HIPAA and HITRUST telehealth video on WebRTC and LiveKit: sub-300 ms consultations, EHR integration on FHIR R4 with US Core v9, and the audit trail your assessor asks for. Behind TransLinguist on the NHS UK national framework and 250+ real-time products since 2005.
A telehealth platform is three systems that have to agree: a video path that stays inside your compliance boundary, a clinical record that accepts what the session produced, and an audit trail that survives a review. We build all three, and we build them so a FHIR version change isn't a rewrite.
Telehealth platforms that carry live consultations, move clinical data, and put AI where a clinician still signs off.
WebRTC and LiveKit for 1:1 and multi-party sessions, screen sharing and medical imaging, sub-300 ms on a tuned path. Recordings are encrypted at rest with keys you hold.
EHR and EMR on FHIR R4: Epic, Oracle Health, MEDITECH, eClinicalWorks. Plus scheduling, billing, e-prescribing and patient portals.

Transcription, summarization, triage flags and image analysis run as swappable services behind one interface. We integrate whichever ambient scribe you've chosen — Microsoft Dragon Copilot, Abridge, Nabla, Suki or Ambience — and the interface means swapping one later doesn't touch the rest of the product.
Four dates that decide the shape of a telehealth build. We keep them current because they move.
The Consolidated Appropriations Act, 2026 extended the location waivers, the expanded provider list, FQHC and RHC eligibility, and audio-only visits. Hospital Care at Home runs to 30 September 2030. Reimbursement is no longer the open question it was two years ago.
The proposed rule landed in January 2025 and the final rule is now targeted for July 2027. We build to the rule in force and to the proposal's likely asks — MFA, encryption, asset inventory — because retrofitting those later costs more than doing them now.
Worth watching if your product touches reproductive-health records. The 42 CFR Part 2 alignment deadline already passed, on 16 February 2026.
It now maps the OWASP Top 10 for LLM Applications. If your product has an AI layer, your assessor has questions about it that didn't exist in the last cycle.
AI telehealth platforms operate on a secure real-time video infrastructure combined with AI processing and healthcare integrations.
Each stage of the system is clearly defined to ensure reliability, compliance, and scalability.
Patients and clinicians connect through encrypted WebRTC video sessions. Identity verification and role-based access control are applied.
Audio and video streams are optimized for stability and low latency. Sessions support screen sharing, medical images, and device data.
Speech-to-text, summaries, risk flags, and image analysis run as separate services behind one interface. That matters because the scribe market keeps changing—and a product tied to one vendor’s SDK can age with it.
Session data, notes, and AI outputs are transferred to EHR/EMR systems and internal healthcare tools.
The system tracks connection quality, session activity, and AI-triggered risk indicators.
Consultation metadata, transcripts, and recordings (if enabled) are stored securely with full audit trails.
We map resources so the move to R6 is a migration, not a rewrite. That's a design decision you make once, at the start, and it's the one most telehealth builds skip.
A HIPAA-compliant voice AI agent needs three things video alone doesn't: a call path that never parks audio outside your boundary, transcripts that live in your database, and an audit trail per turn. We build voice agents on LiveKit and SIP inside the same telehealth platform, so the call, the chart, and the log stay in one system.
Most voice platforms route audio through their own infrastructure and keep the transcript. In a clinic that's the whole problem: the transcript is PHI, and now it's in someone else's logs. The second problem is the handoff. A patient who asks to speak to a nurse can't be dropped, so the agent has to transfer mid-call with the context attached, not start a new ticket.
We'd put the agent on your own media path and keep the model calls stateless. It costs more engineering up front than a managed voicebot, and for a 20-seat practice that trade isn't worth it. Past a few thousand calls a month, it is.
LiveKit or SIP carries the call. Speech-to-text and text-to-speech run as swappable providers, so a vendor's price change or an accuracy problem in noisy telephony audio doesn't become a rewrite. The agent calls your EHR through FHIR R4 — Epic and Oracle Health cover most of the market — and writes back to the same record the video visit writes to. Turn detection and barge-in are tuned on your own audio, not on a demo set.
We built Nucleus, an on-premise communication platform whose AI phone agents handle 600M+ call minutes a month for 5,000+ businesses, under SOC II, GDPR and HIPAA. On the clinical side we built CirrusMed, a HIPAA telemedicine practice platform now licensed in 48+ U.S. states. We haven't run a healthcare voice agent past that call volume on a single tenant — beyond it, ask someone who has.
A typical deployment includes:
This architecture supports small clinics as well as large healthcare networks. Architectures can be aligned with HIPAA, GDPR, and enterprise security requirements.
The layer boundaries are the deliverable. They're what lets you replace a scribe vendor, move a region, or answer an assessor about one layer without auditing the whole product.
Figure 1. HIPAA and HITRUST AI telehealth reference architecture. Patient and clinician on WebRTC, AI on the side bus, EHR via FHIR R4, audit from day one.
From design and backend to launch and support, with the compliance work in scope from day one.
More speed, more stability, or the AI layer your roadmap has been promising.
Unfinished or inherited code. We read it, name what's salvageable, and finish it.
Add our engineers to your team for ongoing development, support, and technical ownership.
How most of our clients work
When you need one number signed off

Send the use case and a few minutes of footage. You get back the models worth trying, the cost per stream, and whether an off-the-shelf API would do.
Get it free →
Already have a model that underperforms in production? We look at the data, the pipeline and the thresholds, and tell you which of the three is the problem.
Get it free →
After one discovery call: structured requirements, recommended technologies, block-level estimate.
Get it free →
A specialist review of your video or streaming product covering latency, media server architecture, WebRTC, playback reliability, real-time chat, and scalability. Every finding is specific, located, and fixable. Delivered within a week.
Get it free →Four claims, each with a named system behind it.
Video, audio and voice AI, 250+ projects, 50 in-house engineers. Telehealth, broadcast, classrooms and surveillance — the same real-time problems in different clothes.
We've been the only development team on VALT for 10+ years — HIPAA and GDPR video used in medical education and simulation labs, shipped through v6.5 in 2025.
TransLinguist runs on the NHS UK national framework with 75+ languages and 30,000+ interpreters.
Architectures shipped against HIPAA, HITRUST, SOC 2 Type II, GDPR and FERPA: SRTP and DTLS encryption, KMS-encrypted recordings, scoped RBAC, audit-ready logs.
What it is, what it integrates with, what compliance asks, and what it costs.
Ask an engineerA secure system for remote consultations that combines live video with AI for documentation, triage and workflow. The three parts that decide the build are the media path, the FHIR integration and the audit trail.
R4, with US Core v9.0.0 and USCDI v6. R4 is what the ONC rule and the CMS payer APIs require. We map resources so the eventual move to R6 is a migration rather than a rewrite — US Core is skipping R5 entirely.
The platform we build supports your compliance: encrypted transport, keys you hold, scoped access, and per-action audit logs. Compliance is an attestation about your organization, not a feature anyone can ship on your behalf.
The Security Rule update is still proposed, not final — the target for a final rule is now July 2027. A Privacy Rule final rule is due August 2026, and the 42 CFR Part 2 alignment deadline passed on 16 February 2026.
As of CSF v11.8.0, released 8 May 2026, it maps the OWASP Top 10 for LLM Applications. So yes, and your assessor will ask about prompt handling and model data flow.
The flexibilities run through 31 December 2027 under the Consolidated Appropriations Act, 2026, and several policies became permanent in the CY 2026 fee schedule. Hospital Care at Home runs to 30 September 2030.
Whichever one you've chosen. The market has five credible vendors and no standard — Microsoft Dragon Copilot (formerly Nuance DAX), Abridge, Nabla, Suki and Ambience — and roughly a third of providers had ambient access by early 2026. We build the interface, so the choice stays yours and stays reversible.
Yes: live transcription, summaries, risk flags, and image analysis where it's warranted. What we won't ship is a model making a clinical call without a clinician in the loop.
EHR and EMR on FHIR R4 — Epic holds 43.7% of US acute-care hospitals and Oracle Health 21.9%, so those two cover most cases — plus scheduling, billing and patient portals.
Yes, and the honest version is that scale is an architecture decision made early: multi-region SFU, session routing, recording storage. We've run real-time systems at 600M+ minutes a month, and we'll tell you where your design stops being cheap.
The three services this page touches: the telemedicine build itself, imaging when the AI has to look at a scan, and voice agents when it has to answer the phone.
Three products in production: a telemedicine practice platform, a HIPAA video system used in medical training, and interpretation running inside the NHS.
The long versions: how the build actually goes, which features earn their place, and what the bill looks like.
Within 24 hours you get a realistic estimate, technical recommendations and next steps. Free, no obligations.