How to choose a healthcare software development company in 2026

““

TL;DR

How to choose a healthcare software development company in 2026 is a contract question before it is an engineering question. The vendor becomes your HIPAA business associate the day it touches patient data, and business associates filed 16% of the large breach reports in OCR's breach report to Congress for calendar year 2024 while accounting for 85% of the individuals affected. Twelve checks separate a partner from a liability.

  • Get the business associate agreement signed before any protected health information moves, and get one for every subcontractor.
  • Ask for a dated risk analysis, not a badge. HHS says it does not endorse private certifications.
  • Ask which clinical integrations they shipped and against which versions.
  • Put the exit in the first contract: code assigned on creation, data returned, credentials revoked on a named day.

What you are buying when you hire a healthcare software partner

You are buying a second set of hands on your patients' records. That is the whole difference from ordinary outsourcing, and it is the part most vendor pages skip.

The money is back. US digital health startups raised $7.4 billion across 244 deals in the first half of 2026, according to Rock Health, up a billion on the same period a year earlier. More products, more vendors, same regulator.

And the regulator counts. In its report to Congress for calendar year 2024, the HHS Office for Civil Rights logged 663 breaches of unsecured protected health information affecting 500 or more people, touching 242,908,056 individuals. Business associates filed 106 of those reports, 16% of the total, and those reports covered 206,921,071 individuals: 85% of everyone affected that year. Your development vendor is a business associate.

Enforcement follows the same line. OCR received 30,256 new HIPAA complaints in 2024, opened 730 compliance reviews and closed 22 investigations with corrective action plans or civil money penalties totaling $9,944,612. The failure named again and again in those resolutions is the same one: no accurate and thorough risk analysis.

Four dates in 2026 and 2027 that change the questions

Four dates decide which of these checks is urgent for you. None of them moved for your project.

The FDA's Quality Management System Regulation took effect on February 2, 2026. Part 820 now incorporates ISO 13485:2016 by reference, so if your product is a regulated device, "we follow an agile process" is no longer an answer to a quality question.

Payer deadlines are next. Under CMS-0057-F, prior authorization decision timeframes applied from January 1, 2026. The four required FHIR APIs, covering patient access, provider access, payer-to-payer exchange and prior authorization, are due by January 1, 2027. A vendor you sign in the fourth quarter has one quarter.

The HIPAA Security Rule rewrite slipped. The proposed rule published on January 6, 2025 would make encryption, multi-factor authentication, an asset inventory and annual compliance audits mandatory, and would require covered entities to obtain verification of a business associate's technical safeguards. The Unified Agenda now lists final action for July 2027. It is not law yet. That is a reason to write those controls into the contract, not a reason to drop them.

Then there is the one that should worry you most. On March 5, 2026 OCR settled with MMG Fusion, a software company and business associate, over a breach affecting 15 million individuals. It was the twelfth enforcement action under OCR's Risk Analysis Initiative. The regulator is now settling with software vendors by name.

How we built this checklist

Four rules, applied to every check.

  • The answer is verifiable before money moves, in a document, a log, or a phone call with a named person.
  • There is a wrong answer. A question every vendor passes is a warm-up.
  • The check maps to a citable obligation or to a failure OCR has actually penalized.
  • Where we state our own numbers, any group with fewer than three data points is not published.

We also read the three guides that currently rank for this question: Aback AI, ICS and Scalater. They cover the right territory. None of the three publishes a source list, which is the gap this piece is trying to close.

One disclosure. Mercury Development sells healthcare software development, so every check below is aimed at us too, and the primary research section applies two of them to our own published work.

The 12 checks at a glance

#Ask thisA real answer contains
1Will you sign a BAA, and does every subcontractor sign one?A draft BAA, plus the list of companies that get one
2Can we see your most recent risk analysis and its date?A dated document with scope and an owner per finding
3How many hours until you tell us you suspect a breach?A number in the contract, well inside 60 days
4Which proposed Security Rule controls do you already run?Encryption, MFA, an asset inventory, an audit cadence
5Who can read production PHI, and when does access end?A named list and an offboarding rule in days
6Can you show an audit log from something you built?A de-identified export showing who read which record, and when
7Which clinical integrations shipped, against which versions?HL7 v2 message types, FHIR release, sandbox evidence
8Whose quality system does the device code live inside?An ISO 13485 aligned QMS and design history records
9Who owns the code, and when does assignment take effect?Assignment on creation, not on final payment
10What does the exit look like for our data and accounts?PHI returned or destroyed, credentials revoked on a date
11What is the smallest paid piece that leaves us something?A priced phase whose output survives you firing them
12Which engagements did you inherit from another team?Two references you can call, on inherited codebases

Compliance claims and what replaces them

Most vendor compliance pages are adjectives. Replace each adjective with a document.

1. Will you sign a BAA, and does every subcontractor sign one?

Not optional, and not theirs to grant as a favor. 45 CFR 164.308(b) lets you hand ePHI to a business associate only if you obtain satisfactory assurances, documented in a written contract. Ask for the draft before the proposal. Then ask which subcontractors, offshore entities and AI vendors sit behind them, because each one needs its own agreement.

2. Can we see your most recent risk analysis and its date?

Ask for the document, because the badge is worthless. HHS states plainly that it "does not endorse or otherwise recognize private organizations' 'certifications'" of HIPAA compliance, and that no certification stops OCR finding a violation later. A real answer is a risk analysis with a date, a scope that names systems, and a remediation owner per finding. NIST SP 800-66 Rev. 2 is the format to ask for.

3. How many hours until you tell us you suspect a breach?

45 CFR 164.410 gives a business associate until 60 calendar days after discovery to tell you. That is the legal outer edge and a terrible contract term, because you cannot meet your own notification duty if your vendor takes the maximum. Put a number in hours in the BAA: initial notice, forensic detail, and who pays for the notification letters. Ask what triggers the clock, suspicion or confirmation. Suspicion is the answer you want.

Security engineering you can verify

Every vendor says security. Ask for the four things that are either running or not.

4. Which proposed Security Rule controls do you already run?

Use the proposed rule as a maturity checklist while it waits for final action. Encryption of ePHI with narrow exceptions, multi-factor authentication, a technology asset inventory, annual compliance audits. A partner already running all four will say so in a sentence. A partner who calls them future requirements has just told you where it is.

5. Who can read production PHI, and when does that access end?

Ask for the current list of humans with production access, by role, not by count. Then ask the offboarding question: when a developer rolls off on Friday, which day are their credentials revoked, and who verifies it. Vendors who answer "immediately" without naming the process are describing an intention. Ask to see one revocation ticket.

6. Can you show us an audit log from something you built?

Request a de-identified export from a system they shipped. You are looking for the user, the record, the action and the timestamp in one row, retained long enough to investigate. A team that has built auditable healthcare systems produces this in a day. A team that has not will send you an architecture diagram instead.

Clinical data and integration competence

This is where generalist agencies stop being cheaper.

7. Which clinical integrations have you shipped, against which versions?

Vague answers are the tell. Ask for HL7 v2 message types by name, the FHIR release they built against, which EHR sandboxes they tested in, and who did the certification paperwork. If your product exchanges data with payers, the CMS API deadline of January 1, 2027 is theirs to hit with you, so ask what they have already built against those requirements.

8. Whose quality system does the device code live inside?

If your software is a regulated device, the code lives inside a quality system or it does not ship. Ask which one, who maintains the design history file, and whether they have supported a submission. For a cyber device, 21 U.S.C. 360n-2 requires a software bill of materials covering commercial, open-source and off-the-shelf components. The FDA reissued its premarket cybersecurity guidance on February 3, 2026, superseding the June 2025 final version, so ask which one their checklist was written against.

What the contract must say about ownership and exit

The contract is the only part of a vendor you can inspect before paying.

9. Who owns the code, and when does the assignment take effect?

Ask for a written assignment effective as the code is written, then check whether it is conditional on final payment. Conditional assignment means a billing dispute becomes an ownership dispute while your product is live. Ask the same question about model weights and any fine-tuning data if the build uses machine learning.

10. What does the exit look like for our data and our credentials?

Negotiate the ending at the beginning, because your leverage peaks before the first invoice. A real exit clause names what happens to PHI, returned or destroyed with written certification, which accounts transfer, how long access persists after termination, and what the handover package contains. Ask for a dry run before the final invoice clears.

Evidence before you commit

Two checks that cost a vendor nothing to pass and everything to fake.

11. What is the smallest paid piece that leaves us something we keep?

The good answer is a priced discovery phase producing artifacts you own: a specification, a threat model, a data flow diagram showing every place PHI lands. You can hand those to a different vendor. A free proposal and a twelve-month commitment is a sales process, not a pilot.

12. Which engagements did you inherit from another team?

Anyone can show a launch. Ask for two products they took over from somebody else and still run, then ask to call those clients. Inheriting a healthcare codebase means reading someone else's access controls and audit trails under a live compliance obligation, which is the closest public proxy for how they will treat yours.

Which checks matter most for your situation

Twelve checks is a long call. Cut the list by what you are actually doing.

A first build with no clinical staff of your own: checks 1 and 2, then check 7. You are buying domain knowledge, and those reveal whether it exists before a specification hides it.

A rescue after a failed vendor: checks 5 and 6, then 10 and 12, asked about your current product before the new one. If nobody can tell you today who holds production credentials, that is your first deliverable.

A live product moving into payer or device territory: checks 4 and 7, plus 8 if the software is regulated. Both deadlines above are regulatory and neither negotiates.

What happened when we ran this on our own case pages

These are our own numbers, counted by hand from our published portfolio pages rather than from a CRM.

Check 12 first. Around 30% of those case pages describe work we inherited from another team, including a system whose original vendor handed it over without source code. That is the number we would want a buyer to ask us for.

Check 6 is less flattering. Only around 35% of the same pages carry an outcome number we can attribute to our own work rather than a client's scale, which means roughly two thirds of our published evidence would not survive the test this article tells you to apply. Around 10% name the compliance regime the product had to meet at all.

Two of those do, and they are the ones a healthcare buyer should read: a medical billing workflow system we have extended since 2006, now on its fourth major release, described on the Precision Practice Management page as 100% HIPAA compliant, and the web migration of a 510(k) FDA-cleared imaging application delivered with HIPAA-compliant online access in three months. The gap between those two pages and the other twenty-seven is exactly the gap this checklist is built to find.

A checklist is a filter, not a scorecard

Opinion, stated plainly. What matters is not the score. It is what happens when you ask.

A vendor with a working compliance practice answers all twelve in writing inside a week, because the answers already exist as documents. A vendor who needs three weeks and sends adjectives is showing you how the first incident will go. That signal costs you nothing and arrives before the contract.

The failure mode on your side is subtler. You can run all twelve, get good answers, then sign a template that contradicts them: assignment on payment, a sixty day breach clause, no named subcontractors. Now you hold the risk plus the false comfort of having done diligence. Every check above has one durable form, and it is a clause.

Written by Rob Devereaux, Chief Operating Officer at Mercury Development. Rob has run the firm's operations from Hudson, Ohio since 2019 and has over 20 years of operational and financial experience. The contract terms, subcontractor lists and delivery records these checks test are the ones he signs at Mercury.

Ready to run this on us? Start with check two

Use the list on us before you use it on anyone else. Tell us what you are building, whose data it touches and what you have today. We come back in writing, including the awkward answers about what our own published work does and does not prove.

Put the checklist to us

Feel free to contact us and we'll respond as soon as possible.

Frequently asked questions

Sources

  1. Rock Health. H1 2026 funding and market overview: Durable roots, shifting routes. Published 2026-07-13. (Report)
  2. Office for Civil Rights. Annual Report to Congress on Breaches of Unsecured Protected Health Information For Calendar Year 2024. Undated. (Report)
  3. Office for Civil Rights. Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance For Calendar Year 2024. Undated. (Report)
  4. Food and Drug Administration. Medical Devices; Quality System Regulation Amendments. Published 2024-02-02. (Legislation)
  5. Centers for Medicare and Medicaid Services. Medicare and Medicaid Programs; Patient Protection and Affordable Care Act; Advancing Interoperability and Improving Prior Authorization Processes. Published 2024-02-08. (Legislation)
  6. Office for Civil Rights. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information. Published 2025-01-06. (Legislation)
  7. Office of Information and Regulatory Affairs. HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information, RIN 0945-AA22. Undated. (WebPage)
  8. Department of Health and Human Services. HHS' Office for Civil Rights Settles HIPAA Investigation of MMG Fusion, LLC Breach Affecting 15 Million Individuals. Published 2026-03-05. (NewsArticle)
  9. Aback AI. How to Evaluate a HIPAA-Compliant Software Development Company. Undated. (BlogPosting)
  10. ICS. How to Choose the Right Medical Device Software Development Partner. Undated. (WebPage)
  11. Scalater. How to Choose a Telehealth Software Development Company (10-Point Checklist). Undated. (BlogPosting)
  12. Mercury Development. Driving Healthcare Transformation. Undated. (WebPage)
  13. Office of the Federal Register. 45 CFR 164.308, Administrative safeguards. Undated. (Legislation)
  14. Department of Health and Human Services. Are we required to "certify" our organization's compliance with the standards of the Security Rule?. Undated. (WebPage)
  15. National Institute of Standards and Technology. Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide. Published 2024-02-14. (Report)
  16. Office of the Federal Register. 45 CFR 164.410, Notification by a business associate. Undated. (Legislation)
  17. Office of the Law Revision Counsel. 21 U.S. Code 360n-2. Ensuring cybersecurity of devices. Undated. (Legislation)
  18. Food and Drug Administration. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions. Published 2026-02-03. (Report)
  19. Mercury Development. Precision practice management. Undated. (WebPage)
  20. Mercury Development. Developing a Custom Web-based Application for Medical Use. Undated. (WebPage)
  21. Mercury Development. Internal count of published portfolio case pages, healthcare and regulated work, aggregated. Undated. (Dataset)