Patient portal
What we build

Patient
portal

A secure area for an ongoing treatment relationship.

A patient portal for people managing an ongoing relationship with a treatment or programme: secure access to their own information, adherence support and a channel back to your patient support team.

What it is
What is included

What a patient
portal includes

What it involves

A patient portal holds personal and often health-related data about identifiable individuals, which makes the access and data protection model the central design constraint, not an add-on to a content-focused site.

What we deliver

Secure authentication appropriate to the sensitivity of the data, personalised content for the patient’s specific treatment stage, a channel to your patient support team, and data handling built to your data protection officer’s requirements.

Built to your data protection officer's rules

Data collection and retention rules come from your data protection officer, and we build the portal precisely to them, so the handling of sensitive data follows the standard your organisation already sets, not one we improvise.

case studies

Clients we've worked with

Real projects for industrial and pharmaceutical companies.
Patient portal track record
Track record

What our patient
portal builds have handled

The scope our patient portal builds have operated within.

+10
years building for regulated industries
+200
organisations have trusted Code
+1.500
documents migrated with their access permissions intact
+160
scientific papers in a single managed repository
Patient portals by need
Who needs it

What a patient portal
has to support by condition

The support need differs by treatment type. A patient portal starts from that need.

Build process
Four stages

How we build a
patient portal

Four stages. A patient portal is built with data protection requirements as the foundation.

DATA PROTECTION REQUIREMENTS
01
01

Set by your DPO before any design work

We start from what your data protection officer requires for the specific personal and health data the portal will hold, since this shapes authentication, hosting and retention decisions.

What we confirm

We confirm exactly what categories of personal and health data the portal will hold, how long that data can be retained, what consent needs to be captured and when, and how strong authentication needs to be given the sensitivity involved.

Result

Hosting, authentication and data handling are built to what your DPO actually requires for this specific data, rather than to a generic idea of what a healthcare portal should do.

PATIENT JOURNEY
02
02

What the patient needs at each stage

We map what a patient at different points in their treatment needs from the portal, so content and features are relevant rather than generic.

What we map

We map the distinct stages a patient moves through during treatment, what information and support each stage genuinely calls for, and how the portal should adapt its content so someone newly diagnosed sees something different from someone well into treatment.

Result

A patient opening the portal finds content that matches where they actually are in treatment, not a static set of pages written for an average user who does not exist.

BUILD
03
03

Secure, personalised, connected to support

We build the portal with authentication matched to the data sensitivity, personalised content, and a clear channel to your patient support team.

What we build

We build the portal itself, authentication matched to the sensitivity confirmed earlier, content areas that adapt to the patient's stage, and a direct channel through to your patient support team for when self-service is not enough.

Result

Patients can log in, find what applies to them, and reach real support when needed, with the security appropriate to the health data involved handled invisibly in the background.

LAUNCH
04
04

Live, compliant, documented

We launch with data protection documentation in place and hand over what your team needs to operate and maintain the portal.

What we handle

We handle launch, produce the data protection documentation your team needs on file, and train whoever will administer the portal so patient accounts and content can be managed correctly from day one.

Result

The portal is live, compliant, and your team is equipped to run it — nothing is left half-documented for someone to work out later.

Patient portal questions

What comes up when scoping a patient-facing portal.

Who is responsible for the patient data?

You remain data controller for all patient data held in the portal — we never take on that role. We build the platform to the requirements your data protection officer sets for retention, consent capture and access control, and act only as a processor executing those rules, not as the party deciding how patient data is used.

How strong does authentication need to be?

It scales directly with the sensitivity of the data being held, a decision your DPO makes for your organisation rather than a fixed default we apply everywhere. A portal holding detailed health data clearly warrants stronger authentication than one holding only order history and little else.

Can this connect to a support programme?

Yes, the patient portal can connect to a dedicated support programme when participants need more than the portal’s standard account features. See patient support programme website for that build, which typically needs its own enrolment flow, eligibility checks and consent handling distinct from the ongoing account management the portal itself covers.

Does this replace our medical information intake?

Not necessarily — the two serve different functions and often coexist. See medical information portal for structured handling of specific medical information requests, which is a distinct workflow from the ongoing patient account, order history and engagement content that a patient portal is built to manage over time.

Other things we build

Other pharmaceutical portals we build

A patient portal often sits alongside these other builds.

Patient portal

Start your
patient portal

Patients on an ongoing treatment who need a secure place to manage it. Tell us the treatment context and we will tell you how we would approach the patient portal.

contact us
Contact Form

Tell us
about your project

Tell us about your organization’s context and the planned scope of the project.
CODE GxP, as the data controller, will process your data in order to respond to the query and/or request you submit through this contact form. Privacy Policy.
Our site uses cookies to collect information about your device and browsing activity. We use this data to improve the site, ensure security and deliver personalized content. You can manage your cookie preferences by clicking here.
Accept cookies Configure Decline cookies
Basic cookie information
This website uses cookies and/or similar technologies that store and retrieve information when you browse. In general, these technologies can serve very different purposes, such as, for example, recognizing you as a user, obtaining information about your browsing habits or personalizing the way in which the content is displayed. The specific uses we make of these technologies are described below. By default, all cookies are disabled, except for technical ones, which are necessary for the website to function. If you wish to obtain more information or exercise your data protection rights, you can consult our Cookie Policy".
Accept cookies Configure
Technical cookies needed Always active
Technical cookies are strictly necessary for our website to work and for you to navigate through it. These types of cookies are those that, for example, allow us to identify you, give you access to certain restricted parts of the page if necessary, or remember different options or services already selected by you, such as your privacy preferences. Therefore, they are activated by default, your authorization is not necessary.Through the configuration of your browser, you can block or alert the presence of this type of cookies, although such blocking will affect the proper functioning of the different functionalities of our website.
Analytics cookies
Analytics cookies are used to analyse website behaviour anonymously. They help us measure activity and improve the website.
Confirm preferences
Title
Popupcontent
Contact us
CODE GxP, as the data controller, will process your data in order to respond to the query and/or request you submit through this contact form. Privacy Policy.
Aceptar