Which workflows does a first project usually touch?
Clinics, home-care agencies, care homes and digital health start-ups share five administrative workflows, and a first project should own one of them end to end.
- Scheduling and reminders. Appointment or visit slots, clinician or carer availability, cancellations and the reminder that reduces missed visits. In home care the schedule is also a route, so travel time and carer skills belong in the rules.
- Referral and intake. A referral letter, a self-referral form or a call arrives; someone checks eligibility, collects history and decides who sees the person first.
- Visit and encounter records. What was done, by whom, when and with what outcome. For a care agency this is the electronic visit record the family and the commissioner may later ask to see.
- Consent and data-sharing preferences. Who agreed to what, for which purpose, and when the agreement must be checked again.
- Billing, claims or commissioning returns. An insurer claim, a public commissioner's return or a private invoice, each built from the records above.
Documents that move between these steps, such as referral letters, care plans and discharge summaries, follow the approval patterns on document and approval workflows.
Who are the actors, and what do they need?
want to book, rearrange and understand what happens next without a phone queue.
want the record to take less time than the visit, on a phone, often with poor connectivity.
carry the hardest rules: skills, continuity of carer, travel, legal limits on working hours.
ask for visibility, and the system has to know when they are entitled to it.
want evidence that visits happened and records were kept.
decides what may be collected, where it may be stored and who may see it.
The pressure most operators describe in 2026 is the same: administration grows faster than care hours, and every workaround, such as a shared spreadsheet or a personal messaging group, becomes an undocumented copy of health data.
Which regulatory questions should you put to your own advisers?
Software suppliers do not answer these; your privacy counsel, clinical safety lead or regulatory adviser does. Put them in writing before a vendor designs anything.
Decides whether the vendor may touch real protected health information and what safeguards the contract requires
45 CFR Part 164, Subpart C security standards (eCFR, accessed 2026-09-28)
Sets the lawful basis, the impact assessment and where data may be hosted
Regulation (EU) 2016/679, Article 9 (EUR-Lex, accessed 2026-09-28)
Organisations with that access must complete the Data Security and Protection Toolkit; version 9 for 2026-27 was released on 8 September 2026
NHS England DSPT site (accessed 2026-09-28)
Software intended for a medical purpose can be regulated as a medical device, which changes validation and release
FDA, Software as a Medical Device (accessed 2026-09-28)
An electronic health record that offers an HL7 FHIR interface is an integration; one that does not is a migration or a manual step
HL7 FHIR specification (accessed 2026-09-28)
Where does AI help, and where must it stop?
AI earns its place in the administrative layer: answering booking and opening-hours questions, drafting an intake summary for a human to confirm, routing a message to the right team, and searching policy documents. It should not diagnose, triage or advise on treatment unless your regulatory adviser has classified that feature and a clinical safety process covers it.
The nearest Netbase record is not a healthcare project. For a client who is not named, Netbase built a WhatsApp Business AI chatbot with intent and conversation-flow handling, an LLM API (GPT-4 in the stack) and CRM synchronisation for lead capture, customer data and workflow automation, delivered in milestones from design and prototype to documentation, knowledge transfer and 30 days of support over four to eight weeks. The WhatsApp chatbot record shows the build shape of a booking assistant; the healthcare version adds a consent notice, a no-clinical-advice boundary and a human hand-over that record does not claim. Netbase has also delivered anonymised client AI projects including retrieval-based knowledge assistants, document AI and MLOps pipelines, and works with commercial and open-source AI models chosen per project, with no vendor partnership implied. The AI workflow blueprint is the route for deciding which of these belongs in your workflow.
What does a worked first project look like?
A hypothetical home-care agency runs visits from a spreadsheet and a group chat. Carers message changes, a coordinator re-keys them, and the monthly commissioner return takes several days to reconcile.
- Milestone one replaces the spreadsheet with a visit schedule that knows carer skills, service-user preferences and travel time, and sends visit changes to the carer's phone.
- Milestone two adds an electronic visit record: arrival, tasks completed, notes, departure, captured offline and synchronised later.
- Milestone three produces the commissioner return from those records, and adds a read-only family view governed by recorded consent.
Real service-user data enters only after the privacy lead signs off hosting, access and the processing agreement; until then the team builds and tests on synthetic records.
Where does outsourcing fit, and where does it not?
Good fit
- Administrative workflows: scheduling, intake, visit records, consent, returns
- A portal or app beside an existing health record that exposes an interface
- Replacing spreadsheets and chat groups that hold health data
- Firms like professional services practices with a health-adjacent service line
Another route fits better
- An approved clinical system you must buy, where configuration rather than a build is the job
- A medical device feature without a regulatory adviser engaged
- Advice on your own legal compliance, which belongs to counsel
- Front-line support volume only, where customer support automation is the narrower route
Custom product engineering for a bounded release outcome
One defined release of your product, built to named outcomes and handed over with acceptance evidence.
Learn More
What must be settled about data before the build?
- Minimum necessary. Collect the fields the workflow needs and no more; free-text notes are where unexpected health detail accumulates.
- Environments. Development and test use synthetic data. Production access is named, logged and time-limited.
- Audit trail. Every read and change to a record is attributable to a person, because inspectors and complainants will ask.
- Hosting region and processors. Decided with the privacy lead, written into the processing agreement, and checked for every AI provider as well.
- Offline capture. Carers work in homes with poor signal, so conflict handling on synchronisation is a requirement, not polish.
Netbase security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request. Its compliance practices are GDPR alignment for data privacy in Europe, HIPAA-aligned methodologies for healthcare data handling, and CCPA compliance for clients with U.S. customer bases. These are practices, not certificates, and they never stand in for your organisation's own compliance. The data security and compliance guide lists the access questions in full.
What delivery record exists, and what does not?
Netbase has delivered projects for healthcare clients who are not named. No healthcare project is described in the claim register, so this page publishes no healthcare client, figure, platform description or result, and it builds no capability argument on that statement. The WhatsApp chatbot above names no sector and is adjacent evidence only. The domain review for this page was carried out by David Nguyen (CEO) acting as domain owner; it is not a clinical safety or legal review, and the regulatory table above is a list of questions for your advisers, not advice. Evidence labelling is explained on the methodology page.
Which delivery risks are specific to this sector?
-
Consent recorded once, never re-checked
Preferences change; the system must know when a family member's access lapses.
-
Real data in test environments
A copied production database is a frequent cause of privacy incidents during a build.
-
Integration assumed, not confirmed
Teams plan around a record system's interface and discover the licence or access was never granted.
-
Scope drifting into clinical judgement
A helpful scoring feature can turn an administrative tool into a regulated product.
-
Rostering rules left in one coordinator's head
Continuity, skills and working-time limits must be written down in discovery.
Netbase's delivery lifecycle runs from discovery and strategic alignment through team assembly and architecture planning, agile execution with outcome-based milestones, modular components, training and rollout to ongoing support; in this sector discovery closes when the privacy lead has signed off the data rules.
Common questions
No healthcare case study is published. Netbase has delivered projects for healthcare clients who are not named, and those clients are not described on this site.
No. Netbase follows HIPAA-aligned methodologies for healthcare data handling, which is a practice statement, and your own compliance remains your organisation's responsibility.
Yes, for most of the build. Synthetic records cover design and testing, and production access, where needed, is named, logged and approved by your privacy lead.
Only if the record system exposes an interface you are licensed to use, such as HL7 FHIR. Confirm access in discovery before the plan depends on it.
Netbase JSC's head office is in Hanoi, Vietnam, and it is the company's only office.
Start with one workflow and your data rules
Bring one workflow, the list of people who touch it, and your adviser's answers to the regulatory questions above. Related sectors include real estate and construction and financial services and fintech, and all sectors are listed under industries. The build route is custom product engineering. OutsourcingVN is operated by Netbase JSC and is Netbase's own outsourcing-services platform; submit a project when the brief is ready.