Custom healthcare app development
A care app is a mobile application with which care professionals record information at the bedside and clients view their own care data, linked to the source system where the record lives. Appfront builds these apps to measure: tailored to your care process, with data exchange via HL7 FHIR, and built to NEN 7510 and the GDPR so you stay demonstrably in control of who sees which record.
What is a care app?
A care app is the mobile shell around your care record. The record itself stays in the source system, usually an electronic health record or EHR. The app retrieves the data needed at that moment and writes the entry back. This distinction matters: an app that keeps its own shadow record recreates exactly the duplicate admin you wanted to avoid.
In practice there are two users with opposing needs. The care worker wants to sign off an action with one hand, standing beside a bed, in a few taps. The client or family carer wants to read the care plan calmly at home and reschedule an appointment. Cramming both into one interface produces an app where neither feels at home. That is why we build them as separate entry points on the same secure foundation.
Where a care app really stands out is in its evidential burden. The Act on Supplementary Provisions for the Processing of Personal Data in Healthcare (Wabvpz) refers, via the Decree on Electronic Data Processing by Healthcare Providers, to NEN 7510, and as a healthcare provider you must be able to demonstrate that you meet that standard. Logging, authorisation and data minimisation are therefore not an afterthought; they shape how the app looks from the very first sketch.
One record, no copies
The app reads from and writes to the source system directly via an integration. There is no second version of the truth, and the care professional doesn't have to retype anything from another screen.
Logging under NEN 7513
NEN 7513 describes how you record actions on an electronic record. Every access and change is logged, so it stays traceable who opened which record and why.
Keeps working with poor coverage
In a basement, a lift or a home with no signal, registration carries on. As soon as connectivity returns, the app synchronises and any conflicts are put to the care worker explicitly.
How we build your care app
We start not with screens but with the care process and the data flows. Care workers, your data protection officer and the administrator of the source system sit at the table early, because that is where the decisions live that are costly to change later.
We walk through the workflow as it really happens: who records what, at what moment, and on what legal basis. For each data flow we define which data is needed and which is deliberately not retrieved.
We design the integration with your EHR, preferably using HL7 FHIR resources, along with the authorisation model and logging. We also determine what may be available offline and what the device must never store.
We build in short iterations and let care workers follow along with working versions as we go. An action that seems logical in the office often turns out to be two taps too many at the bedside.
Controlled rollout via your mobile device management, with monitoring of integrations and synchronisation. Then ongoing maintenance, including when the Wegiz (Dutch Electronic Exchange of Health Information Act) makes new exchanges mandatory.
If you show data to a patient, they have the right to see who has accessed their record. See Wabvpz software.
Two applications that start on the shop floor: reporting an incident at the moment it happens and logged access outside the institution.
If you work in youth care, the difference often lies in what happens to the hours you record: they have to match the assignment before you can claim them. This is described in our app for start, stop and hours in youth care.
What a care app actually does
Which functionality matters most differs greatly between a home care organisation, a mental health institution and a hospital ward. These are the components we build most often.
Recording at the bedside
Capturing treatments, measurements and reports at the moment they happen, rather than from memory at the end of the shift. Input fields follow the structure of your record, so the data flows back usefully into the source system.
Medication overview and sign-off
Viewing the current medication overview and signing off administration, with a checking step for discrepancies. The app shows what has been prescribed, not a list kept by hand.
Care plan and goals
The care plan with goals and agreements made visible to both carer and client, so that both work from the same plan and evaluations do not disappear into loose notes.
Client portal and informal carers
Clients and, with their consent, their relatives can view appointments, reports and the care plan. See also our work on patient intake software.
Secure messaging
Messaging between care professionals and with clients, with the trust framework described in NEN 7512 for electronic communication in healthcare. For traffic with other care providers, we build a ZorgMail integration.
Management information without personal data
Aggregated figures on turnaround times, treatments and usage, built from minimised data, so team leaders can steer without looking into records.
Which care organisations we build for
The care process determines the app, not the other way round. The focus differs depending on the type of organisation.
Residential care institutions
Nursing homes and clinics where several carers work on a single client. Here the emphasis is on handover: what happened during the previous shift, and what is still open now.
Home care and community teams
Teams who are on the move all day and record on location, often with patchy coverage. Routing, scheduling and offline working matter most here.
Mental health and long-term support
Care pathways that run for months or years, where the care plan and evaluation take centre stage rather than individual treatments. See also our mental health software.
Care software vendors
Software vendors who want to give their existing package a mobile layer without rebuilding its core. We build the app on the API you already have, or help you get that API in order first.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations in healthcare
A care app stands or falls with its integration. HL7 FHIR is the standard for structured exchange between healthcare systems and suits mobile applications well. For exchange with personal health environments, the MedMij framework of agreements applies. Where a source system has no modern API, we build an intermediate layer rather than letting the app look directly into a database. You can read more about our broader approach on our healthcare software development page.
For practices using FysioManager alongside their own app, there is our page on a FysioManager integration.
If you fit insoles and want to keep the scan, prescription and evaluation together, take a look at our app for insole fitting records.
Why choose Appfront for your care app?
We build custom software with smart technology and thoughtful design, and we start with the process rather than with a screen design. In healthcare, that means first establishing which data comes from where and who may see it, and only then thinking about how it should look.
We work in design and development sprints, so you see working versions along the way. Care professionals who look on early help us remove the steps that don't work in practice. In healthcare this matters even more, because an app that costs time instead of saving it will be left lying next to the bed within two weeks.
The process runs from a no-obligation introductory conversation through planning and development to maintenance. Work continues after go-live too: the Wegiz introduces mandatory exchange step by step for each care process, which requires ongoing upkeep of integrations.
Looking around more broadly? Take a look at our app development services, what we offer in custom software, our overview of healthcare software agencies, or our sovereign cloud for healthcare.
- Custom apps for iOS, Android and web that suit your care process
- Built to NEN 7510 and the GDPR, so you can demonstrate compliance
- Logging set up in line with NEN 7513
- Experience with integrations on EHR systems
- HL7 FHIR as the foundation for structured data exchange
- Offline working where coverage is unreliable
- Care professionals involved during the sprints, not just at handover
- Clear documentation of data flows for your record of processing activities
- Ongoing maintenance as the Wegiz makes new exchanges mandatory
Security and privacy for a care app
A care app processes health data, which is special category personal data under the GDPR. On top of that, NEN 7510 applies as the management standard for information security in healthcare. Certification is not mandatory, but as a care provider you must be able to demonstrate that you meet the standard. We configure the app so that this evidence comes from the system itself rather than from a separate declaration.
In practice, that means authorisation based on role and treatment relationship, so an employee doesn't see every record by default, logging of access and changes in line with NEN 7513, and data minimisation within the integration. It also involves an explicit decision about what may be stored encrypted on the device, with remote wipe should a device be lost.
Our broader approach is set out in our information security policy and vulnerability disclosure policy. Would you like to present your situation to us? Get in touch with us.
- Processing of special category personal data in line with the GDPR
- Built to NEN 7510 as the management standard
- Basis of trust for exchange under NEN 7512
- Logging of actions on the record under NEN 7513
- Authorisation based on role and treatment relationship
- Encrypted offline storage and remote wipe
- Encryption in transit (TLS 1.2 or higher) and at rest
- Data minimisation in every integration
- Documented data flows for your record of processing activities
Frequently asked questions about building a care app
The questions care organisations ask us most often before they commission an app.
A care app is a mobile application with which care professionals record information and clients view their care data, connected to the source system where the record is held. The record stays in the EHR; the app retrieves what is needed and writes the entry back. An app that keeps a second record of its own recreates exactly the duplicate admin you wanted to avoid.
The Act on Supplementary Provisions for the Processing of Personal Data in Healthcare (Wabvpz) refers, via the Decree on Electronic Data Processing by Care Providers, to NEN 7510. As a care provider you must be able to demonstrate compliance with that standard. Certification is not mandatory, but demonstrating compliance is. We configure authorisation, logging and data minimisation so that you can extract that evidence from the system.
NEN 7510 is the management standard for information security in healthcare and describes how you organise security. NEN 7512 covers the foundation of trust for electronic communication in healthcare. NEN 7513 describes logging of actions on electronic records, so you can verify who accessed or changed which record.
Preferably via HL7 FHIR, the international standard for structured data exchange that works well for mobile applications. If your source system doesn't have a modern API, we build an intermediate layer to handle the exchange. We never let an app read directly from another system's database, as that makes every upgrade of that system a risk.
It can, and in home care it is usually a firm requirement. The app keeps an encrypted local work list and synchronises as soon as there is a connection. What matters is what happens when conflicts arise: we surface these explicitly to the care professional rather than quietly letting one version win.
MedMij is the Dutch framework of agreements for data exchange between care providers and personal health environments. If you want clients to be able to retrieve their data into their own PGO, connecting to that framework is the route. It does bring requirements that only pay off if your clients actually use it, so we weigh that up together beforehand.
Yes. We regularly take over an existing application or build a mobile layer on top of a system that is already in place, even when another party built it. We start with a review of the architecture, integrations, authorisation model and logging, and document what we find before changing anything.
The Electronic Data Exchange in Healthcare Act (Wegiz) introduces mandatory electronic exchange step by step, per care process. This means new requirements will arrive periodically for flows you currently handle differently. So build on standards such as HL7 FHIR, so that a new obligation becomes an extension rather than a rebuild.
Ready to build your care app?
Tell us where your care process gets stuck: registration that only happens at the end of the shift, a client portal nobody uses, or a source system that cannot be opened up on mobile. We are happy to think along with you about integrations, authorisation and what NEN 7510 and the GDPR require in your situation.
Is this topic also relevant within your own organisation? You can read more about software for healthcare on applatenmaken.com.