The challenge: video, data, and compliance in one app
You're building a telemedicine app. The video must work in low-bandwidth areas. Medical records need to sync with existing hospital systems via FHIR. And the app must pass Apple's Medical category review while storing health data securely under 152-FZ. Each requirement alone is complex; together they demand a structured approach. We've executed 15+ medical projects over 7 years, solving exactly these problems.
How to choose a media server for telemedicine
The core of a telemedicine app is real-time video. The media server choice determines quality, latency, and regulatory compliance. Three main options exist: self-hosted WebRTC with Mediasoup/Janus, cloud SDKs like Vonage/Agora/Twilio, and HIPAA-ready platforms like Daily.co/100ms.
Self-hosted WebRTC with Mediasoup/Janus as SFU (Selective Forwarding Unit). Use WebRTC.framework (Google WebRTC port) on iOS and libwebrtc.aar on Android. Full control over infrastructure—recordings stay on your servers, critical for 152-FZ and medical confidentiality. Mediasoup reduces transactional costs by 40% compared to Twilio at loads above 1,000 consultations per month, paying off in 6–8 months.
Vonage Video API / Agora / Twilio Video provide ready SDKs with dashboards, cloud recording, and adaptive bitrate. Faster time-to-market, but data passes through provider servers—requires verifying regulatory compliance and signing a BAA for HIPAA.
Daily.co / 100ms are relatively new with good documentation and HIPAA-ready plans.
For most Russian projects requiring on-premises data storage, self-hosted infrastructure with Mediasoup plus a TURN server (coturn) in a Russian data center is best. Mediasoup delivers 3× lower latency than Twilio under peak load—critical for real-time consultations.
| Feature | Mediasoup (self-hosted) | Vonage/Twilio | Daily.co |
|---|---|---|---|
| Data control | Full | Partial | Partial |
| Latency | <100 ms | 200–400 ms | 150–300 ms |
| HIPAA-ready | Yes (with BAA) | Yes (with BAA) | Yes (with BAA) |
| Cost model | Payoff in 6–8 months | Per transaction | Fixed |
Why FHIR matters for telemedicine
HL7 FHIR R4 API is the standard for exchanging medical data. Resources like Patient, Appointment, Observation, Condition, and MedicationRequest cover most clinical scenarios. Most hospital information systems (1С:Медицина, Медиалог, Инфоклиника) offer FHIR endpoints or SOAP APIs. FHIR cuts integration time by 30–50% compared to proprietary formats.
HealthKit (iOS) and Health Connect (Android 14+) provide device health data: heart rate, SpO2, ECG from Apple Watch, step count. The doctor sees patient data before the consultation and tracks trends over time.
// iOS — request heart rate data from HealthKit let heartRateType = HKQuantityType(.heartRate) let query = HKSampleQuery( sampleType: heartRateType, predicate: HKQuery.predicateForSamples( withStart: Date().addingTimeInterval(-7*24*3600), end: Date() ), limit: 100, sortDescriptors: [NSSortDescriptor(key: HKSampleSortIdentifierEndDate, ascending: false)] ) { _, samples, error in guard let samples = samples as? [HKQuantitySample] else { return } let readings = samples.map { $0.quantity.doubleValue(for: .count().unitDivided(by: .minute())) } } healthStore.execute(query) Electronic prescriptions and signatures
An enhanced qualified electronic signature (UKEP) for doctors is required by Ministry of Health order No. 965n. On mobile devices, use CryptoPro CSP / CryptoPro NGate, or sign via backend with a hardware token. Native iOS integration without jailbreak uses UKEP services like Diasoft or Signal-COM.
Compliance and security
Medical data is a special category of personal data under 152-FZ. We implement:
- Encryption at rest: AES-256 for local storage (iOS Keychain + Data Protection API, Android Keystore + EncryptedSharedPreferences).
- Encryption in transit: TLS 1.3 with certificate pinning.
- Two-factor authentication for doctors.
- Audit log of all data operations.
- Data storage on Russian servers (localization).
| Requirement | Implementation |
|---|---|
| Encryption (rest) | AES-256 / Keychain |
| Encryption (transit) | TLS 1.3 + pinning |
| 2FA | TOTP / SMS |
| Audit | Operation logs |
App Store Medical category: apps handling health data undergo extended review. We prepare a document package including a Privacy Policy explicitly addressing health data, intended use documentation, and a statement that data will not be used for advertising. App Store Review Guidelines Section 5.1.3 Health & Medical Data require strict guarantees.
What our work includes
- Requirements audit and security architecture.
- UX design considering accessibility (patients of all ages).
- iOS and Android development (SwiftUI / Jetpack Compose).
- HealthKit, Health Connect, FHIR API integration.
- Media server setup (Mediasoup / Janus) and CDN.
- Assistance with App Store and Google Play Medical category certification.
- API and administration documentation.
- 3-month post-release support.
Implementation process: step by step
- Requirements and compliance audit (1–2 weeks).
- Infrastructure and architecture selection (1 week).
- UX/UI design (2–3 weeks).
- MVP development (iOS + Android) (4–6 weeks).
- MIS and medical service integration (2–4 weeks).
- Testing and compliance review (2 weeks).
- Store publication (1–2 weeks).
Typical MVP feature set
- Patient registration and verification (SNILS, insurance policy).
- Scheduling and online booking with doctors.
- Video consultation with chat and file sharing.
- Patient card: history, documents, test results.
- HealthKit/Health Connect integration.
- Push notifications: appointment reminders, result readiness.
- Electronic prescriptions and referrals.
References and certifications
We have implemented telemedicine solutions for a network of private clinics (10+ branches) and a state medical center. All projects passed 152-FZ compliance audits and were successfully published in App Store and Google Play.
Process and timelines
Requirements audit → security architecture → accessible UX design → iOS + Android development → device testing → compliance review → publication.
MVP with basic video consultation and scheduling: 6–10 weeks. Full-featured telemedicine platform with EHR integration, prescriptions, and analytics: 3–6 months. Cost is determined individually after requirements analysis. Request an audit of your project or get a consultation — we'll help determine the optimal feature set and timeline.







