Platform
Exactly the right access, for every role
Configure authentication, roles and permissions for everyone who touches your connected medical device — patients, physicians, lab specialists, technicians and the device itself. Extra Horizon's user, group and access services give you a least-privilege model you configure instead of build.
Talk to us →Users and access
A login screen was the easy part
A connected medical device serves many people at once: the patient using it, the physician reviewing it, the lab processing samples, the technician keeping it running. Each needs a different view of the same data — and a guarantee that it stops there.
Health data demands least privilege
A patient should see their own measurements, a physician their own patients, and nobody more. Getting that wrong is not a bug report — it is a data breach.
Roles multiply faster than you plan
The prototype has patients and one admin. Then come clinics, labs, service technicians, study monitors and the devices themselves — each needing its own slice of the same data.
Auditors ask who can see what
Notified bodies, hospital security teams and DPOs all ask the same question. Access rules scattered across application code make it a hard one to answer.
Identity & access management
Configure the access model, don't build it
Extra Horizon brings authentication, user management and data-level access rules together in one model. You define who your users are and what they may do; the platform enforces it on every request.
Secure sign-in
OAuth 2 and OAuth 1 authentication through the SDK, with short-lived access tokens and refresh tokens that rotate every time they are used.
Multi-factor authentication
Add a second factor with an authenticator app, backed by recovery codes, for the users who handle the most sensitive data.
Single sign-on
Let clinicians sign in with their existing hospital or company account through OpenID Connect, instead of managing yet another password.
Roles and permissions
New users start with no permissions. Build roles such as admin, support or technician from granular permissions, and assign them only to the users who need them.
Groups for every care setting
Model a hospital, practice or study site as a group. Enlist its patients and staff, and give staff group roles that apply within that group only.
Access rules on the data itself
For every type of data, decide who may create, read, update and delete it: the creator, linked users, patients or staff of linked groups, or holders of an explicit permission.
One model, every role
Patient, physician, lab, technician — and the device itself
Users, groups, roles and data access rules combine into a single model, so everyone who touches your product gets a precisely scoped view of the same data.
Patient
Patient enlistment
Records and reviews their own measurements, and nothing else. An enlistment can carry an expiry date, so access ends when the prescription does.
Physician
Staff with a group role
Sees every patient enlisted in their practice or hospital group — and no patient outside it.
Lab specialist
Staff with a lab role
Adds and updates the lab results routed to their group, without being handed the rest of the patient record.
Technician
Global role
Manages the device registry and service state across the whole fleet, with no access to clinical data.
Device
Device identity
Authenticates with its own credentials to upload measurements and read its configuration — with a role scoped to exactly that.
Any other role
Your own definition
Nurse, caregiver, study monitor, distributor: define the role, attach its permissions and set the data rules. Access is configuration, not code you rewrite.
Built for regulated devices
Access control your auditor can follow
Who can see which patient's data is one of the first questions a notified body, a hospital security team or a DPO will ask. The answer should be a configuration you can show, not code you have to explain.
Cybersecurity requirements
IEC 81001-5-1 and FDA premarket cybersecurity guidance expect authentication and authorisation controls you can describe, justify and test. A declared role model is exactly that.
Data protection by design
GDPR Articles 25 and 32 ask for access limited to what each person needs. Scoped roles and expiring patient access put that principle into the configuration.
A qualified supplier
The platform underneath is ISO 13485, ISO 27001 and IEC 62304 certified and slots into your supplier controls — evidence you inherit, not produce.
Customer cases
What our customers say
"This partnership with Extra Horizon marks a significant milestone in our journey towards transforming stroke diagnostics. LVOCheck represents not just an innovation in technology, but a step forward in making advanced healthcare accessible and efficient."

Jean-Charles Sanchez
CEO, ABCDx
"Extra Horizon offers best-in-class medical cloud solutions through their deeply proven expertise in medical cloud. The company's professional expertise in developing customized solutions, leveraging an extensive backbone knowledge, makes it an ideal partner for this important undertaking."

Pierre Laboisse
Executive Vice President Global Sales and Marketing, ams AG
"The Extra Horizon platform has played a key role in helping FibriCheck meet the strict compliance issues that apply to medical software and has allowed FibriCheck to stay ahead of the curve."

Lars Grieten
CEO, Founder, FibriCheck
Let's talk about your access model!
Get in touch, explain what you want to build, or have us help you build, and we'll get back to you ASAP! →