Software testing in healthcare: risks, regulation and method
Patient records, appointment booking, prescriptions, billing for care: in healthcare software, a defect does not just cost a support ticket. It can affect a patient's care or the confidentiality of their data.
- Identity is the first risk: a document attached to the wrong patient is a critical defect.
- Test data is never real data: fictitious data sets, generated and recreated for every run.
- Hosting is regulated: in France, health data hosted on behalf of a third party requires an HDS-certified host.
- Interoperability is tested on its own: exchanges between systems, formats and rejections.
Oussama Belakhdar, QA architect and founder of AutomationDataCamp, has worked on software testing projects in this industry. This page sums up what we check first. Our clients are not named.
Industry figures
Figures published by the organisations cited, not results of our own engagements.
What makes testing hard
- Journeys are long and depend on several roles (front desk, clinician, administrator), each with its own permissions.
- The data is sensitive: production cannot be copied into a test environment.
- The software exchanges data with other systems (laboratories, imaging, billing), often in batches or through asynchronous messages.
The scenarios we test first
- Creating, searching and merging patient records, including namesakes and duplicates.
- Role-based access: each profile sees only what it should, and every access is logged.
- Attaching documents and results to the right patient.
- Exchanges with third-party systems: valid message, malformed message, system unavailable, replay.
- Export, deletion and retention period of personal data.
The framework to know
Health data hosting (HDS, France). Article L.1111-8 of the French Public Health Code requires certification for anyone hosting personal health data on behalf of a third party. The certification framework is published by the French Digital Health Agency.
GDPR. Health data is a special category of personal data (Article 9): its processing is strictly regulated.
Medical devices. Software intended for medical use may fall under Regulation (EU) 2017/745, with its own verification and traceability requirements.
Our method
- Start from the risks. We rank features by the impact and likelihood of a defect, then test first what would cost the most.
- Automate what comes back in every release. API tests for rules and integrations, Playwright for user journeys, k6 for load, all wired into your CI.
- Controlled test data. Fictitious data sets, created for each run, never copied from production.
- AI with a review. An assistant speeds up writing scenarios and tests; every generated test is reviewed against our 7-question checklist. See our case study: from a PDF specification to Playwright tests.
Start with an audit
A QA audit reviews your application: a written assessment, a test strategy adapted to your industry and a costed action plan, in 5 days, for €1,000 excl. VAT as a fixed fee. Delivered remotely, in English or French, for companies in the US, the UK, Canada, Australia, Europe, the Gulf and the Nordics. The first scoping session is free.
See the QA audit at €1,000 excl. VAT
Frequently asked questions
Can healthcare software be tested with real data?
No. Tests use fictitious data, generated for the purpose and recreated for every run. Production data has no place in a test environment.
Which tests should be automated first in healthcare software?
High-risk journeys that are repeated in every release: identity and document attachment, role-based access, and exchanges with third-party systems. API tests are often more stable and faster than UI tests for these topics.
How much does a QA audit cost at AutomationDataCamp?
The QA audit and diagnosis costs €1,000 excl. VAT as a fixed fee, over 5 days: a written assessment, a test strategy and a costed action plan. The first scoping session is free.
Other industries: E-invoicing · Finance · Blockchain · Logistics · E-commerce · Document management. All industries.
Page signed by Oussama Belakhdar, written with the help of AI. Regulatory references link to the official sources above; they are not legal advice.
Related articles

AI & ML for test automation
What AI concretely changes in test automation.
Read more : AI and ML for test automation
Integrating Automation into CI/CD
Jenkins, GitLab CI, GitHub Actions — practical examples.
Read more : Integrating Automation into CI/CD