A physician-founded platform needed to collect a patient's full medical history from every provider they'd seen and consolidate it into a summary their care team could actually use. Mindbowser built three role-scoped portals, a HIPAA-compliant fax pipeline, dynamic PDF generation, and a locked-down virtual desktop for staff handling PHI.
Talk to UsA physician-founded platform consolidating fragmented medical records into one shareable patient history for care teams.
Three role-scoped portals, a HIPAA-compliant fax pipeline, dynamic PDF generation, and a VPN-gated virtual desktop for PHI access.
AngularJS, Django REST Framework, AWS (including AWS Workspace), PostgreSQL, SRFax, Stripe
Delivered
Healthcare runs on systems that don't talk to each other, so the burden of communicating a complex medical history falls on the patient, and on the physicians who have to review it under time pressure.
Under 45 CFR § 164.524, patients are entitled to a copy of their own records within 30 days of requesting them. That right doesn't change how providers exchange data. Most still send it by fax, so patients end up doing the coordination work the regulation assumes the system would handle.
Time pressure on the physician side leads to missed diagnoses, duplicate testing, and readmissions that a fuller picture would have prevented. Solving that meant automating the record-chasing that patients and physicians were both stuck doing manually.
Collecting records from another provider still runs through fax. Any integration serving US healthcare providers had to be HIPAA compliant and reliable across hospitals, clinics, and physician offices with wildly inconsistent record formats.
Patient portal, staff access, and document storage all needed strict access control from day one, not bolted on after launch.
A HIPAA-compliant records platform built on AngularJS, Django REST Framework, AWS, PostgreSQL, SRFax, and Stripe.
We split the system into a Patient Portal, an Employee Portal for the platform's staff physicians, and a Super Admin Portal, each scoped tightly to what that role actually needed to do. The split was defined during an upfront design sprint with the client's product and domain team, before any production code was written.
We integrated a HIPAA-compliant, SSL-encrypted fax service to send and receive records from providers across the country. The service only supported US-based connections, so local development and testing had to run through a VPN to behave like a real US endpoint, a detail that would otherwise have gone undetected until staging.
Producing a fax-ready document filled with the correct patient data every time took a few attempts. Editable PDF templates were tried first, then overwriting text directly onto a static PDF. Neither held up cleanly across the volume of variation in patient data. Building the document in HTML and CSS, then converting the whole thing to PDF, proved both the most reliable and most efficient approach, and the one that shipped.
Staff physicians needed access to patient records without that access becoming a security liability. We built their portal access through AWS Workspace, a virtual desktop restricted by VPN, with file transfer from local machines to the virtual environment disabled and a whitelist controlling which external websites the environment could reach. Anything outside that whitelist throws an authorization error instead of loading.
Talk to us about what HIPAA-compliant records infrastructure looks like for your build, across fax pipelines, document generation, or locked-down PHI access.
Partner with us to design, build, and scale digital solutions that drive better outcomes.
Global Tech Teams LLC, 525 Washington Blvd, Industrious at Newport Tower, Jersey City, NJ 07310, United States.
Let’s discuss your goals, workflows, and next steps in a focused consultation call.