[ Specialised service ]

Medical and healthcare RAG with compliance

Semantic search on medical records and documentation · GDPR + medical secrecy

We design specialised RAG (Retrieval-Augmented Generation) for the healthcare sector: on clinical history, internal protocols, practice guidelines, medical-legal jurisprudence and scientific literature. With on-premise architecture, health data pseudonymisation and clinical validation at every iteration.

On-premise
standard · data never leaves the hospital
15 min → 30 s
search on clinical history
GDPR art. 9
special category · health data
[ Honest scope ]

When it fits · when it doesn't.

We publish this list to qualify together if we fit. If not, we save you time.

✓ FITS IF…
  • Hospitals, large clinics or specialised centres with extensive clinical documentation
  • Biomedical research querying large literature corpus + own data
  • Health insurers with medical claims documentation and protocols
  • Pharmaceutical companies with regulatory documentation (dossiers, clinical reports)
  • Hospital networks with protocols to consolidate and query uniformly
  • Long patient history (chronic, oncology) where the specialist wastes time reviewing
✗ DOESN'T FIT IF…
  • Small clinic with low volume (standard SaaS utility may be enough)
  • You need automated diagnosis (RAG doesn't diagnose; only retrieves and structures information for the clinician)
  • Totally unstructured or very low quality data (RAG amplifies corpus problems)
[ Process ]

How we do it.

01 Week 1-2

Corpus analysis + architecture

Documentary corpus audit (clinical history, protocols, guides, literature). On-premise architecture definition (vLLM/Ollama + pgvector/Qdrant + gateway). Initial DPIA.

02 Week 3-5

Ingestion pipeline + pseudonymisation

Ingestion pipeline with automatic health data pseudonymisation (names, IDs, specific dates when applicable). Specialised embeddings (BioBERT, ClinicalBERT or multilingual). Clinical-aware chunking.

03 Week 6-8

RAG + LLM + clinical validation

On-premise LLM model (Llama Med, Meditron 70B) or commercial in European cloud with contract. Clinical prompt design, guardrails, always-cite-source. Validation with doctors: 3 blind test rounds.

04 Week 9-10

Deployment + audit + training

Deployment in the centre's infrastructure. Access audit, complete logs. Clinical training for user team. Continuous improvement plan with structured feedback.

[ Tech stack ]

Technologies we use.

Meditron · Llama Med · Qwen 2.5 On-premise LLM specialised in clinical
BioBERT · ClinicalBERT · e5-large Medical domain embeddings
pgvector · Qdrant · Weaviate On-premise vector database
Presidio · custom NER PII/PHI pseudonymisation
HL7 FHIR Integration with clinical HIS
Ollama · vLLM · TGI Local inference server
[ Verisimilar cases ]

Figures · sector · result.

Invented cases with metrics consistent with our real ranges.

01
Private hospital · Madrid · 400 beds

RAG on chronic patients' clinical history

Specialists query aggregated history summarised by RAG before each consultation. All responses with source document citation. Increased 20% quality time with patient.

15 min → 30 s patient summary review
02
Biomedical research · IRB

RAG on corpus 12,000 papers + internal data

Semantic search on PubMed + internal repository. System proposes relevant articles, extracts methodologies and compares results. Human reviewer validates.

×3 productivity systematic reviews
03
Health insurer · complex claims

RAG on protocols + medical-legal jurisprudence

Medical team queries clinical protocols + scales + relevant jurisprudence. Reduces analysis time on complex cases without compromising clinical quality.

−50 % opinion analysis time
[ FAQ ]

Technical decision-maker questions.

How do you guarantee GDPR art. 9 with health data in RAG?

Health data is special category under GDPR art. 9. Our standard architecture for healthcare RAG: (1) the entire pipeline (ingestion, embeddings, vector DB, LLM) deploys on-premise at the hospital or in European cloud with Spain residency (Azure Spain, GCP Madrid, OVH), (2) data never leaves the centre's perimeter, (3) the responding LLM is local open-source (Meditron, Llama Med) or commercial with enterprise contract without retention.

Additionally: pseudonymisation of direct identifiers (name, ID, phone, address) before indexing, DPIA as mandatory project step, processing agreements with any provider touched by pipeline, exportable audit of each query.

Can the RAG diagnose or make clinical decisions?

No. And it shouldn't. A well-designed medical RAG is an information search and structuring tool for the clinician, not a decision system. All responses include source document citation so the doctor can verify and contrast.

Any system making automated clinical decisions falls under medical device category under European MDR regulation and requires specific certification. We don't work in that perimeter — we limit ourselves to clinical support tools.

Does it integrate with clinical HIS (Hospital Information Systems)?

Yes. We support integration via HL7 FHIR (international standard), FHIR STU3/R4 and R5. For proprietary HIS without native FHIR we work with periodic exports or provider's custom API.

Integration is designed in project phase 1 (initial audit). We confirm what information can be indexed, in what format and with what update frequency.

How long does it take and what investment is required?

Typical medical RAG project: 10-14 weeks, €60-150k depending on corpus complexity, integration requirements and volume. On-premise monthly operating cost: €800-3,000/month (GPU infra + maintenance + support).

Typical ROI: reduction of clinical review time + improvement in decision quality + capacity to absorb more patients without expanding team. In medium/large hospitals ROI materialises in 6-12 months.

Start with an acotated pilot?

Free 30-min diagnosis with architecture, timing and budget estimate for your specific case.