CYBERPORT APPLICATION — OCTOBER 2026
View Live Demo →
Cyberport Incubation Programme · Application · October 2026

AI Medical Concierge
with Blockchain Trust

Veridoc connects medical tourists with JCI-accredited hospitals across Southeast Asia and the Gulf via HIPAA-compliant digital consent forms verified on a blockchain ledger.

Veridoc Limited · Incorporated in Hong Kong · Programme: Cyberport Incubation Programme · Application: October 2026

Executive Summary

Veridoc Limited is an AI-powered cross-border medical concierge incorporated in Hong Kong. We connect medical tourists with JCI-accredited hospitals across Southeast Asia and the Gulf by eliminating the critical compliance fragmentation that blocks safe, verifiable care across jurisdictions. Every patient interaction — from AI triage through multilingual consent capture to post-treatment notarisation — is recorded on a blockchain ledger, giving agencies, hospitals, and regulators cryptographically auditable proof of compliance. We are applying to the Cyberport Incubation Programme (October 2026) to accelerate our expansion across the SEA and Gulf corridors.

6+
Target markets across SEA & Gulf
6
JCI-accredited hospital partners
5
Consent languages (EN/ZH/TH/MS/TR)
Live
Platform deployed on Render + Neon
Programme targeted: Cyberport Incubation Programme — the Hong Kong government's flagship deeptech incubator offering up to HK$500,000 in funding, co-working space in Cyberport, and a structured mentorship programme aligned with Hong Kong's healthcare innovation strategic priorities.

The Problem

🌐
Cross-Border Compliance Fragmentation
There is no portable consent standard across SEA and Gulf jurisdictions. Hospitals in Thailand, Malaysia, and Turkey each require consent documentation in formats that differ from Hong Kong and international norms. Agencies manually bridge these gaps — slowly and inconsistently.
🔐
Trust Gap Between Patients & Foreign Hospitals
Patients travelling abroad for high-value procedures — oncology, cardiac, orthopaedic — have no cryptographic proof that their consent was captured correctly and has not been altered. No verifiable audit trail means disputes are costly and compliance exposure is high.
📋
Coordination Overhead
Medical tourism agencies manage consent paperwork across 5+ languages and 3+ time zones. Without automation, a single patient case requires 8–12 manual document handling steps. This caps agency capacity and introduces HIPAA-class compliance risk at each step.

Our Solution

Veridoc is a platform for the full cross-border patient journey: AI-powered triage routes patients to the right specialists, digital consent capture handles 5 languages with automatic translation, every signed consent is hashed and written to an immutable blockchain ledger, and partner dashboards give agencies and hospitals real-time audit trails.

STEP 01
AI Triage
OpenAI-powered symptom routing to JCI hospitals
STEP 02
Consent Capture
Multilingual HIPAA-compliant digital consent
STEP 03
Blockchain Notarisation
Tamper-evident ledger records every consent
STEP 04
Partner Dashboard
Agencies & hospitals view audit trails live
AI
AI Triage Engine
OpenAI-powered symptom assessment routes patients to matching JCI hospitals. Rule-based fallback operates when AI is unavailable.
Language
Multilingual Consent
English, Chinese, Thai, Malay, Turkish. AI-powered translation with consent version control and legal review workflow.
Blockchain
Blockchain Notarisation
Sequential hash chain links every consent record. Tamper-evident ledger with cryptographic proof exportable on demand.
Audit
Compliance Audit Trail
HIPAA-class audit log on every PHI access. PII masking in logs, rate limiting, consent token authentication.

Market Opportunity

Southeast Asia's medical tourism market is projected to reach USD $12 billion by 2028, driven by growing outbound demand from China, South Korea, and the Middle East. The Gulf corridor (UAE, Saudi Arabia, Qatar) is growing at 18% YoY as regional healthcare capacity lags demand. Hong Kong sits at the intersection of both flows — a natural compliance and coordination hub for cross-border patient management.

$12B
SEA medical tourism TAM by 2028
18%
Gulf corridor YoY growth rate
~6,000
Addressable medical tourism agencies in SEA
🏢
Medical Tourism Agencies
Primary buyers. Subscription SaaS to automate compliance documentation across their patient caseloads. Key pain: manual consent management at scale.
🏥
JCI-Accredited Hospitals
Receive blockchain-verified patient pipelines with pre-completed consent records. Key pain: intake compliance risk from unverified foreign patient documentation.
🏢
Corporate Health Programmes
Corporates sending employees abroad for executive health checks and elective procedures. Key pain: duty-of-care documentation across jurisdictions.

Business Model

Revenue Streams
SaaS Subscription
Monthly per-agency and per-hospital tiers. Covers platform access, case management, partner dashboard, and compliance exports.
Per-Case Transaction Fee
Fee per completed patient case flowing through the platform (consent captured + hospital matched). Scales directly with agency volume.
Compliance Audit Export
On-demand blockchain certificate export and notarisation report for legal or regulatory submission.
Unit Economics (Targets)
Agency MRR targetHK$1,200–3,600/mo
Hospital MRR targetHK$2,400–6,000/mo
Per-case feeHK$80–200
Target gross margin72–80%
Break-even (customers)~40 agency accounts

Partner Tier Pricing

Tier Target Customer Monthly Price (HKD) Includes
Starter Small agencies (<50 cases/mo) HK$1,200 5 user seats, 50 cases/mo, EN/ZH consent, basic audit export
Growth Mid-size agencies (50–200 cases/mo) HK$3,600 15 seats, 200 cases/mo, 5-language consent, full audit trail, priority support
Enterprise JCI hospitals & large agencies Custom Unlimited seats & cases, custom integrations, dedicated compliance export, SLA

Traction & Product Status

Live Product veridoc.health ↗
June 2026
Hospital Directory & Provider Onboarding
JCI-accredited hospital registry wired (Bumrungrad, Bangkok Hospital, Gleneagles, AdventHealth, Medanta, Anadolu). Agency onboarding with PBKDF2-hashed PIN authentication (100k rounds, sha512). Hospital cards served in consent page triage results.
June 2026
Translation Engine & Document Repository
OpenAI-powered translation across EN/ZH/TH/MS/TR with language detection. R2 document repository with versioning, PHI access audit, and translate+approve workflow. Consent version control with legal review workflow.
June 2026
Patient Case Workflow (10-Step Journey)
patient_cases aggregation root with full state machine: intake → consenting → consented → matched → documents_collected → treatment_scheduled → in_treatment → post_care → notarised → archived. Case detail workspace UI with timeline view.
June 2026
SMTP Email Fallback Chain
5-provider fallback: Polsia proxy → Postmark → Resend → SMTP primary → SMTP fallback (SendGrid). Ensures consent reminder and alert delivery even under provider outage.
June 2026
HIPAA Compliance Audit Layer
Rate limiting, PHI access audit log, PII field masking in all logs. Consent token auth on POST /api/consents. Provider PIN hashing migrated from plaintext to PBKDF2. Pagination capped at 100 records (minimum necessary). Blockchain API stripped of patient name fields (data minimisation).
May 2026
Conversion Funnel & Analytics
Article-to-demo conversion funnel tracking. Onboarding funnel drop-off events. Weekly conversion digest (CEO email, Monday 8am UTC). Admin dashboard with funnel visualisation, subscriber analytics, demo request stats.

10-Step Patient Journey — Build State

Step Journey Stage Status
0Patient registration + case creationLive
1AI triage + JCI hospital matchingLive
2Multilingual consent captureLive
3Blockchain notarisation of consentLive
4Document repository + translationLive
5Treatment scheduling + hospital confirmationIn Progress
6In-treatment care coordinationPlanned
7Post-care follow-up & discharge docsPlanned
8Notarisation certificate exportIn Progress
9Case archival + compliance exportPlanned

Technology

Platform Stack
Runtime
Node.js · Express.js
Database
PostgreSQL via Neon (serverless)
Infrastructure
Render (Web Service + Crons)
AI
Polsia AI proxy (OpenAI-compatible)
Storage
Cloudflare R2 (document repository)
Email
Polsia proxy → Postmark → Resend → SMTP
AI
AI Triage Engine
OpenAI-powered symptom assessment maps patient conditions to appropriate JCI-accredited specialists. Rule-based fallback operates without AI. Triage session audit logged.
Blockchain
Hash Chain Ledger
Sequential consent records where each record hashes the prior. Tamper-evident: any modification breaks the chain. Blockchain records exportable as compliance certificates.
HIPAA
HIPAA-Compliant Audit Log
PHI access audit trail on every record read. PII field masking in all server logs and console output. Rate limiting on all patient-facing endpoints. Consent token auth.
NLP
Multi-Language Engine
OpenAI-powered translation across EN/ZH/TH/MS/TR with language detection. Consent version control tracks every translation revision through legal review workflow.
Security practices: PBKDF2 PIN hashing (100,000 rounds, sha512) for provider authentication · consent token authentication on all patient form submissions · rate limiting on all public-facing endpoints · data minimisation — patient name fields stripped from blockchain API responses · PII masking middleware on all log output.

Team

F
Carlos Chou
Chief Executive Officer
Hong Kong-based. Background in medical technology and cross-border healthcare operations. Prior experience in compliance automation and digital health platforms in Southeast Asia.
linkedin.com/in/carloschou ↗
C
[CTO]
Chief Technology Officer
Full-stack engineering background with expertise in healthcare data systems, blockchain integration, and HIPAA-class security architecture.
[To be completed before submission — full name, LinkedIn, specific prior roles]

Advisory Board

Medical Tourism Industry Advisor
Senior executive with 15+ years in medical tourism facilitation across SEA markets. Deep relationships with hospital procurement and agency operations teams.
[To be completed before submission]
HIPAA / Compliance Advisor
Healthcare compliance specialist with expertise in cross-border patient data regulations, HIPAA Business Associate Agreements, and Asian data protection frameworks.
[To be completed before submission]
Hong Kong Health Innovation Advisor
Connected to Hong Kong's HealthTech ecosystem; familiarity with Hong Kong's eHealth record infrastructure and the Hospital Authority's digital transformation initiatives.
[To be completed before submission]

Financials & Use of Funds

Current Funding Status
Stage: Pre-seed / Bootstrapped
Prior external capital: None
Current runway: [To be completed before submission]
Funding Ask
Cyberport grant: Up to HK$500,000
Programme duration: 24 months
Additional raise: Targeting seed round in parallel (USD $300K–500K) to extend SEA BD capacity

Use of Cyberport Funds (HK$500,000)

45%
Engineering
Expand hospital matching engine (real-time availability, procedure pricing). SMS/WhatsApp consent reminder integration. Automated notarisation certificate generation. API hardening for hospital EHR integrations.
35%
Business Development
SEA agency pipeline development (Thailand, Malaysia, Singapore). Gulf corridor partnership outreach (UAE, Saudi Arabia). JCI hospital onboarding in target markets. Conference attendance (IMTJ, AMSEA).
20%
Compliance & Legal
TH/MS/TR multi-language consent legal review and validation (currently a noted backlog blocker). BAA template library for HIPAA-covered entities. HK PDPO compliance review. Cross-border data transfer legal framework.

Supporting Documents

Blockchain audit records, compliance export certificates, case notarisation reports, and BAA documentation are available upon request. Contact the founding team to arrange a secure share.

Contact & Next Steps

Company Veridoc Limited (incorporated in Hong Kong)
Website veridoc.health
Founder Carlos Chou

Application Timeline

MilestoneTarget DateStatus
Application package finalised September 2026 In Progress
Team section completed (CEO / CTO bios) August 2026 Pending
Application submitted to Cyberport October 2026 Pending
Cyberport review & due diligence November–December 2026 Pending
Programme start (if accepted) Q1 2027 Pending