Custom VECOZO integration development
Appfront builds custom VECOZO integrations that automate declaration and insurer traffic in your healthcare organisation, directly from your own EHR or billing software. Through VECOZO's secure web services, you submit claims based on Vektis's EI standards, process return messages, check insurance eligibility with COV and request authorisations. Authentication runs on the VECOZO certificate, in line with GDPR and NEN 7510.
What is a VECOZO integration?
VECOZO (Secure Communication in Care) is the central, secure communication hub for Dutch healthcare. It enables secure data exchange between care providers and health insurers: submitting claims based on Vektis EI standards, checking insurance entitlement with COV, and requesting authorisations. Access is solely via the VECOZO certificate as the digital access means.
In practice, a custom integration means: building claims programmatically from your EHR, ECD or billing software and submitting them to VECOZO, reading return messages in automatically and matching them to the right treatment, checking a patient's insurance eligibility in advance with the COV service, and requesting authorisations, all through secure web services with certificate-based authentication.
Appfront builds on the official VECOZO technical information and Vektis's EI standards, in line with NEN 7510 and GDPR. We align message handling, error management for return information and certificate management with your actual claims and verification processes, so the integration stays reliable even at high claim volumes.
Claims traffic with health insurers
Submit claims based on Vektis's EI standards and process return messages automatically, with no manual uploads or loose files. Approved, rejected and corrected lines are fed back to the correct treatment.
Checking insurance eligibility in advance
With the COV service, you check at the start of treatment whether and how a patient is insured. This prevents rejected claims after the fact and gives your administration certainty in advance about coverage and insurer.
Certificate authentication
All communication with VECOZO runs over encrypted connections, using the VECOZO certificate (PKI) as the means of access. We set up certificate management and timely renewal so your traffic never stops unexpectedly.
For youth care, message traffic runs via the Schakelpunt or the Gemeentelijk Gegevensknooppunt, with dedicated messages for allocation and claiming. For how field registration ties into this, see the app for start, stop and hours in youth care.
Our development process for VECOZO integrations
We work to a proven method that removes uncertainty early and delivers a stable integration. From an initial analysis of your claims and control processes, the VECOZO certificate and the connection to your EHR or claims software, through to go-live and ongoing management, every step is aimed at an integration that your care organisation can understand and trust itself.
We map out which services you need, such as claiming, COV checks and authorisations, which Vektis EI standards apply, how the VECOZO certificate is set up, and which system (EHR, ECD or billing software) we connect to.
We design the integration architecture, choose the right certificate authentication and define an error-handling strategy for return messages.
Implementation with automated tests, structured logging and monitoring. You see working builds along the way.
Controlled go-live with data validation and safeguards, followed by ongoing management, certificate renewal and further development.
What a VECOZO integration delivers in practice
Every VECOZO integration is set up specifically for your claims and verification processes and the systems around them. Below are the features we most often deliver for healthcare organisations and suppliers who use VECOZO as part of their administration.
Submitting claims (Vektis EI standards)
Claims are assembled using the correct Vektis EI message standard and submitted to VECOZO. The integration validates the message structure in advance, so formal errors are caught before a claim reaches the health insurer.
Processing return messages
Return information from the health insurer is read in automatically and linked to the original claim line. Approved, rejected or corrected: the status comes straight back into your EHR or claims software, with clear handling of rejection reasons.
Insurance eligibility checks (COV)
Using the COV service, you check at the start of treatment and when claiming whether a patient is insured and with which health insurer. This prevents rejected claims and keeps your debtor risk low — automated from your own system.
Requesting authorisations
Authorisation requests for care that requires prior approval from the insurer go directly through VECOZO. The integration monitors the status of requests and links the response back to the correct treatment pathway in your record.
Certificate and PKI authentication
The VECOZO certificate (PKI) is the means of access to all services. We set up certificate storage in secure vaults, automate renewal where possible and monitor validity, so that claims and verification traffic does not come to a standstill because of an expired certificate.
Integration with EHR, ECD and claims software
VECOZO connects to your existing EHR, ECD or claims and billing software. Treatments, performance codes and patient data flow from your system into the claim, and the return status flows back, without duplicate entry or manual exports.
Typical use cases in practice
A VECOZO integration differs from one organisation to the next. We often see a number of recurring patterns, and for each of them we have a working setup that addresses the EI standards, COV checks, authorisations and certificate management.
Allied health, mental health & social care
Practices and organisations in allied healthcare, mental health and long-term care that claim digitally and verify insurance eligibility in advance. Claims via the EI standards, COV checks at the start of treatment and automatic processing of return messages — directly from the treatment record. See also our API integrations.
Hospitals & pharmacies
Hospitals, clinics and pharmacies with high claim volumes and complex insurer communication. Automated submission via the EI standards, bulk COV checks and structured processing of return information keep the claims flow reliable and debtor risk under control.
Healthtech, EHR and ECD vendors
Software vendors who want to offer VECOZO functionality within their EHR, ECD or care platform. We build a reusable, well-documented integration layer for claims, COV and authorisations, with certificate authentication, so your customers can communicate with health insurers directly through your product.
Claims & invoicing software
Builders of claims and billing software for healthcare who need a reliable VECOZO connection. Validation of EI messages, robust processing of return information and rejection reasons, and automated certificate management give you a claims flow your users can depend on.
Technology we use
We build VECOZO integrations using VECOZO's secure web services and the Vektis EI message standards, combined with the backend stack that suits you. The exact choice depends on your EHR, ECD or claims software and the services you subscribe to, so your own team can manage or further develop the integration.
If you receive referrals via ZorgDomein and want them directly in your own system, see our page on a ZorgDomein integration.
If you claim mental healthcare under the GDS801 standard, see our page on an integration for the care performance model.
Why Appfront for your VECOZO integration?
Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands, including in privacy-sensitive sectors such as healthcare. We always begin with a thorough analysis of your existing systems and processes. An integration should not only work technically but also add practical value to your claims and checking work.
With every integration we write clear documentation and make sure your own team, or a future supplier, can understand and manage it. No black box, but transparent code and clear agreements on monitoring, alerting, certificate management and maintenance.
You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.
See also our wider services around API integrations, middleware, custom software and web app development. Do you also work with inter-organisational care communication or a care record? Then see our ZorgMail integration and Nedap ECD integration.
- Experience with VECOZO web services, EI standards and COV
- Specialists in integrations with EHR, ECD and claims software
- Familiar with claims, authorisation and return message flows
- Secure by default: certificate management, scoped permissions, data minimisation
- Working method aligned with NEN 7510 and the GDPR
- Structured error handling and retry mechanisms
- Comprehensive logging and monitoring from day one
- Clear documentation your team can read and manage
- A fixed point of contact, no account managers passed around
- Ongoing management, certificate renewal and further development
Security and privacy in VECOZO integrations
Declaration and insurer traffic contains medical and financial personal data, which counts as special category personal data under the GDPR. Appfront builds VECOZO integrations in line with NEN 7510 (information security in healthcare) and the OWASP ASVS. That means, among other things: the VECOZO certificate (PKI) and secrets held in secure vaults, scoped permissions per service, data minimisation, and regular audits of the declaration, COV and authorisation flows.
All communication with VECOZO runs over encrypted connections with certificate authentication. We document the data flows, message standards and certificate configuration so that your record of processing activities is complete and you can demonstrate compliance with the GDPR. Audit trails at message level serve as evidence for every declaration and check sent.
More on our security approach: information security policy and CVD policy.
- GDPR-compliant processing of special category personal data
- NEN 7510 as the framework for information security in healthcare
- VECOZO certificate (PKI) and certificate management in secure vaults
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access and least-privilege principles
- Audit logs with traceable data flows
- Automatic retries and dead-letter queues
- Documentation for your record of processing activities
Frequently asked questions about VECOZO integrations
Answers to the questions we are asked most often about VECOZO implementations.
A VECOZO integration is a secure technical link between your own healthcare application and VECOZO, the central hub for secure data exchange between care providers and health insurers. Through VECOZO's web services, you submit claims based on Vektis's EI standards, process return messages, check insurance entitlement with COV and request authorisations. Authentication uses the VECOZO certificate (PKI). An integration can range from simple (submitting claims and processing return messages) to extensive (COV, authorisations and full integration with your EHR or claims software).
VECOZO is the route for declaration and insurer traffic in Dutch healthcare: submitting declarations to health insurers, checking insurance eligibility and requesting authorisations. For communication between care providers, such as referrals, letters and results, you use ZorgMail, and for the clinical record itself an EHR such as Nedap. We help you determine which VECOZO interface suits your declaration and verification processes.
A simple integration, submitting claims via the EI standards and processing return messages, can be up and running relatively quickly once the VECOZO certificate and connection are set up. More extensive scenarios with COV checks, authorisations and deep integration into your EHR or claims software generally take more time. After an intake meeting, we give you a realistic estimate.
We work with VECOZO's secure web services (SOAP over HTTPS), Vektis's EI message standards for declarations and response information, the COV service for insurance eligibility, and the VECOZO certificate (PKI) for authentication. We build the backend in the stack that suits you, whether Node.js, .NET, Java or Python. Everything runs over encrypted connections with certificate-based access.
The cost is determined by the services you need (declarations, COV, authorisations), the number of EI message standards you support, the depth of integration with your EHR or declaration software, and the requirements for handling response message errors. Ongoing management, monitoring and certificate management also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.
Yes. VECOZO is set up as a secure communication hub for healthcare: access is only possible with the VECOZO certificate (PKI) over encrypted connections. Because it involves medical and declaration data, Appfront builds in line with the GDPR and NEN 7510 for information security in healthcare, with data minimisation, certificates held in secure vaults, scoped permissions and audit trails. We document the data flows so that your record of processing activities remains complete and you can demonstrate GDPR compliance.
Yes. Appfront regularly takes over the management of existing VECOZO integrations, including those originally set up by another party. We review the web services connection, EI message processing, the COV and authorisation flows, the certificate configuration and the error handling of return messages, document the current setup and draw up improvement proposals. From then on, we handle changes, extensions and monitoring, including timely certificate renewal.
A VECOZO integration suits healthcare providers that bill digitally and check insurance entitlement, such as allied health professionals, mental health services, long-term care, hospitals and pharmacies. It also suits healthtech, EHR and ECD suppliers, and builders of billing and invoicing software who want to offer VECOZO functionality in their product. Typical uses include submitting claims via the EI standards, processing return messages automatically, running COV checks upfront and requesting authorisations.
Ready to build your VECOZO integration?
Tell us which services you want to handle via VECOZO (claims, COV checks, authorisations) and which EHR, ECD or billing software the integration needs to work with. We are happy to advise on the EI standards, return message processing, certificate management and security under NEN 7510. A no-obligation first conversation will quickly give you a clear picture of what is possible.