How We Built a HIPAA-Compliant Patient

This case study covers a patient portal we built for a mid-sized medical practice in Florida. Certain details have been modified to protect client confidentiality.

The Client

A network of primary care clinics in South Florida with 8 locations and approximately 12,000 active patients. They were managing patient intake, appointment scheduling, and medical records through a combination of paper forms, email, and an outdated EHR system that had no patient-facing portal.

The Problem

Patients couldn’t access their own medical records online. Appointment scheduling required a phone call. Staff was spending 3+ hours per day scanning and filing paper intake forms. And the existing system had zero HIPAA-compliant communication channels for patient-provider messaging.

A competitor clinic across the street had just launched a slick patient app — and they were losing patients because of it.

The Solution They Asked For

A web-based patient portal that would allow patients to:

  • Schedule and manage appointments online
  • Complete intake forms digitally before their visit
  • View their own medical records and lab results
  • Send secure messages to their care team
  • Pay balances online

And it all had to be HIPAA-compliant.

Week 1: Discovery and Architecture

We kicked off with a 2-day discovery sprint with the practice manager and IT coordinator. We mapped every workflow, identified every data touchpoint, and documented the specific HIPAA requirements that applied.

Key technical decisions made in Week 1:

  • Frontend: React with TypeScript — component-based UI that could scale
  • Backend: Node.js with Express, PostgreSQL database
  • Hosting: AWS with HIPAA-eligible services (EC2, RDS, S3)
  • Authentication: Auth0 with MFA enforced for all users
  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Audit logging: Every access to PHI (Protected Health Information) logged to an immutable CloudWatch log stream

Week 2-3: Core Development

We built the core patient and provider interfaces in parallel:

Patient-side features built:

  • Secure login with MFA
  • Appointment booking connected to the clinic’s scheduling system via API
  • Digital intake forms (replacing paper)
  • Lab results viewer with doctor notes
  • Secure messaging system (encrypted end-to-end)

Provider-side features built:

  • Patient message dashboard with 24-hour response SLA tracking
  • Intake form review and approval workflow
  • Lab result publishing with optional patient notes

Week 4: HIPAA Compliance Implementation

HIPAA compliance isn’t just about encryption — it’s a combination of technical safeguards, administrative policies, and physical controls. In Week 4, we focused on:

  • Completing the Business Associate Agreement (BAA) with AWS
  • Implementing automatic session timeouts (15 minutes of inactivity)
  • Setting up audit log reviews and alerts for unusual PHI access patterns
  • Documenting all data flows for the client’s HIPAA privacy officer
  • Configuring backup and disaster recovery (RPO: 1 hour, RTO: 4 hours)

Week 5: Testing and Staff Training

We ran three rounds of testing:

  • Security testing: Penetration test by a third-party firm, OWASP Top 10 vulnerability scan
  • Performance testing: Load tested for 500 concurrent users
  • User acceptance testing: 10 patients and 5 staff members tested all workflows

We also ran a 2-hour training session for clinic staff on the new system, created a video walkthrough for patients, and set up a helpdesk email for transition support.

Week 6: Deployment and Go-Live

We deployed the portal to production on a Tuesday morning — chosen because it was historically the clinic’s lowest-volume day. We had our team on standby for the first 72 hours.

Go-live results after the first week:

  • 340 patients registered in the first 7 days
  • Staff reported saving 2.5 hours/day on intake processing
  • 0 critical issues post-launch
  • 2 minor UI bugs resolved within 24 hours

The Outcome (3 Months Later)

  • 68% of appointments now booked online (previously 0%)
  • Paper intake forms eliminated across all 8 locations
  • Patient satisfaction scores increased by 22 points (NPS)
  • Staff saved an average of 12 hours/week across the network
  • Zero HIPAA incidents or data breaches since launch

What Made This Project Succeed in 6 Weeks

A 6-week timeline for a HIPAA-compliant portal sounds aggressive — and it is. Here’s what made it possible:

  • Clear scope from Day 1. We didn’t add features mid-project.
  • Client availability. The practice manager was available daily for quick decisions.
  • Pre-built HIPAA infrastructure. We had AWS HIPAA templates and policies ready from previous healthcare projects.
  • Fixed team, fixed scope. One PM, two developers, one QA engineer — no handoffs, no confusion.

If your healthcare organization needs a patient portal, telemedicine platform, or HIPAA-compliant web application, let’s talk →

Leave a Reply

Your email address will not be published.