Skip to main content
For patient and clinical apps

Fix patient and clinical apps without waiting on store review

When a fix only touches the web layer of your Capacitor app, ship it as an encrypted live update. Test it on a staging channel, roll it out in steps, and keep a record of every release for your compliance team.

BAA available for HIPAA programs
SOC 2 Type II and ISO 27001 (Enterprise plan)
Encrypted and signed bundles

Why care teams add a live update lane

Web-layer fixes should not wait on a new binary

The store-only fix path

A clinician reports a wrong label on a medication or intake screen. The fix is a few lines of JavaScript.

With a store-only process, you build a new binary, submit it, and wait. Store review is often 24–48 hours, sometimes much longer.

Even after approval, patients and staff still have to install the update before they see the fix.

Store review sits between you and the fix

Booking, intake, and reminder screens change often. Each web-layer fix waits for a new binary, store review, and user updates.

Your HIPAA review asks about data flows

Reviewers want to know what the updater sends, where it goes, and whether you can keep it in your own infrastructure.

Support needs to know which version is live

When a clinician reports an issue, your team has to tell which bundle and native version that device runs.

Every change needs a record

Compliance teams ask who shipped a change, when, and to which channel.

What Capgo gives healthcare teams

A controlled way to ship patient app fixes

Encrypted bundles, staged exposure, and updater settings your compliance owner can review.

Patch the web layer directly

Upload the fixed JavaScript, HTML, and CSS with the Capgo CLI. By default, devices download the bundle and apply it when the app moves to the background. Native code changes still go through the stores.

BAA and HIPAA review options

Capgo signs a BAA with healthcare customers. The updater does not send names, emails, or medical record numbers, and you can limit or move what it does send.

BAA and HIPAA options
  • EU endpoints for the updater traffic
  • Disable statistics or send them to your own endpoint
  • Licensed self-hosting on Enterprise

End-to-end encryption

Create a key pair with the CLI. Bundles are encrypted before upload and checked by the app before install. Capgo, storage providers, and CDNs only see ciphertext.

Encryption docs

Staged rollouts and automatic rollback

Send a bundle to a small share of devices, check install and failure data, then increase. Auto-pause can stop a rollout when failures rise, and a bundle that never calls notifyAppReady() is rolled back on the device.

First rollout step 5%
After checking failures 25%
Promoted to all devices 100%

How it works

How a healthcare team ships a fix with Capgo

Set up the updater once to match your review, then send each web-layer fix through staging and a staged production rollout. Every command below is from the Capgo docs.

  1. Configure the updater for your review

    Point all three plugin endpoints to the EU host, or set statsUrl to an empty string if hosted statistics are not allowed. Do not set a custom ID that maps to a patient. Ship this config in a store build.

    // capacitor.config.ts
    plugins: {
      CapacitorUpdater: {
        updateUrl: 'https://plugin.eu.capgo.app/updates',
        // use statsUrl: '' to disable hosted statistics
        statsUrl: 'https://plugin.eu.capgo.app/stats',
        channelUrl: 'https://plugin.eu.capgo.app/channel_self',
      },
    }
    BAA and HIPAA options
  2. Create your encryption key once

    Create a key pair, save the public key in your Capacitor config, and sync. Keep the private key in your CI secrets, never in the repo.

    npx @capgo/cli@latest key create
    npx @capgo/cli@latest key save --key ./.capgo_key_v2.pub
    npx cap sync
    Encryption docs
  3. Upload the fix to a staging channel

    Upload the encrypted bundle to the staging channel and check it on QA devices before it reaches patients.

    npx @capgo/cli@latest bundle upload --channel staging --key-v2
    Channels docs
  4. Roll out to production in steps

    Start with 5% of production devices. When install and failure data look right, promote the bundle to everyone. If not, roll the cohort back.

    npx @capgo/cli@latest bundle upload --channel production --key-v2 --rollout 5
    npx @capgo/cli@latest channel set production --rollout-promote
    # or, if something looks wrong
    npx @capgo/cli@latest channel set production --rollout-rollback
    Progressive rollouts docs

Traceability

Know which code runs on each device

Link each bundle to its commit, keep an audit log of who shipped it, and show the running version inside the app.

Link bundles to commits

Add a comment and a link to each bundle at upload time with --comment and --link, so you can trace a deployed bundle back to its source.

# Attach the commit to each bundle
npx @capgo/cli bundle upload \
  --comment "Fix dosage rounding ($(git rev-parse --short HEAD))" \
  --link "https://github.com/your-org/your-app/commit/$(git rev-parse HEAD)"

Show the running version in your app

Read the current bundle and native version with CapacitorUpdater.current() and show them on a settings or support screen, so staff can tell support what they run.

// Show version info to clinical staff
const info = await CapacitorUpdater.current()

// Display in app settings
console.log(info.bundle.version)  // "2.4.1"
console.log(info.native)          // Native app version

Security and compliance details

What you can share with your compliance owner and vendor review

BAA and HIPAA review options

Use EU endpoints, disable or self-host updater statistics, or move to licensed self-hosting. Your compliance owner decides which setup fits.

Capgo and HIPAA
SOC 2

SOC 2 Type II and ISO 27001 (Enterprise plan)

SOC 2 Type II, ISO 27001, and SSO are included on the Enterprise plan. The DPA and sub-processor list are public for your vendor review.

Open source you can audit

The updater plugin and the Capgo backend are open source on GitHub. Your team can read the code that runs on patient devices.

Apps built with Capacitor

Patient flows change faster than app review

Appointment, health-record, and benefits apps can update intake screens, booking instructions, provider messaging, and patient education without destabilizing the native shell.

HotDoc app icon MEDICAL

HotDoc

Appointment flow where booking instructions and intake copy can change often.

Google Play installs
2.1M
Store rating
4.6
Conecte SUS app icon MEDICAL

Conecte SUS

Health-record app with public guidance and document flows that must stay current.

Google Play installs
27.7M
Store rating
4.6
Odontoprev app icon MEDICAL

Odontoprev

Benefits app where provider, eligibility, and support journeys need careful patching.

Google Play installs
1.9M
Store rating
4.5

Customer proof

What teams shipping with Capgo say

5.0/5 rated by developer teams 9,400+ teams Read reviews
Portrait of Sergiu S

Sergiu S

Lead Developer, drivolino GmbH

“The Capgo Capacitor Updater plugin completely transformed how we ship updates. What used to take days now takes just minutes.”

Kapil

Founder, NuTriQ

“Being able to push production OTA updates instantly without waiting for full App Store review cycles has been a massive operational advantage.”

no-tone @ Webincode

Developer, Webincode

“Being able to add Device ID's to certain groups and push the changes to only certain groups is a life saver.”

FAQ

Questions healthcare teams ask

Short answers for engineering teams preparing a security or HIPAA review.

Is Capgo HIPAA compliant? Do you sign a BAA?

Capgo signs a Business Associate Agreement (BAA) with healthcare customers, and U.S. organizations already run Capgo in HIPAA-compliant programs. The updater data is minimal and device-scoped. If your review needs more control, you can also use EU endpoints, disable statistics, self-host the statistics endpoint, or move to licensed self-hosting.

BAA and HIPAA options

What data does the updater send to Capgo?

Operational data: app ID, a random app-scoped device ID, platform, bundle and native versions, OS version, plugin version, and update events. The IP address is used at transport level. It does not send names, emails, account IDs, or medical record numbers. Do not set a custom ID that maps to a patient or user.

Privacy and data collection

Can update data stay in the EU or in our own infrastructure?

Yes. Point the update, stats, and channel endpoints to plugin.eu.capgo.app to keep the plugin data path in Europe. You can also send statistics to your own endpoint. The Enterprise plan adds dedicated, hybrid, and licensed self-hosted options.

EU data location

What can a live update change in our app?

Only the web layer: JavaScript, HTML, CSS, and assets. Changes to native code, plugins, or permissions still need a new build through the App Store and Google Play.

What can ship as a live update

How do we show auditors what was shipped?

Audit logs record bundle uploads, channel changes, and member changes. Channel history lists every bundle that was live, and each bundle can carry a comment and a commit link. Roles limit who can upload bundles or change channels.

Audit logs

Give patient app fixes a faster path

Set up a staging channel, encrypted bundles, and the updater config your review needs on your own app during the trial.

14-day free trial, no credit card. A BAA, SOC 2 Type II, ISO 27001, SSO, and self-hosting options come with the Enterprise plan.