Telemedicine App: Video, FHIR, Compliance – Full Stack

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Telemedicine App: Video, FHIR, Compliance – Full Stack
Complex
from 2 weeks to 3 months
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    860
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    746
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1163
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1035
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    970
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    563

The challenge: video, data, and compliance in one app

You're building a telemedicine app. The video must work in low-bandwidth areas. Medical records need to sync with existing hospital systems via FHIR. And the app must pass Apple's Medical category review while storing health data securely under 152-FZ. Each requirement alone is complex; together they demand a structured approach. We've executed 15+ medical projects over 7 years, solving exactly these problems.

How to choose a media server for telemedicine

The core of a telemedicine app is real-time video. The media server choice determines quality, latency, and regulatory compliance. Three main options exist: self-hosted WebRTC with Mediasoup/Janus, cloud SDKs like Vonage/Agora/Twilio, and HIPAA-ready platforms like Daily.co/100ms.

Self-hosted WebRTC with Mediasoup/Janus as SFU (Selective Forwarding Unit). Use WebRTC.framework (Google WebRTC port) on iOS and libwebrtc.aar on Android. Full control over infrastructure—recordings stay on your servers, critical for 152-FZ and medical confidentiality. Mediasoup reduces transactional costs by 40% compared to Twilio at loads above 1,000 consultations per month, paying off in 6–8 months.

Vonage Video API / Agora / Twilio Video provide ready SDKs with dashboards, cloud recording, and adaptive bitrate. Faster time-to-market, but data passes through provider servers—requires verifying regulatory compliance and signing a BAA for HIPAA.

Daily.co / 100ms are relatively new with good documentation and HIPAA-ready plans.

For most Russian projects requiring on-premises data storage, self-hosted infrastructure with Mediasoup plus a TURN server (coturn) in a Russian data center is best. Mediasoup delivers 3× lower latency than Twilio under peak load—critical for real-time consultations.

Feature Mediasoup (self-hosted) Vonage/Twilio Daily.co
Data control Full Partial Partial
Latency <100 ms 200–400 ms 150–300 ms
HIPAA-ready Yes (with BAA) Yes (with BAA) Yes (with BAA)
Cost model Payoff in 6–8 months Per transaction Fixed

Why FHIR matters for telemedicine

HL7 FHIR R4 API is the standard for exchanging medical data. Resources like Patient, Appointment, Observation, Condition, and MedicationRequest cover most clinical scenarios. Most hospital information systems (1С:Медицина, Медиалог, Инфоклиника) offer FHIR endpoints or SOAP APIs. FHIR cuts integration time by 30–50% compared to proprietary formats.

HealthKit (iOS) and Health Connect (Android 14+) provide device health data: heart rate, SpO2, ECG from Apple Watch, step count. The doctor sees patient data before the consultation and tracks trends over time.

// iOS — request heart rate data from HealthKit
let heartRateType = HKQuantityType(.heartRate)
let query = HKSampleQuery(
    sampleType: heartRateType,
    predicate: HKQuery.predicateForSamples(
        withStart: Date().addingTimeInterval(-7*24*3600),
        end: Date()
    ),
    limit: 100,
    sortDescriptors: [NSSortDescriptor(key: HKSampleSortIdentifierEndDate, ascending: false)]
) { _, samples, error in
    guard let samples = samples as? [HKQuantitySample] else { return }
    let readings = samples.map { $0.quantity.doubleValue(for: .count().unitDivided(by: .minute())) }
}
healthStore.execute(query)

Electronic prescriptions and signatures

An enhanced qualified electronic signature (UKEP) for doctors is required by Ministry of Health order No. 965n. On mobile devices, use CryptoPro CSP / CryptoPro NGate, or sign via backend with a hardware token. Native iOS integration without jailbreak uses UKEP services like Diasoft or Signal-COM.

Compliance and security

Medical data is a special category of personal data under 152-FZ. We implement:

  • Encryption at rest: AES-256 for local storage (iOS Keychain + Data Protection API, Android Keystore + EncryptedSharedPreferences).
  • Encryption in transit: TLS 1.3 with certificate pinning.
  • Two-factor authentication for doctors.
  • Audit log of all data operations.
  • Data storage on Russian servers (localization).
Requirement Implementation
Encryption (rest) AES-256 / Keychain
Encryption (transit) TLS 1.3 + pinning
2FA TOTP / SMS
Audit Operation logs

App Store Medical category: apps handling health data undergo extended review. We prepare a document package including a Privacy Policy explicitly addressing health data, intended use documentation, and a statement that data will not be used for advertising. App Store Review Guidelines Section 5.1.3 Health & Medical Data require strict guarantees.

What our work includes

  • Requirements audit and security architecture.
  • UX design considering accessibility (patients of all ages).
  • iOS and Android development (SwiftUI / Jetpack Compose).
  • HealthKit, Health Connect, FHIR API integration.
  • Media server setup (Mediasoup / Janus) and CDN.
  • Assistance with App Store and Google Play Medical category certification.
  • API and administration documentation.
  • 3-month post-release support.

Implementation process: step by step

  1. Requirements and compliance audit (1–2 weeks).
  2. Infrastructure and architecture selection (1 week).
  3. UX/UI design (2–3 weeks).
  4. MVP development (iOS + Android) (4–6 weeks).
  5. MIS and medical service integration (2–4 weeks).
  6. Testing and compliance review (2 weeks).
  7. Store publication (1–2 weeks).

Typical MVP feature set

  • Patient registration and verification (SNILS, insurance policy).
  • Scheduling and online booking with doctors.
  • Video consultation with chat and file sharing.
  • Patient card: history, documents, test results.
  • HealthKit/Health Connect integration.
  • Push notifications: appointment reminders, result readiness.
  • Electronic prescriptions and referrals.
References and certifications

We have implemented telemedicine solutions for a network of private clinics (10+ branches) and a state medical center. All projects passed 152-FZ compliance audits and were successfully published in App Store and Google Play.

Process and timelines

Requirements audit → security architecture → accessible UX design → iOS + Android development → device testing → compliance review → publication.

MVP with basic video consultation and scheduling: 6–10 weeks. Full-featured telemedicine platform with EHR integration, prescriptions, and analytics: 3–6 months. Cost is determined individually after requirements analysis. Request an audit of your project or get a consultation — we'll help determine the optimal feature set and timeline.

How to Choose a Camera Approach on Mobile Platforms?

Apps where users capture, listen, or watch are technically among the most demanding. We deal with this every day. Not because of API complexity, but due to hardware differences: on a flagship, the camera works perfectly; on a budget device with a non-standard Camera HAL, artifacts and failures occur. On iOS, stabilization differs between generations. Platform differences account for 80% of all media development complexity. Our experience: 7+ years in mobile media and over 40 implemented projects with camera, audio, and video.

What are the Differences Between CameraX, Camera2, and AVFoundation?

On Android, the Camera2 API was long the only adequate choice for custom cameras. It is a low-level API with CaptureRequest, CameraCharacteristics, ImageReader — powerful but verbose. Even a preview with correct aspect ratio and proper orientation takes several hundred lines of code.

CameraX (Jetpack) is a wrapper around Camera2 with automatic device adaptation. Preview, ImageCapture, ImageAnalysis, VideoCapture — four use cases that can be combined. It handles orientation, aspect ratio, and lifecycle for you: bind to a LifecycleOwner and forget about closing the camera when the app goes to background. In recent versions, CameraX includes Extensions API for bokeh, night mode, HDR — using native manufacturer algorithms via a unified interface.

When is Camera2 needed directly?: RAW capture via ImageFormat.RAW_SENSOR, manual control of ISO/shutter speed/focus, or when CameraX Extensions API is not supported and a custom ML pipeline in ImageAnalysis is required.

On iOS, AVFoundation is the only path for a custom camera. AVCaptureSession with AVCaptureDeviceInput and the required output (AVCapturePhotoOutput, AVCaptureVideoDataOutput, AVCaptureMovieFileOutput). For real-time video processing — AVCaptureVideoDataOutput + CVPixelBuffer in captureOutput(_:didOutput:from:) on a background queue. This is where CoreML models receive frames for inference.

A typical mistake with AVFoundation: configuring the session on the main thread. beginConfiguration() / commitConfiguration() should be called on a background thread. Otherwise, the preview freezes, and the user sees a frozen UI. This mistake appears in 70% of the projects we have audited.

Why is AudioFocus Critical for Android Apps?

Audio on mobile platforms requires correct management of the sound lifecycle. AudioFocus is a coordination mechanism between apps. AudioManager.requestAudioFocus() with OnAudioFocusChangeListener. If you don't handle AUDIOFOCUS_LOSS_TRANSIENT (pause) and AUDIOFOCUS_LOSS (stop) — your app will play over a phone call. That guarantees a bad review on Google Play. Android Developer Guide: AudioFocus

On iOS, AudioSession categories define behavior: playback — for players (continues playing when screen is locked), record — for recording, muting other sources, playAndRecord — for voice messages. Wrong category — the app mutes the user's background music on start.

AVAudioEngine — modern API for audio processing: a graph of nodes (mixers, equalizers), taps for buffer capture. For real-time speech — SFSpeechRecognizer + inputNode.installTap.

On Android for recording with noise suppression — NoiseSuppressor.isAvailable() + create(audioRecord.audioSessionId). Works not on all devices, need a fallback.

Video: Playback and Streaming

ExoPlayer (Media3) — standard for Android. Supports HLS, DASH, SmoothStreaming, progressive playback. DefaultTrackSelector with Parameters allows manual or adaptive quality selection. DRM via DefaultDrmSessionManager with Widevine L1/L3.

Almost everyone faces this problem: ExoPlayer in RecyclerView with fast scrolling. Need a PlayerPool — a pool of reusable players. Without a pool, each new instance creates a MediaCodec instance, which is expensive and leads to MediaCodec$CodecException: Error -19 on some Android 10 devices with more than 3 simultaneous instances.

AVPlayer / AVPlayerViewController on iOS — for playback. For custom UI — AVPlayerLayer + custom controls. HLS works natively via AVPlayer(url:) with m3u8. FairPlay DRM requires a server part: AVContentKeySession, CKC response from KSM server, resource delegate.

For Flutter — video_player as a base layer, chewie for UI. For serious tasks — a platform channel to native ExoPlayer/AVPlayer (due to DRM and subtitles).

Protocol Latency Application
RTMP 2–5 sec Streaming to YouTube/Twitch
HLS 6–30 sec VOD, broadcast
DASH 6–30 sec VOD with adaptive bitrate
WebRTC < 500 ms Video calls, P2P
SRT 1–4 sec Professional streaming

WebRTC on mobile — via native frameworks or flutter_webrtc. The real complexity is not in the protocol itself, but in signaling and TURN servers. Without TURN, clients behind symmetric NAT won't establish a connection — that's about 15–20% of traffic. Coturn is the standard open-source server.

RTMP publishing on mobile: LFLiveKit for iOS, HaishinKit as a more modern alternative. On Android — rtmp-rtsp-stream-client-java or via FFmpeg with JNI. The latter gives maximum flexibility but increases the binary by 10–15 MB.

Media Processing: Compression and Transcoding

ProRes video can take up to 6 GB/minute. Compression is needed before upload. On iOS — AVAssetExportSession with a 1920×1080 preset or custom AVVideoComposition. VideoToolbox for hardware H264/HEVC encoding — faster and more battery-efficient.

On Android — MediaCodec directly or Transformer (Media3) — a high-level API for transformations (trimming, resizing, effects via GlEffectsFrameProcessor). For images — BitmapFactory.Options.inSampleSize for downsampling, Glide / Coil for caching. Coil on Coroutines fits well with Compose. Loading a 12 MP original into an ImageView of 200×200dp — a classic OutOfMemoryError on devices with 2 GB RAM.

How to Implement Streaming on Mobile Devices: Step-by-Step Plan

  1. Define requirements: target latency, number of concurrent users, need for P2P.
  2. Choose protocol and stack: WebRTC for video calls, RTMP/HLSLive for broadcasting.
  3. Set up signaling (SIP, WebSocket, MQTT) and TURN server.
  4. Implement publishing/viewing via native API or cross-platform plugin.
  5. Test on real devices with different cameras and network conditions.
  6. Optimize bitrate and resolution based on bandwidth.
Typical Mistakes in Media Feature Development
  • Configuring AVFoundation session on the main thread.
  • Missing AudioFocus Loss handling on Android.
  • Ignoring MediaCodec limitations on cheap devices.
  • Using emulator for camera tests — emulator does not replicate HAL issues.
  • Memory leaks when recreating media players without a pool.

What is Included in the Work

Deliverable Description
Requirements analysis Stack selection, priorities, test devices
Design Architecture, data flow diagrams, API selection
Implementation Code using chosen tools
Backend integration GraphQL/REST, DRM, WebRTC signaling
Testing On real devices (at least 5 models)
Documentation API documentation, build instructions
Post-release support 1 month incident support, team training

Development Process for Media Functionality

Complexity is non-linear: basic video playback — 1–2 days, custom camera with frame processing and streaming — 3–5 weeks. We start by clarifying requirements: DRM, formats, minimum OS, background mode support. Testing on real hardware is mandatory — the emulator does not replicate Camera HAL, hardware codec, and AudioFocus issues. Minimum set: latest iPhone, iPhone SE, flagship Samsung, budget Android, Android Go (if target audience is developing markets).

Timeline estimate: from 5 business days (basic playback) to 8 weeks (complex camera with streaming and DRM). Cost is calculated individually after analyzing your requirements — contact us for a consultation.

Our service: "Mobile Media Integration" — this is our expertise. Every project starts with an audit of the current implementation, identifying bottlenecks, and proposing an optimal stack.

Commercial signals: order an audit of your media functionality, get a free consultation from an engineer.