Platform

Exactly the right access, for every role

Configure authentication, roles and permissions for everyone who touches your connected medical device — patients, physicians, lab specialists, technicians and the device itself. Extra Horizon's user, group and access services give you a least-privilege model you configure instead of build.

Talk to us →
An access policy giving patients, physicians, lab specialists, technicians and devices exactly the data access they need, secured by OAuth 2, MFA and single sign-on

Users and access

A login screen was the easy part

A connected medical device serves many people at once: the patient using it, the physician reviewing it, the lab processing samples, the technician keeping it running. Each needs a different view of the same data — and a guarantee that it stops there.

Health data demands least privilege

A patient should see their own measurements, a physician their own patients, and nobody more. Getting that wrong is not a bug report — it is a data breach.

Roles multiply faster than you plan

The prototype has patients and one admin. Then come clinics, labs, service technicians, study monitors and the devices themselves — each needing its own slice of the same data.

Auditors ask who can see what

Notified bodies, hospital security teams and DPOs all ask the same question. Access rules scattered across application code make it a hard one to answer.

Identity & access management

Configure the access model, don't build it

Extra Horizon brings authentication, user management and data-level access rules together in one model. You define who your users are and what they may do; the platform enforces it on every request.

Secure sign-in

OAuth 2 and OAuth 1 authentication through the SDK, with short-lived access tokens and refresh tokens that rotate every time they are used.

Multi-factor authentication

Add a second factor with an authenticator app, backed by recovery codes, for the users who handle the most sensitive data.

Single sign-on

Let clinicians sign in with their existing hospital or company account through OpenID Connect, instead of managing yet another password.

Roles and permissions

New users start with no permissions. Build roles such as admin, support or technician from granular permissions, and assign them only to the users who need them.

Groups for every care setting

Model a hospital, practice or study site as a group. Enlist its patients and staff, and give staff group roles that apply within that group only.

Access rules on the data itself

For every type of data, decide who may create, read, update and delete it: the creator, linked users, patients or staff of linked groups, or holders of an explicit permission.

Read the access management documentation →

One model, every role

Patient, physician, lab, technician — and the device itself

Users, groups, roles and data access rules combine into a single model, so everyone who touches your product gets a precisely scoped view of the same data.

Patient

Patient enlistment

Records and reviews their own measurements, and nothing else. An enlistment can carry an expiry date, so access ends when the prescription does.

Physician

Staff with a group role

Sees every patient enlisted in their practice or hospital group — and no patient outside it.

Lab specialist

Staff with a lab role

Adds and updates the lab results routed to their group, without being handed the rest of the patient record.

Technician

Global role

Manages the device registry and service state across the whole fleet, with no access to clinical data.

Device

Device identity

Authenticates with its own credentials to upload measurements and read its configuration — with a role scoped to exactly that.

Any other role

Your own definition

Nurse, caregiver, study monitor, distributor: define the role, attach its permissions and set the data rules. Access is configuration, not code you rewrite.

Built for regulated devices

Access control your auditor can follow

Who can see which patient's data is one of the first questions a notified body, a hospital security team or a DPO will ask. The answer should be a configuration you can show, not code you have to explain.

Cybersecurity requirements

IEC 81001-5-1 and FDA premarket cybersecurity guidance expect authentication and authorisation controls you can describe, justify and test. A declared role model is exactly that.

Data protection by design

GDPR Articles 25 and 32 ask for access limited to what each person needs. Scoped roles and expiring patient access put that principle into the configuration.

A qualified supplier

The platform underneath is ISO 13485, ISO 27001 and IEC 62304 certified and slots into your supplier controls — evidence you inherit, not produce.

All platform regulations & certifications →

Customer cases

What our customers say

ABCDx
In Vitro Diagnostics
"This partnership with Extra Horizon marks a significant milestone in our journey towards transforming stroke diagnostics. LVOCheck represents not just an innovation in technology, but a step forward in making advanced healthcare accessible and efficient."
Jean-Charles Sanchez

Jean-Charles Sanchez

CEO, ABCDx

Read case study →
ams AG
In Vitro Diagnostics
"Extra Horizon offers best-in-class medical cloud solutions through their deeply proven expertise in medical cloud. The company's professional expertise in developing customized solutions, leveraging an extensive backbone knowledge, makes it an ideal partner for this important undertaking."
Pierre Laboisse

Pierre Laboisse

Executive Vice President Global Sales and Marketing, ams AG

Read case study →
FibriCheck
Wearables & Home Monitoring
"The Extra Horizon platform has played a key role in helping FibriCheck meet the strict compliance issues that apply to medical software and has allowed FibriCheck to stay ahead of the curve."
Lars Grieten

Lars Grieten

CEO, Founder, FibriCheck

Read case study →

Let's talk about your access model!

Get in touch, explain what you want to build, or have us help you build, and we'll get back to you ASAP! →