Agnotic Technologies Logo
    Patient Portal Development

    Patient Portal

    We build patient portals on the FHIR Patient Access API and SMART on FHIR — so patients securely reach their records, results, and care team, and you meet 21st Century Cures information-sharing rules.

    HIPAA-ReadyFHIR R4SMART on FHIRCures Act

    Trusted by global innovators

    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve
    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve
    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve
    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve

    What a modern patient portal has to do

    A patient portal is where patients see themselves in your system — their results, medications, visit summaries, bills, and messages. Under the 21st Century Cures Act, patients have the right to access that data through standards-based APIs, which means a modern portal is built on the FHIR Patient Access API rather than a proprietary data feed. Get that foundation right and the portal is both compliant and genuinely useful.

    Most legacy portals fail patients: clunky logins, stale data, no mobile experience, and no way for third-party apps to connect. We build portals on SMART on FHIR authorization and FHIR R4 resources, so data is live from the record, patients can authorize the apps they choose, and the experience is fast on any device — meeting the rules and earning actual usage.

    What it is

    Where patients meet their own health data

    Patient portal development builds the secure web and mobile experience where patients access records, results, messaging, scheduling, and bills. Under the 21st Century Cures Act, that access must be standards-based, which makes the FHIR Patient Access API and SMART on FHIR the modern foundation.

    We build portals on those standards so data is live, patients control which apps connect, and the experience is fast and accessible — meeting the rules and earning real engagement.

    Architecture

    A portal architecture built on the FHIR Patient Access API and SMART on FHIR authorization — live data from the record, patient-controlled access.

    Patient portal architecture built on FHIR Patient Access API and SMART on FHIR

    What We Build Into Your Patient Portal

    A compliant, standards-based portal that patients actually use — data live from the record, access in the patient's control.

    15-Minute Scoping Call

    FHIR Patient Access API

    The portal reads from the FHIR Patient Access API using FHIR R4 resources (Patient, Observation, DocumentReference, MedicationRequest, DiagnosticReport), so patients see live data and you satisfy the Cures Act patient-access requirement.

    SMART on FHIR Authorization

    OAuth2-based SMART on FHIR launch and scopes let patients securely authorize the portal and any third-party health apps they choose, with granular, revocable consent — no shared credentials.

    Results, Records & Summaries

    Lab results with LOINC-coded reference ranges, visit summaries, problem and medication lists, immunizations, and C-CDA document download — presented in plain language patients can understand.

    Secure Messaging & Assistance

    HIPAA-compliant patient-provider messaging with optional AI-assisted plain-language explanations of results and instructions, always with clinician oversight of clinical content.

    Scheduling, Bills & Forms

    Online appointment booking, intake and consent forms, and bill pay — integrated with your practice-management and EHR systems so actions flow both ways.

    Identity, Consent & Audit

    Identity proofing, proxy/caregiver access, granular consent, and immutable audit logging of every record view — engineered to HIPAA and Cures Act information-blocking rules.

    Where it fits

    Who needs a custom patient portal

    Providers who need Cures Act compliance and a portal patients will actually use.

    Health systems & hospitals

    Enterprise portals unifying records, results, and messaging across service lines.

    Specialty & multi-site groups

    Branded portals tailored to specialty workflows and multiple locations.

    Digital health platforms

    Products embedding patient access via SMART on FHIR into their own experience.

    Practices replacing legacy portals

    Groups moving off clunky, low-adoption portals onto modern FHIR-based ones.

    Value-based care organizations

    Portals that drive engagement in care plans and preventive outreach.

    Payers & TPAs

    Member portals surfacing claims, benefits, and care resources.

    A portal that meets the rules and earns usage

    Compliance is table stakes; adoption is the goal. We build portals that satisfy the Cures Act and that patients return to.

    FHIR
    Patient Access API, live from the record
    SMART
    OAuth2 patient-controlled app authorization
    2–4 mo
    Typical patient portal MVP timeline

    Compliance-First Healthcare App Development Services Backed by Global Standards

    15-Minute Scoping Call
    01HIPAA logo

    HIPAA

    Health Insurance Portability and Accountability Act

    Protect PHI with privacy-first architecture, encrypted storage and transmission, strict access controls, and traceable audit logs.

    02GDPR logo

    GDPR

    General Data Protection Regulation

    Implement lawful consent flows, data minimization, retention controls, and secure processing for sensitive health data.

    03FHIR logo

    FHIR

    Fast Healthcare Interoperability Resources

    Enable standardized health data exchange across apps, care teams, and systems through robust FHIR-ready APIs.

    04HL7 logo

    HL7

    Health Level Seven International

    Support enterprise-grade interoperability with HL7-based integrations for records, events, and clinical messaging workflows.

    05HITRUST logo

    HITRUST

    Health Information Trust Alliance

    Align security programs to healthcare-specific control and risk management practices trusted by providers and ecosystem partners.

    06HITECH logo

    HITECH

    Health Information Technology for Economic and Clinical Health Act

    Design with breach notification readiness, digital record safeguards, and operational controls that support regulated care programs.

    07SaMD logo

    SaMD

    FDA Software as a Medical Device

    Plan software quality, traceability, and documentation pathways for products that may require SaMD review and submission.

    08MDR (EU) logo

    MDR (EU)

    Medical Device Regulation (European Union)

    Prepare EU market-ready processes for risk classification, evidence tracking, and lifecycle governance under MDR expectations.

    09SAMHSA logo

    SAMHSA

    Substance Abuse and Mental Health Services Administration

    Apply confidentiality controls and consent-aware sharing models for behavioral and mental health data experiences.

    Standards and compliance

    Standards baked into the portal

    FHIRSMARTUSCDILOINCCuresHIPAA
    Our Process

    How we ship a patient portal

    We build the compliant data foundation first, then the experience — so the portal is both standards-correct and genuinely usable.

    1.

    Discovery & Access Design

    We map the data patients need, your source systems, and the SMART on FHIR authorization model, then design the portal's information architecture.

    Cures-Act aligned
    2.

    FHIR Data Layer

    We connect the FHIR Patient Access API and map resources to portal views, with SMART on FHIR OAuth2 scopes and consent handling.

    Live from the record
    3.

    Experience & Integrations

    We build the responsive patient experience — results, messaging, scheduling, and bill pay — integrated with EHR and practice-management systems.

    Patient-first UX
    4.

    Launch & Adoption

    Phased go-live with identity proofing, accessibility checks, and analytics to drive real patient adoption and support.

    Built for adoption

    Featured case study

    Read Case Study

    Lera Health: compliant women's health platform

    Related proof of compliant patient-facing delivery: for Lera Health we built a privacy-first patient experience and data layer end to end. It shows the consent, PHI handling, and UX craft a patient portal demands, though it is a distinct product.

    Lera Health app across desktop and mobile
    Why Partner With Us

    Why teams build portals with Agnotic

    We build portals that meet the Cures Act and that patients actually open — standards-correct and human-friendly.

    15-Minute Scoping Call

    Standards-Correct by Default

    FHIR Patient Access API and SMART on FHIR built in, so Cures Act access rules are met without workarounds.

    Patient-Centered UX

    Plain-language results and accessible, mobile-first design so patients engage instead of abandoning the login.

    Integrated, Not Bolted-On

    Scheduling, messaging, and bill pay wired into your EHR and PM systems so actions actually take effect.

    Healthcare Domain Depth

    We know FHIR, consent, and information-blocking rules cold, so compliance is handled without slowing delivery.

    Our relevant experience

    Compliant patient access patients actually use

    Frequently Asked Questions

    Cost depends on how many features and integrations you need — a read-only records-and-results portal is far cheaper than one with messaging, scheduling, and bill pay wired into your EHR and PM systems. We scope in phases and give a fixed estimate, so you can launch core patient access first and expand.

    Ready for a portal patients actually use?

    Tell us your source systems and the experience you want. We'll return a plan built on the FHIR Patient Access API and SMART on FHIR, compliant with the Cures Act.

    Email

    contact@agnotic.com

    Partnerships

    contact@agnotic.com