AI for healthcare: an eight-week care-planning MVP and a security review you can pass.
In healthcare the build is the easy half. The security posture, the data boundary and the question of what a model is allowed to touch decide whether it ships.
Bastion Health needed a care-planning MVP in front of clinicians before a funding milestone. Eight weeks later it was live: an intake pipeline that assembles a patient's history, a planning surface a clinician edits, and a boundary written into the product about what the model may and may not do.
MedArc arrived from the other direction. A security rebuild over twelve weeks that closed with zero critical findings, because the review happened against a system designed for it rather than a system that had to be argued into shape afterwards.
Those two engagements describe the whole practice. Move quickly on the product, slowly and explicitly on the data boundary, and never let a model take a clinical action without a named person accountable for it.
Healthcare at a glance
- Usual first project
- An MVP with a defined clinical boundary, or a security rebuild
- Time to production
- 8 to 12 weeks
- Where it runs
- Your cloud tenancy, zero-retention model endpoints
- Price band
- $50K to $150K for a production build
- Cases on this page
- Bastion Health · MedArc · Nordwind Insurance
Healthcare is a security project with a product attached
Every digital health build eventually meets a questionnaire: where does protected health information live, who can read it, what is logged, how is access revoked, what happens on deletion, and is any of it used to train a model. Teams that leave those questions to the end rebuild.
The default pattern we use is your cloud account, your tenancy, encryption in transit and at rest, scoped service access, zero-retention model endpoints, and logs that record decisions and evidence rather than clinical payloads. We work under your BAA and DPA; we are not a covered entity and do not present ourselves as one.
MedArc's engagement is the version of this done as remediation. Zero critical findings at re-test is achievable, but it is much cheaper to design toward than to retrofit.
What an eight-week MVP actually contains
Bastion's MVP was deliberately narrow: one intake pathway, one clinician-facing planning surface, one integration, and a written list of everything the model was not allowed to do. That narrowness is why it launched in eight weeks rather than becoming a platform nobody could review.
The parts that always take longer than teams expect are consent handling, audit logging and the clinician correction path. The parts that go faster than expected are extraction and summarisation, which are genuinely mature.
An MVP is not a pilot that runs forever. It is the smallest system that can be used by real clinicians on real data with the boundary enforced in code, which is what makes the next funding conversation concrete.
Where a model belongs in a clinical workflow, and where it does not
Drafting, summarising, extracting, coding support, intake triage and documentation relief: these are places where a model reduces a documented burden and a clinician reviews the output. Diagnosis, treatment selection and anything that would meet the definition of a clinical decision without a clinician are not places we build.
In practice the rule is that the system may prepare and propose, and a licensed person disposes. Every proposal shows its evidence, the same way Nordwind's claims agent cites the clause and page it relied on, so review is a glance rather than an investigation.
If a product needs to make an autonomous clinical determination, it needs a regulatory pathway, and that is a different project with a different timeline. We say so at the scoping call rather than at week ten.
Documentation burden is where the payback is fastest
The clearest wins in healthcare operations are rarely clinical. Prior-authorisation packets, referral letters, intake summaries, discharge instructions and coding support all consume clinician hours and follow written rules.
The same workbench pattern applies: assemble the context on one screen, draft with citations, let the person correct in a click, and log what happened. Nordwind's claims workbench moved forty minutes of assembly per case into a pre-read screen, and a referral packet has the same anatomy as a claim file.
Evaluation, and what you show a clinical safety officer
A graded evaluation set with known-correct outcomes, run on every change, plus override rates by pathway. That is the evidence pack that makes a safety review productive, and it is a deliverable rather than an afterthought.
It is also what makes the system maintainable. Without it, a prompt change that fixes one complaint and quietly breaks four others is invisible until someone reports it, and in this sector that is not an acceptable way to find out.
Budget, timeline and the fit test
A production healthcare build runs $50,000 to $150,000 over eight to twelve weeks. A narrower documentation-relief workflow starts at $4,000 as a pilot. A security review and remediation is scoped separately after a first look at the architecture.
The fit test is whether the clinical boundary can be written in a paragraph. If your team can say what the system proposes, who approves it and what it never does, this is buildable. If that paragraph does not exist yet, the audit week is where it gets written, and you keep it regardless of what you decide next.
What changed, measured
Bastion Health, an eight-week engagement in 2026, and MedArc, a twelve-week security rebuild in 2022.
Healthcare work that shipped
Where to go next
Onboarding paperwork
Credentialling packets parsed, verified and filed on the day they arrive.
Contract review
Payer and vendor agreements checked against your playbook with sources shown.
Questions we get from healthcare teams
Compliance belongs to the covered entity, not to a development partner, so the honest answer is that we build to your requirements and sign your BAA. In practice that means PHI stays in your cloud tenancy, model calls use zero-retention endpoints, access is scoped and every read is logged.
No. Systems we build prepare and propose; a licensed clinician decides. The boundary is written down during the audit week and enforced in code, and anything that would require a regulatory pathway is flagged at the scoping call rather than discovered late.
Usually, through the interface your vendor supports, which is most often FHIR or HL7 for the read side and a defined write path for the rest. Where an EHR only allows exports, we build against that instead, and the audit week establishes which of the two you have.
Bastion Health had a live MVP in eight weeks. That timeline holds when scope is one pathway and one integration. It does not hold if the first release has to cover several specialties, and we will say so before you plan around it.
Both. The review starts in the audit week, and MedArc's engagement was a rebuild done specifically to reach zero critical findings at re-test. If you already have a penetration test report, bring it to the scoping call and we will scope against the actual findings.
The scoping call is free and thirty minutes. The audit week is a paid engagement that produces a written plan, a data-boundary paragraph and a fixed estimate, and you keep all three whether or not you build with us.
Have a healthcare problem shaped like this?
Thirty minutes on a call answers fit and gives you a rough estimate. The audit week that follows produces a written plan and a fixed price, and you keep the plan either way.

