The challenge: video, data, and compliance in one app
You're building a telemedicine app. The video must work in low-bandwidth areas. Medical records need to sync with existing hospital systems via FHIR. And the app must pass Apple's Medical category review while storing health data securely under 152-FZ. Each requirement alone is complex; together they demand a structured approach. We've executed 15+ medical projects over 7 years, solving exactly these problems.
How to choose a media server for telemedicine
The core of a telemedicine app is real-time video. The media server choice determines quality, latency, and regulatory compliance. Three main options exist: self-hosted WebRTC with Mediasoup/Janus, cloud SDKs like Vonage/Agora/Twilio, and HIPAA-ready platforms like Daily.co/100ms.
Self-hosted WebRTC with Mediasoup/Janus as SFU (Selective Forwarding Unit). Use WebRTC.framework (Google WebRTC port) on iOS and libwebrtc.aar on Android. Full control over infrastructure—recordings stay on your servers, critical for 152-FZ and medical confidentiality. Mediasoup reduces transactional costs by 40% compared to Twilio at loads above 1,000 consultations per month, paying off in 6–8 months.
Vonage Video API / Agora / Twilio Video provide ready SDKs with dashboards, cloud recording, and adaptive bitrate. Faster time-to-market, but data passes through provider servers—requires verifying regulatory compliance and signing a BAA for HIPAA.
Daily.co / 100ms are relatively new with good documentation and HIPAA-ready plans.
For most Russian projects requiring on-premises data storage, self-hosted infrastructure with Mediasoup plus a TURN server (coturn) in a Russian data center is best. Mediasoup delivers 3× lower latency than Twilio under peak load—critical for real-time consultations.
| Feature |
Mediasoup (self-hosted) |
Vonage/Twilio |
Daily.co |
| Data control |
Full |
Partial |
Partial |
| Latency |
<100 ms |
200–400 ms |
150–300 ms |
| HIPAA-ready |
Yes (with BAA) |
Yes (with BAA) |
Yes (with BAA) |
| Cost model |
Payoff in 6–8 months |
Per transaction |
Fixed |
Why FHIR matters for telemedicine
HL7 FHIR R4 API is the standard for exchanging medical data. Resources like Patient, Appointment, Observation, Condition, and MedicationRequest cover most clinical scenarios. Most hospital information systems (1С:Медицина, Медиалог, Инфоклиника) offer FHIR endpoints or SOAP APIs. FHIR cuts integration time by 30–50% compared to proprietary formats.
HealthKit (iOS) and Health Connect (Android 14+) provide device health data: heart rate, SpO2, ECG from Apple Watch, step count. The doctor sees patient data before the consultation and tracks trends over time.
// iOS — request heart rate data from HealthKit
let heartRateType = HKQuantityType(.heartRate)
let query = HKSampleQuery(
sampleType: heartRateType,
predicate: HKQuery.predicateForSamples(
withStart: Date().addingTimeInterval(-7*24*3600),
end: Date()
),
limit: 100,
sortDescriptors: [NSSortDescriptor(key: HKSampleSortIdentifierEndDate, ascending: false)]
) { _, samples, error in
guard let samples = samples as? [HKQuantitySample] else { return }
let readings = samples.map { $0.quantity.doubleValue(for: .count().unitDivided(by: .minute())) }
}
healthStore.execute(query)
Electronic prescriptions and signatures
An enhanced qualified electronic signature (UKEP) for doctors is required by Ministry of Health order No. 965n. On mobile devices, use CryptoPro CSP / CryptoPro NGate, or sign via backend with a hardware token. Native iOS integration without jailbreak uses UKEP services like Diasoft or Signal-COM.
Compliance and security
Medical data is a special category of personal data under 152-FZ. We implement:
- Encryption at rest: AES-256 for local storage (iOS Keychain + Data Protection API, Android Keystore + EncryptedSharedPreferences).
- Encryption in transit: TLS 1.3 with certificate pinning.
- Two-factor authentication for doctors.
- Audit log of all data operations.
- Data storage on Russian servers (localization).
| Requirement |
Implementation |
| Encryption (rest) |
AES-256 / Keychain |
| Encryption (transit) |
TLS 1.3 + pinning |
| 2FA |
TOTP / SMS |
| Audit |
Operation logs |
App Store Medical category: apps handling health data undergo extended review. We prepare a document package including a Privacy Policy explicitly addressing health data, intended use documentation, and a statement that data will not be used for advertising. App Store Review Guidelines Section 5.1.3 Health & Medical Data require strict guarantees.
What our work includes
- Requirements audit and security architecture.
- UX design considering accessibility (patients of all ages).
- iOS and Android development (SwiftUI / Jetpack Compose).
- HealthKit, Health Connect, FHIR API integration.
- Media server setup (Mediasoup / Janus) and CDN.
- Assistance with App Store and Google Play Medical category certification.
- API and administration documentation.
- 3-month post-release support.
Implementation process: step by step
- Requirements and compliance audit (1–2 weeks).
- Infrastructure and architecture selection (1 week).
- UX/UI design (2–3 weeks).
- MVP development (iOS + Android) (4–6 weeks).
- MIS and medical service integration (2–4 weeks).
- Testing and compliance review (2 weeks).
- Store publication (1–2 weeks).
Typical MVP feature set
- Patient registration and verification (SNILS, insurance policy).
- Scheduling and online booking with doctors.
- Video consultation with chat and file sharing.
- Patient card: history, documents, test results.
- HealthKit/Health Connect integration.
- Push notifications: appointment reminders, result readiness.
- Electronic prescriptions and referrals.
References and certifications
We have implemented telemedicine solutions for a network of private clinics (10+ branches) and a state medical center. All projects passed 152-FZ compliance audits and were successfully published in App Store and Google Play.
Process and timelines
Requirements audit → security architecture → accessible UX design → iOS + Android development → device testing → compliance review → publication.
MVP with basic video consultation and scheduling: 6–10 weeks. Full-featured telemedicine platform with EHR integration, prescriptions, and analytics: 3–6 months. Cost is determined individually after requirements analysis. Request an audit of your project or get a consultation — we'll help determine the optimal feature set and timeline.
How to Choose a Camera Approach on Mobile Platforms?
Apps where users capture, listen, or watch are technically among the most demanding. We deal with this every day. Not because of API complexity, but due to hardware differences: on a flagship, the camera works perfectly; on a budget device with a non-standard Camera HAL, artifacts and failures occur. On iOS, stabilization differs between generations. Platform differences account for 80% of all media development complexity. Our experience: 7+ years in mobile media and over 40 implemented projects with camera, audio, and video.
What are the Differences Between CameraX, Camera2, and AVFoundation?
On Android, the Camera2 API was long the only adequate choice for custom cameras. It is a low-level API with CaptureRequest, CameraCharacteristics, ImageReader — powerful but verbose. Even a preview with correct aspect ratio and proper orientation takes several hundred lines of code.
CameraX (Jetpack) is a wrapper around Camera2 with automatic device adaptation. Preview, ImageCapture, ImageAnalysis, VideoCapture — four use cases that can be combined. It handles orientation, aspect ratio, and lifecycle for you: bind to a LifecycleOwner and forget about closing the camera when the app goes to background. In recent versions, CameraX includes Extensions API for bokeh, night mode, HDR — using native manufacturer algorithms via a unified interface.
When is Camera2 needed directly?: RAW capture via ImageFormat.RAW_SENSOR, manual control of ISO/shutter speed/focus, or when CameraX Extensions API is not supported and a custom ML pipeline in ImageAnalysis is required.
On iOS, AVFoundation is the only path for a custom camera. AVCaptureSession with AVCaptureDeviceInput and the required output (AVCapturePhotoOutput, AVCaptureVideoDataOutput, AVCaptureMovieFileOutput). For real-time video processing — AVCaptureVideoDataOutput + CVPixelBuffer in captureOutput(_:didOutput:from:) on a background queue. This is where CoreML models receive frames for inference.
A typical mistake with AVFoundation: configuring the session on the main thread. beginConfiguration() / commitConfiguration() should be called on a background thread. Otherwise, the preview freezes, and the user sees a frozen UI. This mistake appears in 70% of the projects we have audited.
Why is AudioFocus Critical for Android Apps?
Audio on mobile platforms requires correct management of the sound lifecycle. AudioFocus is a coordination mechanism between apps. AudioManager.requestAudioFocus() with OnAudioFocusChangeListener. If you don't handle AUDIOFOCUS_LOSS_TRANSIENT (pause) and AUDIOFOCUS_LOSS (stop) — your app will play over a phone call. That guarantees a bad review on Google Play. Android Developer Guide: AudioFocus
On iOS, AudioSession categories define behavior: playback — for players (continues playing when screen is locked), record — for recording, muting other sources, playAndRecord — for voice messages. Wrong category — the app mutes the user's background music on start.
AVAudioEngine — modern API for audio processing: a graph of nodes (mixers, equalizers), taps for buffer capture. For real-time speech — SFSpeechRecognizer + inputNode.installTap.
On Android for recording with noise suppression — NoiseSuppressor.isAvailable() + create(audioRecord.audioSessionId). Works not on all devices, need a fallback.
Video: Playback and Streaming
ExoPlayer (Media3) — standard for Android. Supports HLS, DASH, SmoothStreaming, progressive playback. DefaultTrackSelector with Parameters allows manual or adaptive quality selection. DRM via DefaultDrmSessionManager with Widevine L1/L3.
Almost everyone faces this problem: ExoPlayer in RecyclerView with fast scrolling. Need a PlayerPool — a pool of reusable players. Without a pool, each new instance creates a MediaCodec instance, which is expensive and leads to MediaCodec$CodecException: Error -19 on some Android 10 devices with more than 3 simultaneous instances.
AVPlayer / AVPlayerViewController on iOS — for playback. For custom UI — AVPlayerLayer + custom controls. HLS works natively via AVPlayer(url:) with m3u8. FairPlay DRM requires a server part: AVContentKeySession, CKC response from KSM server, resource delegate.
For Flutter — video_player as a base layer, chewie for UI. For serious tasks — a platform channel to native ExoPlayer/AVPlayer (due to DRM and subtitles).
| Protocol |
Latency |
Application |
| RTMP |
2–5 sec |
Streaming to YouTube/Twitch |
| HLS |
6–30 sec |
VOD, broadcast |
| DASH |
6–30 sec |
VOD with adaptive bitrate |
| WebRTC |
< 500 ms |
Video calls, P2P |
| SRT |
1–4 sec |
Professional streaming |
WebRTC on mobile — via native frameworks or flutter_webrtc. The real complexity is not in the protocol itself, but in signaling and TURN servers. Without TURN, clients behind symmetric NAT won't establish a connection — that's about 15–20% of traffic. Coturn is the standard open-source server.
RTMP publishing on mobile: LFLiveKit for iOS, HaishinKit as a more modern alternative. On Android — rtmp-rtsp-stream-client-java or via FFmpeg with JNI. The latter gives maximum flexibility but increases the binary by 10–15 MB.
Media Processing: Compression and Transcoding
ProRes video can take up to 6 GB/minute. Compression is needed before upload. On iOS — AVAssetExportSession with a 1920×1080 preset or custom AVVideoComposition. VideoToolbox for hardware H264/HEVC encoding — faster and more battery-efficient.
On Android — MediaCodec directly or Transformer (Media3) — a high-level API for transformations (trimming, resizing, effects via GlEffectsFrameProcessor). For images — BitmapFactory.Options.inSampleSize for downsampling, Glide / Coil for caching. Coil on Coroutines fits well with Compose. Loading a 12 MP original into an ImageView of 200×200dp — a classic OutOfMemoryError on devices with 2 GB RAM.
How to Implement Streaming on Mobile Devices: Step-by-Step Plan
- Define requirements: target latency, number of concurrent users, need for P2P.
- Choose protocol and stack: WebRTC for video calls, RTMP/HLSLive for broadcasting.
- Set up signaling (SIP, WebSocket, MQTT) and TURN server.
- Implement publishing/viewing via native API or cross-platform plugin.
- Test on real devices with different cameras and network conditions.
- Optimize bitrate and resolution based on bandwidth.
Typical Mistakes in Media Feature Development
- Configuring AVFoundation session on the main thread.
- Missing AudioFocus Loss handling on Android.
- Ignoring
MediaCodec limitations on cheap devices.
- Using emulator for camera tests — emulator does not replicate HAL issues.
- Memory leaks when recreating media players without a pool.
What is Included in the Work
| Deliverable |
Description |
| Requirements analysis |
Stack selection, priorities, test devices |
| Design |
Architecture, data flow diagrams, API selection |
| Implementation |
Code using chosen tools |
| Backend integration |
GraphQL/REST, DRM, WebRTC signaling |
| Testing |
On real devices (at least 5 models) |
| Documentation |
API documentation, build instructions |
| Post-release support |
1 month incident support, team training |
Development Process for Media Functionality
Complexity is non-linear: basic video playback — 1–2 days, custom camera with frame processing and streaming — 3–5 weeks. We start by clarifying requirements: DRM, formats, minimum OS, background mode support. Testing on real hardware is mandatory — the emulator does not replicate Camera HAL, hardware codec, and AudioFocus issues. Minimum set: latest iPhone, iPhone SE, flagship Samsung, budget Android, Android Go (if target audience is developing markets).
Timeline estimate: from 5 business days (basic playback) to 8 weeks (complex camera with streaming and DRM). Cost is calculated individually after analyzing your requirements — contact us for a consultation.
Our service: "Mobile Media Integration" — this is our expertise. Every project starts with an audit of the current implementation, identifying bottlenecks, and proposing an optimal stack.
Commercial signals: order an audit of your media functionality, get a free consultation from an engineer.