Who it's for
Digital health startups shipping a first product, and research programs that need a study app that will survive IRB review, a security questionnaire, and the app stores. The common thread is that the app has to be defensible, not just functional. We build it with a senior team only; nothing is offshored.
What's included
- Native iOS and Android — or a cross-platform stack when it is the right trade-off, chosen deliberately rather than by habit.
- HIPAA technical safeguards built in — encryption at rest and in transit, access control, audit logging, session handling, and a Business Associate Agreement for every vendor in the path.
- eConsent and identity — IRB-ready consent flows, identity verification, and account recovery that does not leak PHI.
- Sensor and wearable data — HealthKit, Health Connect, Bluetooth devices, and vendor APIs, with signal quality handled before it reaches analysis.
- Backend and EHR connectivity — FHIR-based integration and a data model a biostatistician or clinician can use.
- App-store and review readiness — privacy manifests, health-data disclosures, and the documentation reviewers ask for.
- Handoff — documented architecture, runbooks, and an optional transition plan to your own engineers.
How it runs
- Scope and architectureIntended use, data flows, compliance requirements, and the architecture decisions that are expensive to reverse, agreed in writing in the first two weeks.
- Build in sprintsSenior engineers ship weekly, with clinical and scientific review in the loop rather than after the fact.
- Verify and releaseSecurity review, test evidence, and app-store submission, with regulated-software documentation when the product needs it.
- Hand offYour team or ours runs it from here, with a written handoff either way.
Questions
Do you build on CardinalKit or another framework?
When it fits. Our founder created CardinalKit, an open-source foundation for regulated mobile health apps, and we use it or Apple ResearchKit where they shorten the path. We are not tied to any framework.
Can you take over an app that already exists?
Yes. We start with a short architecture and security review, then decide with you whether to extend, refactor, or rebuild. Most inherited apps are extendable.
How is HIPAA handled inside the app?
Encryption, access control, audit logging, session timeouts, and secure storage are designed in from the start, every third-party SDK is checked for PHI exposure, and we document the technical safeguards so your compliance file matches the code.
Related services
Scope it in 30 minutes
Book a scoping call and we'll name the smallest engagement that moves you forward. Most teams start with the fixed-scope Initial Audit.
Book a 30-min scoping callPrefer to write? Send a short note.