HealthTech platforms built by people who have run a Class IIa device in production.
Regulated workflows, secure data boundaries, and identity integrations, scoped and architected before a single line of code.
Where HealthTech builds break down
Teams decide whether the software is a medical device (MDSW) late, then discover the class drives the whole development lifecycle under IEC 62304.
Patient data boundaries and access control defined informally, then discovered as problems during testing.
Identity and authentication integrations underestimated in complexity and timeline.
Risk management treated as a document written at the end, rather than the ISO 14971 file that shapes the design as it is made.
Multi-role workflows (clinicians, administrators, patients) not mapped before engineering starts.
Estimation misses regulatory review cycles and security review timelines.
Class IIa device software, built and run in production
Before ALTARISE existed, our team built, shipped and maintained the software for AioCare, a connected mobile spirometer: the device SDK, the iOS and Android applications, and the platform that held test results and generated reports for clinicians and patients. The work was scoped to MDR Class IIa requirements across both software and hardware, and included preparing documentation for a 510(k) submission to the FDA. The certification programme ended when the funding did, not for engineering reasons, and through that period a very small team kept the platform running so patients and their doctors could keep using the device. What transfers is the part that decides your architecture: what IEC 62304 asks of your development lifecycle, what ISO 14971 asks of your risk file, and how early both of them constrain the data model.
Concrete outputs, not just advice
- Clear scope with compliance requirements mapped from the start
- Data boundary architecture and access control direction
- Identity integration map, with approach and risk assessment
- Audit trail requirements and implementation notes
- Multi-role workflow maps (clinicians, admins, patients)
- Security requirements and compliance checklist for regulated environments
- Prioritized backlog structured around delivery milestones
- Budget ranges and delivery strategy with compliance cycles accounted for
Recommended first step
Start with a LaunchRail Sprint
A focused 10-day planning sprint that answers the hard questions: what to build, what it costs and what the risks are, so you start with a clear plan.
Questions, answered.
Let's talk about your project
Book a short call. We'll listen, ask the right questions, and within 24 hours you'll have a clear recommended next step.