Healthcare & Meditech

Software that has to prove what it does

In medtech the code is only half of what you hand over. The other half is the evidence: what the software does, who changed it, why, and whether that still matches the technical documentation a notified body will read. We build clinical and device integrations, regulated workflows, and complete applications from scratch — inside your quality management system, not alongside it. Embedded in your team, or as a scope we take end to end.

We work under your QMS

You remain the manufacturer if you want to. We work as a qualified development supplier inside your ISO 13485 processes, producing deliverables that fit your design documentation instead of a parallel set of our own.

Built around your systems

Hospital and practice systems, PACS, LIMS, ERP, in-house tools. We work in the landscape you already have — no rip-and-replace, no migration you didn't ask for.

Teams that stay

The same engineers across releases, so the reasoning behind a risk control or a design decision is still in the room three audits later.

Our Clients

Trusted by industries & large-scale competitors

ACCA
Bosch
Deutsche Bank
EHF
Enel
Federal Mogul
HMM
Howdens
KSB
Mitsubishi
NetCologne
Outside Clinic
Pfisterer
Verivox
Virgin Media
Wurth
Where we build
Where we build

The layers between your systems

Clinical and device data sit in systems that were never designed to talk to each other, and the regulatory duties sit on top of all of them at once. We build the connections — and, now and then, the application that should exist and doesn't. Both are our work.

Clinical and device integration

Interfaces over HL7 v2, FHIR, and DICOM, and device output brought into records, registries, and analysis in a form clinicians and reviewers can actually use.

Post-market data

Structured capture of complaints, incidents, and field feedback — so post-market surveillance and vigilance reporting become a query against real data instead of a reconstruction every quarter.

Regulated workflows

Design control, change control, CAPA, and release documentation held in software with the trail intact — including the traceability from requirement to risk control to test that an auditor will follow.

Patient- and staff-facing applications

Portals, scheduling, therapy and rehabilitation applications — built for people who have thirty seconds between patients, not five minutes.

Data, security, jurisdiction
Data, security, jurisdiction

Questions your compliance team will ask first

Patient data and regulated documentation raise the governance questions long before anyone looks at functionality. Here are our answers before you have to ask.

Where the data is

Development and operations run from Romania — inside the EU, under GDPR, with no third-country transfer to justify for special-category health data. Hosting follows your requirements, not ours.

Access and supplier record

Named engineers, defined access scope, documented on- and offboarding — and a supplier record you can put in front of an auditor who asks who touched the software.

Security and lifecycle practice

Our processes are aligned with ISO 27001 for information security and ISO 20000 for service management, and we work to the software lifecycle rigour your safety class requires.

Health data in development

Pseudonymised or synthetic test data by default, minimisation where pseudonymisation is not possible, and no client data used to train models.

How we set up
How we set up

The project environment comes with us

Getting a nearshore team productive usually costs weeks of licence procurement, tool provisioning, and access requests. We remove that step: our project and delivery environment is hosted, configured, and included.

Tooling included

Project management, tracking, and delivery tooling are provided and hosted by us at no additional cost — configured before the first sprint, not during it.

Or your validated toolchain

If your QMS requires specific validated tools, we work in yours instead. The point is that setup is never the bottleneck, and never the thing that breaks your process.

Service management

Defined responsibilities, response expectations, and escalation paths, aligned with ISO 20000 practice — documented, because your supplier controls will ask for it.

Visibility

You see the same board we do: progress, open issues, quality checks, and what is actually shipping this sprint — exportable when someone needs it as evidence.

Why now
Why now

Four deadlines already in your planning

Medtech roadmaps are currently driven less by product ideas than by dates set elsewhere that cannot be moved. All of them compete for the same internal engineering capacity.

MDR certificates expire in 2027 and 2028

Extended deadlines for legacy devices fall at the end of 2027 for class III and implantable class IIb, and the end of 2028 for most others. The technical documentation, and the software behind it, has to be ready long before the certificate lapses.

Rule 11 pulled software up a class

Decision-support and diagnostic software that used to sit comfortably in class I frequently lands in IIa or higher under MDR — which means a notified body, a full technical file, and a software lifecycle process to match.

AI Act duties arrive in 2027

An AI-based medical device faces conformity obligations under both MDR and the AI Act. Data governance, logging, and human oversight are far cheaper to design in than to retrofit into a device already on the market.

The European Health Data Space

Structured, interoperable, exportable health data becomes an obligation rather than a feature request. Systems that keep clinical detail in free text will feel this first.

Our Case Studies

Take a look at our work and imagine your project here

Unifying lead streams and building a single source of customer truth for Outside Clinic
Completed

Unifying lead streams and building a single source of customer truth for Outside Clinic

Outside Clinic, a UK domiciliary healthcare provider, acquires leads through many channels at once — Facebook campaigns, Google Ads, its own website, and purchased lead lists. dotWhite built the Azure-based pipeline that unifies these streams so no lead falls through the cracks, and the services behind a single customer portal used as the source of truth across all branches.

A modular practice-management platform for physiotherapy, rehab sport, and fitness
Completed

A modular practice-management platform for physiotherapy, rehab sport, and fitness

Healthcare facilities typically run separate systems for scheduling, member management, billing, and documentation — with the media breaks, data loss, and double entry that implies. With Proleos⁺, a modular platform was built that unifies these processes: practice management, rehab management, member management, billing and POS, scheduling, and digital anamnesis (eVA), each activatable as an independent module.

What you can achieve with us

The Architecture of Immediacy: High-Velocity AI Built on European Integrity

We master the full spectrum of artificial intelligence, weaving sophisticated models into a framework that is inherently aligned with the highest standards of European data sovereignty. By condensing complex, high-volume operations into near-instantaneous execution, we replace traditional operational lag with a new standard of organizational cadence. Partnering with us means deploying intelligence that respects legal boundaries while providing the unhindered velocity required to redefine your market position.

Connect now

Certificates

The Gold Standard: Your Strategic Edge in European Software Engineering

By achieving ISO 27001, we turn rigid European data protection requirements into a powerful asset, securing your sensitive information within a robust, world-class digital fortress. Simultaneously, our ISO 20000 certification strips away operational friction, ensuring seamless process excellence where every stage of your development cycle is executed with surgical precision. This dual certification serves as your premium passport to the European market, blending high-velocity innovation with the most rigorous international benchmarks for security and service quality.

ISO27001ISO20000
Contact

Tell us what's blocked

Let's talk about your next project and how we can help you succeed.

Contact

Latest News

The bottleneck was never typing
Company News

The bottleneck was never typing

Every nearshoring provider is talking about AI. Here is what we actually point it at — requirements, test coverage and code review — and why that is a deliberate choice rather than a modest one.

Explore the story

Somewhere Worth Coming In For
Company NewsCareers

Somewhere Worth Coming In For

We've moved into a house in the middle of Cluj-Napoca — 35+ desks, rooms to think in and rooms to argue in, and a garden that has already seen its first barbecue.

Explore the story

Tell us what's blocked

So what's next?

interested in exploring potential business opportunities with dotWhite? Use the button below to send us a message.

Or better yet, book a meeting with us in Calendly.

To Top