Croatian startup WERXE is developing a platform to automate privacy and cybersecurity compliance in healthcare. But its experience shows why even technically sound healthtech products can struggle without access to hospitals, users, and the systems already embedded in clinical practice.
For a health technology startup, building the software may be only the beginning. The more difficult task is often persuading an overstretched hospital to make time for it.
That was the problem facing WERXE, a Croatian company developing PrivacyMark, a platform designed to help healthcare institutions create and maintain documentation required under the EU’s General Data Protection Regulation and Croatia’s Cybersecurity Act, which transposes the EU’s NIS2 directive.
The company understood the regulation. It also understood the technology. What it needed was direct access to the people who would eventually be expected to use the product.
“The reality is that nobody has time for a small startup with an idea,” says Filip Pravica of WERXE. “It is very difficult to open the doors of hospitals and reach key partners on your own.”
WERXE joined AI4Health.Cro not primarily in search of funding, but in search of validation. The company needed to know whether PrivacyMark was addressing a genuine operational problem and, equally important, whether the proposed solution reflected how healthcare institutions work.
That distinction matters. Healthcare has no shortage of digital products designed around what developers believe hospitals need. Far fewer are shaped around the fragmented processes, legacy systems, regulatory responsibilities and limited staff capacity found within the institutions themselves.
Testing before investing
Through AI4Health.Cro, WERXE used the programme’s Test Before Invest service to conduct an early proof-of-concept assessment.
The process gave the team detailed feedback that has already been incorporated into the PrivacyMark prototype. The company is now preparing to test the user experience and identify where additional functionality may be required.
WERXE also participated in specialised training intended to give technology companies a closer understanding of the healthcare sector, including its working practices and the digital tools already used in clinical and administrative settings.
However, Pravica says the programme’s most valuable contribution was not a general introduction to the health sector. It was the ability to identify institutions with a concrete interest in the product and to bring the relevant people into the same conversation.
“The team understood the needs of its consortium, recognised what we were offering and connected us very effectively with organisations where the interests overlapped,” he says.
The programme also provided administrative support, creating a structure within which the startup and participating institutions could test the concept without allowing the collaboration to become unmanageable.
For Pravica, this is an important distinction for other startups considering similar programmes. Networking alone has limited value unless companies arrive knowing what they need to learn.
“The value is not in the introduction itself,” he says. “It is in the input you manage to extract from it.”
From compliance theory to hospital practice
Through AI4Health.Cro, WERXE connected with two university hospitals and two consortium partners – Magdalena, Clinic for Cardiovascular Medicine, and the Croatian technology company IN2.
The experts enabled the PrivacyMark team to discuss the product with prospective users and test its assumptions against real processes. This helped move the platform from an internally developed concept towards a product being validated in the environment for which it is intended. Hospital staff, meanwhile, were allowed to influence the design before the system became fixed around assumptions that might later prove difficult or expensive to change.
The connection with IN2 was particularly significant. The company is one of Croatia’s major suppliers of hospital information systems, placing it close to the technical infrastructure with which a compliance product may ultimately need to coexist.
“Without understanding that technical reality, a compliance tool remains theoretical,” says Pravica.
Privacy and cybersecurity documentation may appear, from the outside, to be predominantly a legal or administrative problem. In practice, however, the quality of such documentation depends on an accurate understanding of information flows, access rights, software systems, responsibilities and risks across the institution.
A tool that cannot reflect the technology used by hospitals, or the way responsibilities are divided between clinical, administrative, legal and IT teams, risks adding another layer of paperwork rather than reducing it.
Pravica says WERXE would have been unlikely to establish collaborations at this level, and within the same timeframe, without the support of the innovation hub.
Healthcare products cannot be developed from the outside
The experience has reinforced one of the central difficulties facing healthtech founders: healthcare products cannot be developed convincingly in isolation from healthcare.
Regulatory compliance is demanding, but so is the everyday clinical and institutional reality into which a product must fit. A technically elegant platform may still fail if it creates additional work, misunderstands internal responsibilities or requires hospitals to reorganise established processes around the software.
“Healthcare is not a market you can build for from the outside,” Pravica says. “Both regulation and clinical reality are unforgiving. You need to validate against real processes as early as possible.”
That also means being realistic about the cost of participating in publicly supported innovation programmes.
Services such as Test Before Invest are frequently described as free for participating companies. In financial terms, this may be true: public funding covers many of the direct costs that would otherwise make such collaboration impossible.
But the description can obscure the investment required from everyone involved.
The startup contributes staff time, development resources and its own money. Hospital employees, technical experts and programme partners must also set aside time alongside their regular duties to review the product, attend meetings and provide feedback.
Pravica says funding secured through Croatia’s Ministry of Economy is essential because it supports the chain of organisations and individuals required to make the testing process credible.
“Without coverage of the basic costs, people would not be able to make time for these activities,” he says. “But what we received in return, access, feedback and faster development, was worth many times more to us than the financial support itself.”
Validation before investment
WERXE’s experience also challenges the assumption that innovation hubs are useful mainly for startups preparing to raise capital. Pravica argues that early access to healthcare institutions can improve a product’s maturity before a company approaches investors. This may ultimately lead to better investment opportunities because the startup can demonstrate that its product has been tested with prospective users and refined in response to evidence.
For companies working in regulated sectors, the ability to navigate established processes is itself a form of value. Startups do not have to identify every regulatory obligation independently, and they may gain better access to the information needed for technical, organisational and market analysis.
Pravica says the company has also attended the hub’s annual conference for two years and has seen how competitive programmes and financial awards can motivate early-stage teams.
But for WERXE, the decisive benefit was more fundamental: credibility.
The programme gave a small company a legitimate route into conversations with hospitals and established technology providers. It did not remove the need to build a reliable product, demonstrate expertise or invest significant time. It did, however, create conditions in which those efforts could be tested against the sector they were intended to serve.
Pravica says he would recommend the programme to teams developing digital or AI-based healthcare products whose principal obstacle is no longer the underlying technology.
“It is particularly relevant when the bottleneck is access to institutions and the credibility required to enter the conversation,” he says.
For healthtech companies, that may be the difference between developing a valid product and developing the one that a hospital can use.