Your EHR, your clinical platform, your claims database — they hold patient data, and they are not moving. What you need is a way to give partner apps, research workflows, and internal product teams API access without rebuilding the security model your compliance team already approved.
FastCRUD connects to the database you have (SQL Server, Oracle, PostgreSQL, MySQL, MongoDB), introspects the schema, and exposes a documented REST and GraphQL API — with per-access-key row filters, IP allowlists, KMS-encrypted credentials, and a query-level audit log mapped to the HIPAA Security Rule § 164.312. BAA available on Business and Enterprise.
why healthcare teams call us
the ehr isn't moving
Whether you're on Epic, Cerner, Meditech, athenahealth, a custom SQL Server install, or an Oracle-backed claims platform — the database is the place truth lives. Migrating it is a multi-year program with patient safety implications.
phi is everywhere or nowhere
If a key can read the patients table, it can probably exfiltrate every chart you've ever produced. Coarse-grained access is the default; fine-grained is the work.
audit trails are required, not nice-to-have
HIPAA § 164.312(b) requires audit controls — the implementing rule, not the marketing language. Wiring exportable, query-level audit trails into a generic API gateway after the fact is brutal.
vendor risk reviews are slow
Every new SaaS vendor goes through 6–12 weeks of security review. If a tool can't produce a SOC 2 report, a BAA, sub-processor list, and pen test summary on request, it doesn't get bought.
how teams use it
phi-scoped api keys
Bind a key to a row filter (Provider.eq.acme-clinic, Location.eq.miami) so partner apps, billing tools, or research workflows only see the records they're allowed to.
soc 2 / hipaa evidence
The audit log is your evidence stream. Streamable to S3 or Splunk on Enterprise, exportable on Team. Captures the actor, IP, query, target rows, and outcome on every call.
research / analytics handoff
Expose a de-identified subset of your clinical schema as a separate FastCRUD project with its own access policy. Researchers get an API, your PHI stays in the production schema.
internal product velocity
Internal app teams stop blocking on backend cycles. They get a typed REST/GraphQL client, a scoped key, and an audit trail security can review without paging anyone.
compliance posture
HIPAA
BAA available on Business and Enterprise plans. Controls mapped to the HIPAA Security Rule (administrative, physical, technical) — full mapping available on request.
SOC 2
Type I available under NDA. Type II observation window underway; report expected Q4 2026. We won't pretend we have what we don't.
HITRUST
Not certified. Several of our underlying sub-processors (AWS) are. We work with HITRUST-certified customers but cannot map our own attestation onto theirs.
GDPR / EU residency
DPA available. France (Paris) data plane on Business today; other EU regions provisioned on Enterprise request. EU SCCs in place.
Encryption
Database credentials encrypted with AES-GCM via AWS KMS. TLS 1.2+ everywhere. BYOK on Enterprise.
The full security packet — sub-processors, pen test, BAA template, DPA, control mapping — is available under NDA. Email [email protected].
not a fit if
20-minute call. We'll cover the BAA, the audit log format, sub-processors, residency options, and the security packet. Bring your assessor.