic is here: repeat medication, repeat consultations, GGD referrals, and annual checks for chronic care pathways (T2DM, COPD, CVRM). An appointment portal for a GP practice must distinguish between what can be booked by the patient directly and what requires triage, without the patient having to click through seven screens first.

Our module set for GP care includes DigiD login for BSN-based identification, a scheduling layer that only shows freely bookable slots per consultation type, a repeat prescription flow with direct FHIR transmission to Medicom or Promedico, and a reminder module with SMS and push notifications for annual checks.

  • DigiD via LogiusBSN-based identification without creating a separate account.
  • Consultation-type-aware schedulingAcute, routine, repeat and chronic slots, each with their own availability.
  • Repeat prescription flowFHIR transmission to Medicom or Promedico, with pharmacy routing.
  • Chronic care remindersT2DM, COPD and CVRM annual checks via SMS and push.

Built to the strictest healthcare standards.

Compliance is not optional and not an afterthought. An appointment portal touches the whole of the Wbsn-Z, GDPR, NEN 7510, the MedMij rules and the WGBO retention obligation. We work within that framework from the first sprint. For more technical detail, see our page on building NEN 7510-compliant software.

NEN 7510: information security in healthcare

Deliberate risk management

Our patient portals are built in accordance with NEN 7510-2:2017. Risk analysis of data flows, access rights, logging and penetration testing take place before go-live. For large chains, we bring in an accredited auditor for the formal certification.

GDPR & UAVG

Privacy by design

For every project we deliver a DPIA under Article 35 GDPR. Data flows, legal basis (performance of a treatment agreement under Article 6(1)(b) and Article 9(2)(h)), retention periods and data subject rights are documented for the Data Protection Officer.

WGBO and GDPR retention periods

20-year retention obligation

The WGBO retention obligation for the medical record and the adjusted periods for erasure requests are built into the retention policy. Clients can exercise their rights through the portal: access, copy, correction and requests for erasure.

BSN access via DigiD

Wbsn-Z-compliant identification

BSN-based authentication via DigiD (assurance level Substantial or High, depending on the care context). The integration runs via Logius and is approved for healthcare portals. No "self-created account": that doesn't meet the requirements for a BSN integration.

MedMij / FHIR

Personal health environment

The portal complies with the MedMij agreement set so that clients can share their data with a personal health environment (PGO) of their choice (such as Ivido, Quli, MedMij Drugref). FHIR R4 as the interface, Nictiz care information building blocks as the data model. Onboarding via MedMij is supported, and we can arrange participation for you.

eIDAS: electronic signatures

Signing treatment agreements

For informed consent forms, treatment agreements and questionnaires that require a signature, we support eIDAS-compliant electronic signing (advanced or qualified, depending on the use case).

EU AI Act

Responsible AI in triage

For AI features such as intake triage or free-text classification of questionnaires, we make the risk classification explicit, document the governance process and stay within the threshold the EU AI Act sets for healthcare applications.

Seamlessly integrated with the EHR you already use.

The portal does not replace your EHR. It sits alongside it, reading and writing through a secure integration layer. We have working integrations with the systems listed below. For the broader pattern context of patient record apps, see building an electronic patient record app.

Medicom
GP EHR (PharmaPartners)
Promedico-ASP / VDF
GP EHR
OmniHis Scipio
GP EHR
HiX
Hospital EHR (ChipSoft)
Epic
Hospital EHR (UMCs)
MijnQuarant
Allied health / physiotherapy
HC&H / Intramed
Allied health & dental care
Centric Zorg / Procura
Care, mental health & primary care

No one-off integrations built per project.

The integrations above we have standardised across multiple healthcare projects. For a new engagement we set up the integration on the same abstraction layer: an internal FHIR canonicalisation, so that a GP practice and a physiotherapy practice can use the same portal front end on top of different EHRs. That means fewer bugs, a shorter lead time, and the maintenance sits with your IT supplier or FG, not with us.

For custom middleware, older SOAP services or a hospital-specific HL7 bus, we build an adapter case by case. This takes a little extra time in the planning phase, but it avoids the familiar integration debt later on: a working integration that has never been tested against new versions of the EHR.

The portal can also be used purely as a booking layer on top of a diary system for healthcare providers that do not yet have a full EHR. See our work on building a booking system for the underlying reservation architecture.

The technical building blocks under the bonnet.

No black box. We document the entire stack so that your IT team, information governance officer and accountant can see exactly where everything runs — and how we could be replaced without disruption.

Backend

PostgreSQL + Node.js

EU hosting with an NEN 7510-certified provider. Encryption at rest with keys held in an EU HSM. No data leaves the EEA, and no sub-processors outside Europe.

Identification

DigiD via Logius

BSN-based authentication in line with the Wbsn-Z, at Substantial or High assurance level. For healthcare staff, a UZI pass or a qualified alternative via eHerkenning.

Interoperability

FHIR R4 + ZIBs

Your own FHIR server on top of the EHR for a standardised read and write layer. Nictiz health information building blocks (Zorginformatiebouwstenen) as the data model. Compatible with the MedMij set of agreements.

Video consultation

Own WebRTC or Whereby

End-to-end encrypted video consultation, optionally with server-side recording that lands in your EHR. No external party in the chain where the clinical context requires it.

Notifications

SMS, email & push

Multi-channel reminders via an EU SMS provider and our own push server. Clients choose their channel in the portal; no tracking pixels in emails.

Questionnaires

FHIR Questionnaire

Standard questionnaires (PSK, PHQ-9, GAD-7, SF-36) and custom questionnaires as FHIR Questionnaire resources, with automated scoring and forwarding to the EHR.

Multi-language

NL, EN, AR, TR, PL

For neighbourhoods and primary care practices with a diverse public, a multilingual portal as standard. Translations by healthcare interpreters, not raw LLM output.

Accessibility

WCAG 2.2 AA

Keyboard navigation, screen reader labels, contrast and a large-text mode as standard. Mandatory for public healthcare organisations under the Dutch Temporary Act on Digital Accessibility.

Management & decommissioning

Open-source stack

We work with open-source components wherever possible and deliver source code plus deployment documentation. No lock-in: if you want to move to another supplier tomorrow, you can.

From intake to go-live in clear steps.

An implementation project for a care portal has its own rhythm. Five phases recur in every project, whether it's a GP practice or an outpatient clinic.

01 · Audit

Workflow and EHR mapping

A day-part in your practice with a GP, practice manager and assistant. Outcome: current flows mapped, EHR interfaces identified, and an initial DPIA outline ready.

02 · Design

Scope per care pathway

For each discipline, which flow goes into the portal, which integrations take priority and which questionnaires are included by default. NEN 7510 risk analysis on the scope.

03 · Build

Fortnightly sprints

One working flow delivered every sprint. Practice staff test along from the start; the first flow is usually live on a test environment within a few sprints.

04 · Cutover

Phased go-live

First one care pathway, then the next. Each rollout includes training for administrative staff, a written work instruction and a handover to your practice manager or quality officer.

05 · Maintenance

Ongoing

We support every EHR update, GDPR guidance change and MedMij version bump. Fixed monthly fee, first-line incident response in line with your NEN 7510 requirements.

Built for healthcare providers.

GP chain · Randstad

Self-scheduling portal for repeat consultations

DigiD login, FHIR integration with Medicom, and automated SMS reminders for annual chronic-care check-ups across multiple practices.

−61%
inbound call minutes
9 practices
combined into one portal
Physiotherapy chain · North Holland

Pre-visit questionnaires & video consultations

PSK, NPRS and our own intake questionnaire as FHIR Questionnaire, integrated with MijnQuarant. Video consultations for follow-up via our own WebRTC.

−42%
paper intake
11.000+
clients with an active account
Outpatient clinic · Secondary care

Multidisciplinary appointment portal

Three care lines that take place on a single day within one appointment flow: surgeon, anaesthetist, and intake nurse. Integration with HiX through the agreed FHIR layer.

3 care pathways
in one booking flow
SUS 84
client satisfaction

Recognised within healthcare.

Nictiz MedMij annual report 2024

"The emergence of dedicated appointment portal suppliers is accelerating the use of MedMij among care providers who don't want to rely solely on the EHR portal."

LHV Practice Perspective 2024

"GPs who have introduced self-scheduling for repeat consultations report noticeably fewer inbound phone calls and higher satisfaction among stable patient groups."

Client survey, mental health institution

"The video consultation portal has noticeably reduced no-shows for intake appointments. Clients especially value direct access to their treatment plan."

Answers for the healthcare manager going digital.

The questions we hear most often from practice managers, quality officers and IT coordinators.

How does your portal differ from the standard portal in my EHR?
An EHR portal is a standard product built for "all GPs", designed to work for as many practices as possible. Our custom portals start from your care line, your consultation types, your questionnaires and your patient group. We write back neatly to the EHR via FHIR, but the patient experience is fully tailored to your practice. For a detailed comparison with records apps, see building an EHR app.
Does it comply with NEN 7510 and the GDPR?
Yes, that is non-negotiable. An appointment portal handles special category data (health data) and falls under NEN 7510, GDPR Article 9 and the WGBO retention obligation. From the first sprint we work within that framework: NEN 7510 risk analysis, DPIA, penetration test before go-live, sub-processor register and logging on all record actions. For larger organisations we guide the process towards a formal NEN 7510 certificate — which is issued to the organisation, not the software, but our software supports the audit process.
How does the DigiD integration work?
The DigiD integration runs via Logius. Connecting requires the care provider to submit a connection request to Logius, plus a SAML integration at assurance level Substantial or High. We guide the application, supply the technical connector and make sure the entire flow complies with the Wbsn-Z (the Dutch act on the use of the citizen service number in healthcare). Clients log in with the DigiD app, SMS or ID verification via the DigiD app, and the portal links the BSN to the correct record in your EHR.
Do you work with Medicom, HiX or Promedico?
With all three, and with OmniHis, MijnQuarant, HC&H/Intramed, Centric Zorg, Procura and Epic. For Epic and HiX we work through the agreed FHIR interfaces with the vendor; for Medicom and Promedico via their published interfaces. The portal has its own internal FHIR abstraction layer, so for your patients the difference is invisible, while for your IT team it delivers a reusable integration layer.
What is MedMij and do I need to take part?
MedMij is the Dutch framework of agreements for data exchange between care portals and personal health environments (PGOs). Participation in MedMij is not mandatory for an appointment portal, but it is relevant for clients who want to share their data with a PGO such as Ivido or Quli. We build the portal to be MedMij-compatible as standard, and we complete the participation process during the cutover phase.
How do you handle video consultations and privacy?
We offer two variants: a custom WebRTC stack on EU hosting with end-to-end encryption (no traffic via US servers), or an embedded Whereby Embedded integration where the care context allows it. Recordings, if required, land directly in your EHR; the video stream itself doesn't pass through a third party in the chain if the NEN 7510 classification rules that out.
How much does an appointment portal cost?
For one care line with a standard EHR integration and a limited number of questionnaires, an MVP engagement is compact. A cross-chain portal with multiple care lines, multi-EHR support, video consultations, MedMij participation and a multilingual flow is a larger engagement. We work with a fixed sprint budget and provide a concrete total price for the complete build after the planning phase: no open-ended scope, and no scope creep without your agreement.
Who pays the DigiD, MedMij and Logius costs?
The subscriptions with Logius (DigiD) and MedMij membership are arranged through your organisation, and we have no retainer or pass-through charge on them. We do advise which subscription type suits your volume, and we help with the connection application, including the privacy impact justification that Logius expects with the application.
Does this also work if we want an internal staff portal for our care teams?
Yes. The underlying stack (authentication, FHIR layer, calendar) is equally suited to an internal portal for the care team. For the broader context of internal employee environments, see our page on building an employee portal.
How will our secretarial staff embrace the portal?
Sprint 1 always includes a workshop with your practice secretariat. Their input shapes the flow; the design is never imposed over their heads. At handover there are two training sessions and a written user guide. We have seen that practices where the secretariat is involved from the start notice a drop in incoming phone calls within a few weeks of going live.
Share LinkedIn Email

Ready to make your appointment portal future-proof?

A half-hour introductory conversation with the practice manager and one care professional. We listen, ask questions about your EHR and care line, and suggest an initial direction. No obligation.

Edit content