New · Specialised Track

Healthcare & Health Data QA — testing systems that touch patients

The NZ-localised guide to testing the systems that hold health information and shape clinical care.

Health software is where a defect is not an inconvenience — it is a result attached to the wrong patient, a referral that never arrives, or sensitive health information shown to someone who should never see it. This track teaches you to test clinical systems and patient safety, HL7 v2 and FHIR interoperability, PHI privacy under the Health Information Privacy Code 2020, regulated and medical-device software, and EHR integration across Te Whatu Ora — Health New Zealand and the wider sector.

This track covers

Clinical Systems & Patient Safety HL7 & FHIR Interoperability PHI & Health-Data Privacy Regulated & Medical-Device Software EHR Integration

NZ context

Grounded in the NZ health landscape — Te Whatu Ora — Health New Zealand, the National Health Index (NHI), Medsafe, the Health Information Privacy Code 2020, the Privacy Act 2020, ACC, and Hira, the national health information platform. Every example is a system you might actually test here.

Who this is for

Testers and Test Leads moving into health, clinical, or medtech work in NZ. Assumes ISTQB Foundation Level or equivalent. No clinical background required — the domain is taught from first principles.

The 5 lessons

From the bedside to the integration engine

Why this track

A domain where a defect can reach a patient

Most software fails softly. A broken button frustrates a user, who tries again. Health software can fail in ways that reach a real person. A lab result attached to the wrong National Health Index number puts one patient’s blood test in another patient’s record. A referral lost between two systems means a person waits months for care no one knows they need. A unit silently dropped from a medication dose changes the meaning of the number a clinician reads. The cost of a defect here is measured in safety and in trust.

The good news for a tester is that the domain has clear rules. A patient is identified by their NHI. A message either conforms to its structure or it does not. Health information may be accessed for a permitted purpose or it may not. Once you understand those rules, healthcare gives you something valuable — checkable acceptance criteria where patient safety and privacy are concrete, testable qualities rather than vague aspirations.

This track teaches those rules in the NZ context. By the end you will be able to test a clinical system for patient-safety risk, validate an HL7 v2 message and a FHIR resource against a conformance profile, test PHI handling under the Health Information Privacy Code 2020, reason about regulated and medical-device software, and test an EHR integration end to end — and write the evidence that shows you did.

Related

Other specialised tracks