What I do on healthcare projects
I work with founders and clinicians on requirements, make architecture decisions, own backlogs, contribute to implementation, and lead the team shipping the system. The work has included patient and clinic-admin applications, healthcare quality tools, hospital operations software, clinical content platforms, and AI-assisted intake workflows.
Most teams reach me when they need a practical engineering partner for HIPAA-aware app development, healthcare cloud architecture, secure integrations, or a technical lead who can turn compliance-sensitive requirements into a buildable delivery plan.
Healthcare software needs more than a framework choice. Teams must decide where protected health information can move, which vendors will sign a business associate agreement, how users and roles are separated, what gets audited, and how the product will integrate with existing clinical systems. Those decisions need to be part of architecture and delivery planning from the beginning.
When a healthcare team should reach out
The best fit is a team that already has a real workflow to build or untangle, but needs technical leadership before the architecture hardens in the wrong direction. That can mean a founder preparing an MVP, a clinical team turning manual work into software, or an agency/client team that needs healthcare-aware engineering support.
New product discovery
Turn a healthcare idea into a scoped delivery plan with users, risks, architecture, integrations, and milestones made explicit.
Existing product review
Review PHI flows, cloud boundaries, vendor choices, logs, analytics, AI services, and operational gaps before scaling or selling into healthcare.
Team leadership gap
Add a technical lead or fractional TPO who can speak with founders, clinicians, designers, engineers, and client stakeholders.
Agency-scale delivery
For larger builds, I can route the conversation through Technology Rivers while staying involved in discovery and architecture.
Services
HIPAA-aware application development
Web and mobile architecture designed to support a client's compliance program through controlled PHI handling, encryption, access controls, auditability, and BAA-covered infrastructure.
Healthcare integrations
API and data-flow planning for healthcare products, including current project work on a SMART on FHIR R4 integration, secure imports, document flows, and vendor boundaries.
Healthcare AI workflows
AI-assisted questionnaires, retrieval, transcription evaluation, and LLM selection with clinical oversight, explicit failure handling, and vendor constraints considered.
Technical discovery and architecture
Requirements workshops, platform and vendor evaluation, risk registers, phased estimates, migration planning, and delivery-ready technical scopes.
Selected healthcare work
AI-powered patient history platform
Patient and clinic-admin applications built around an AI-sequenced intake flow with more than 150 conditional questions, document capture, and planned EHR integration.
Cloud-agnostic healthcare migration
Mapped 36 managed AWS services to open-source alternatives and organized the work into an eight-phase, six-to-nine-month delivery blueprint.
Clinical content platform
Structured legacy clinical activities, paired-user conditional logic, and an English and Spanish content pipeline with safe fallback behavior.
Operational healthcare applications
Offline-first healthcare quality software, a real-time hospital bed-tracking product, and a healthcare employee portal with data visualization.
Working process
- Discover the clinical and product workflow. Identify users, decisions, data boundaries, integration points, and what must remain under human review.
- Map compliance-supporting controls. Establish PHI flows, access boundaries, audit requirements, vendor BAA status, retention needs, and operational ownership.
- Choose an architecture that fits delivery. Balance security, portability, team skill, time to market, and the cost of operating the system.
- Turn the architecture into milestones. Build a phased backlog with acceptance criteria, risks, dependencies, and testable outcomes.
- Lead implementation and iteration. Work with engineering, product, clinical, and client stakeholders until the product is operating reliably.
Before we talk
Do you certify HIPAA compliance?
No. I build the software, cloud, data, and delivery controls that support a client's HIPAA compliance program. Legal and compliance determinations should stay with qualified counsel and internal compliance owners.
Can we use AI or analytics?
Often, yes, but only after deciding what data reaches each vendor, whether a BAA is required and available, which features are covered, and how prompts, logs, events, traces, and exports are controlled.
Can you join an existing team?
Yes. I can work as a hands-on technical lead, fractional TPO, solution architect, or senior engineering partner alongside an internal or agency team.
What should I send first?
Send the workflow, current stack, integration needs, target timeline, and the biggest risk you already see. Please do not send PHI by email.
Practical healthcare architecture controls
Suspected PHI exposure response
Detect and contain the unsafe path, preserve evidence, assess technical scope, escalate decisions, and recover safely.
Secrets and encryption-key management
Store secrets, separate keys, rotate dependencies, control access, and recover encrypted healthcare workloads.
Tenant isolation and authorization
Enforce verified tenant context across data, storage, queues, caches, jobs, support access, and audit evidence.
Backup and disaster recovery
Define RPO and RTO, protect recovery points, separate administrative boundaries, and test complete restoration.
Centralized cloud audit logging
Collect control-plane, data-access, identity, and application evidence across cloud environments.
Secure CI/CD for healthcare apps
Use short-lived credentials, separate deployment roles, immutable artifacts, and auditable recovery paths.
Production data in lower environments
Use synthetic data, formal de-identification, controlled investigation, access limits, and expiry.
Amazon Macie for PHI in S3
Use sensitive-data discovery to find possible PHI in S3 and route findings into a controlled response process.
Configure Sentry without PHI
Keep error monitoring useful while reducing PHI exposure in events, replays, traces, alerts, and integrations.
Planning a healthcare product?
Send the workflow, current stack, integration needs, and target timeline. I can help with discovery, architecture, implementation, or technical leadership.
Review the HIPAA readiness checklist first
Please do not send patient information or other PHI by email. Technical architecture supports a compliance program but is not legal advice or a certification of HIPAA compliance.