Case study · Healthcare
Treatment engagement, adherence and retention data that falls under HIPAA and 42 CFR Part 2, where a consent mistake is a legal event. The shared-spreadsheet answer was never available, so we built the platform with compliance engineered into the product rather than audited onto it.
The challenge
Drug courts, probation and parole services, recovery housing and case management teams needed shared visibility of treatment engagement, adherence and retention. The data falls under HIPAA and 42 CFR Part 2, where the consent state at the moment of access is the thing an auditor asks about, and the platform had to meet State of New Hampshire DHHS requirements.
Our approach
Compliance was treated as product scope, not a checklist at the end. Consent became a first-class record with its own event history; the audit trail was designed write-once and cryptographically chained before any feature was built on top of it; and the rules that programmes are measured against were modelled as data, with templates, so they could be added without a release.
The solution
Results
A multi-tenant platform in production for BPDS, LLC, with providers and administrators on one system and an audit console that shows authentication, user activity, data access and consent changes with chain integrity verified.
Stack
Practices
Talk to us
A senior engineer plus the relevant department lead joins the first call. No discovery gauntlet, no junior reps.