Healthcare compliance, without spreadsheets.
Fifteen modules with deterministic core and assistive AI for LGPD, security and governance in the healthcare sector. Auditable trail in every decision, human review where it matters.
Onboarding in 4 to 12 weeks, depending on operation scale.
Healthcare compliance today lives everywhere except in one place.
Treatment inventories in Excel sheets no one updates after the audit. DPIAs in Word files where the final version is calledDPIA_final_v3_FINAL_reviewed.docx. The weakness is not your compliance team's will; it is the absence of a single environment that consolidates all of this with an auditable trail.
One environment, three movements.
higeia replaces a patchwork of fragmented tools with a continuous governance regime, organized in three mutually reinforcing movements.
Movement 01 — Consolidate
Inventory, policies, third parties and controls in one place.
The full governance surface in a data model built for healthcare. Treatments inherit across units, policies link to controls, third parties connect to treatments.
Movement 02 — Automate with rigor
AI drafts. Humans decide.
Semi-structured extraction from contracts, first DPIA draft from the source treatment, policy summarization. The DPO reviews, edits and approves.
Movement 03 — Evidence
Append-only log, chained hash, audit in minutes.
Every control, approval and review creates an immutable record. Internal audits or ANPD requests receive a complete report in minutes.
Four pillars, fifteen modules, one data model.
higeia covers the full governance cycle the sector was missing. Every module speaks to the others through the same data model.
LGPD Compliance
LGPD Compliance
The regulatory core: treatment inventory with art. 11 legal basis, AI-assisted DPIA with human review, versioned policy library and third-party due diligence with deterministic scoring.
- Treatment Inventory
- Assisted DPIA
- Policy Library
- Third-Party Due Diligence
Information Security
Information Security
Technical and operational controls: controls engine by domain with cadence and evidence, asset inventory, pentest and vulnerability management, risk analysis and security incident tracking.
- Controls Engine
- Asset Inventory
- Pentests & Vulnerabilities
- Risk Analysis
- Security Incidents
Governance
Governance
Maturity and interoperability: certification and framework tracking (ISO 27001, NIST CSF, CIS Controls), healthcare interoperability mapping (RNDS, FHIR, TISS) and DPO portal for data subject requests.
- Certifications & Frameworks
- Healthcare Interoperability
- DPO Portal
Operational
Operational
Visibility and traceability: executive dashboard configurable by role, immutable audit trail with chained hashing and identity and access configuration.
- Executive Dashboard
- Audit Trail
- Configuration
Three packages, designed for scale and requirements.
Package
Standard
Entry for clinics and healthtechs. Fifteen modules across four pillars, up to 3 units, 20 users, AI assistive (Claude + Gemini), optional SSO, 8x5 support.
Package
Enterprise
For hospitals and multi-unit networks. Unlimited units and users, mandatory SSO, custom workflows, HIS connectors, DPO Portal, multi-provider LLM, 12x5 SLA.
Package
Private / Regulated
For operations under maximum isolation requirements. Dedicated VPC, BYO-LLM, BYO-KMS, sensitive connectors, 24x7.
Pricing on request. Each package is sized to the operation's scale, complexity and onboarding timeline.
Questions every committee asks.
No. higeia is administrative governance software, explicitly outside the scope of medical devices under RDC 657/2022.
As processors under art. 39 of LGPD. We never use client data to train AI models.
Yes, on Enterprise and Private plans. We support Azure OpenAI and BYO-LLM. All plans use Claude and Gemini as default providers.
No. higeia amplifies your team's work. Every material decision remains human and recorded.
Standard: 4-6 weeks. Enterprise: 8-12 weeks. Private/Regulated: 12-20 weeks.
higeia is a product of saude.dev.
higeia is developed by Sciereli HDC, a Brazilian consultancy specialized in healthcare data, privacy and information security, and is part of the saude.dev ecosystem. The team combines clinical experience, healthcare data science and law applied to LGPD and HIPAA. Sciereli's thesis is that the Brazilian healthcare sector needs governance tooling with sector knowledge built in. higeia is that thesis made product.
Ready to see higeia in action?
Write to higeia@saude.dev and we'll set up a demo tailored to your organization's context.