Health systems & hospitals
Enterprise portals unifying records, results, and messaging across service lines.
We build patient portals on the FHIR Patient Access API and SMART on FHIR — so patients securely reach their records, results, and care team, and you meet 21st Century Cures information-sharing rules.
Trusted by global innovators
























A patient portal is where patients see themselves in your system — their results, medications, visit summaries, bills, and messages. Under the 21st Century Cures Act, patients have the right to access that data through standards-based APIs, which means a modern portal is built on the FHIR Patient Access API rather than a proprietary data feed. Get that foundation right and the portal is both compliant and genuinely useful.
Most legacy portals fail patients: clunky logins, stale data, no mobile experience, and no way for third-party apps to connect. We build portals on SMART on FHIR authorization and FHIR R4 resources, so data is live from the record, patients can authorize the apps they choose, and the experience is fast on any device — meeting the rules and earning actual usage.
What it is
Patient portal development builds the secure web and mobile experience where patients access records, results, messaging, scheduling, and bills. Under the 21st Century Cures Act, that access must be standards-based, which makes the FHIR Patient Access API and SMART on FHIR the modern foundation.
We build portals on those standards so data is live, patients control which apps connect, and the experience is fast and accessible — meeting the rules and earning real engagement.
A portal architecture built on the FHIR Patient Access API and SMART on FHIR authorization — live data from the record, patient-controlled access.

A compliant, standards-based portal that patients actually use — data live from the record, access in the patient's control.
The portal reads from the FHIR Patient Access API using FHIR R4 resources (Patient, Observation, DocumentReference, MedicationRequest, DiagnosticReport), so patients see live data and you satisfy the Cures Act patient-access requirement.
OAuth2-based SMART on FHIR launch and scopes let patients securely authorize the portal and any third-party health apps they choose, with granular, revocable consent — no shared credentials.
Lab results with LOINC-coded reference ranges, visit summaries, problem and medication lists, immunizations, and C-CDA document download — presented in plain language patients can understand.
HIPAA-compliant patient-provider messaging with optional AI-assisted plain-language explanations of results and instructions, always with clinician oversight of clinical content.
Online appointment booking, intake and consent forms, and bill pay — integrated with your practice-management and EHR systems so actions flow both ways.
Identity proofing, proxy/caregiver access, granular consent, and immutable audit logging of every record view — engineered to HIPAA and Cures Act information-blocking rules.
Where it fits
Providers who need Cures Act compliance and a portal patients will actually use.
Enterprise portals unifying records, results, and messaging across service lines.
Branded portals tailored to specialty workflows and multiple locations.
Products embedding patient access via SMART on FHIR into their own experience.
Groups moving off clunky, low-adoption portals onto modern FHIR-based ones.
Portals that drive engagement in care plans and preventive outreach.
Member portals surfacing claims, benefits, and care resources.
Compliance is table stakes; adoption is the goal. We build portals that satisfy the Cures Act and that patients return to.
Health Insurance Portability and Accountability Act
Protect PHI with privacy-first architecture, encrypted storage and transmission, strict access controls, and traceable audit logs.
General Data Protection Regulation
Implement lawful consent flows, data minimization, retention controls, and secure processing for sensitive health data.
Fast Healthcare Interoperability Resources
Enable standardized health data exchange across apps, care teams, and systems through robust FHIR-ready APIs.
Health Level Seven International
Support enterprise-grade interoperability with HL7-based integrations for records, events, and clinical messaging workflows.
Health Information Trust Alliance
Align security programs to healthcare-specific control and risk management practices trusted by providers and ecosystem partners.
Health Information Technology for Economic and Clinical Health Act
Design with breach notification readiness, digital record safeguards, and operational controls that support regulated care programs.
FDA Software as a Medical Device
Plan software quality, traceability, and documentation pathways for products that may require SaMD review and submission.
Medical Device Regulation (European Union)
Prepare EU market-ready processes for risk classification, evidence tracking, and lifecycle governance under MDR expectations.
Substance Abuse and Mental Health Services Administration
Apply confidentiality controls and consent-aware sharing models for behavioral and mental health data experiences.
Standards and compliance
We build the compliant data foundation first, then the experience — so the portal is both standards-correct and genuinely usable.
We map the data patients need, your source systems, and the SMART on FHIR authorization model, then design the portal's information architecture.
We connect the FHIR Patient Access API and map resources to portal views, with SMART on FHIR OAuth2 scopes and consent handling.
We build the responsive patient experience — results, messaging, scheduling, and bill pay — integrated with EHR and practice-management systems.
Phased go-live with identity proofing, accessibility checks, and analytics to drive real patient adoption and support.
Related proof of compliant patient-facing delivery: for Lera Health we built a privacy-first patient experience and data layer end to end. It shows the consent, PHI handling, and UX craft a patient portal demands, though it is a distinct product.

We build portals that meet the Cures Act and that patients actually open — standards-correct and human-friendly.
FHIR Patient Access API and SMART on FHIR built in, so Cures Act access rules are met without workarounds.
Plain-language results and accessible, mobile-first design so patients engage instead of abandoning the login.
Scheduling, messaging, and bill pay wired into your EHR and PM systems so actions actually take effect.
We know FHIR, consent, and information-blocking rules cold, so compliance is handled without slowing delivery.
Compliant patient access patients actually use
Tell us your source systems and the experience you want. We'll return a plan built on the FHIR Patient Access API and SMART on FHIR, compliant with the Cures Act.
contact@agnotic.com
Partnerships
contact@agnotic.com