← All work

Case study

HIPAA remote patient monitoring, built to raise a round

Primefocus Health, a US startup later acquired by LG NOVA, needed an investor-ready remote patient monitoring MVP on a fixed date, on HIPAA-eligible AWS, with no in-house engineering team.

Client Primefocus Health (LG NOVA)Period Jul 2024 to Sep 2025Role Engineering manager and architectClient title Technical Product Manager

Context

The platform monitors obesity-care patients in a US health network: vitals from the phone camera, weight from a connected scale, a patient app and a provider portal. Celloscope was the full engineering partner, from discovery and technical assessment through HIPAA-ready infrastructure, backend, both apps and a product roadmap. I worked as the VP of Engineering's right hand, running the engineering team and owning the architecture.

Constraint

The delivery date was tied to investor milestones and could not move. HIPAA compliance had to be demonstrable through an external scan, not promised. After launch the client would operate with a small team, so low maintenance mattered as much as features.

What I owned

Architecture and infrastructure design, vendor selection through proofs of concept, team management and sprint delivery in Jira, the handover documentation, and the on-call setup. I also translated between the client's product intent and the engineering plan, which is why the client called the role Technical Product Manager.

Architecture

Flutter appspatient · provider · web Binah.ai SDKcamera vitals AWS Cognito API gateway Spring Boot services8+ on EKS, 3 accounts RDS · ElastiCache FF4j flag servicecanary · A/B · dark launch Tenovi smart scaleor manual entry

Decisions and trade-offs

  • One Flutter codebase for Android, iOS and web. Three frontends became one for a client that would run with a small team. Clean architecture layers kept it testable.
  • Camera-based vitals over a webview SDK. After a proof of concept, Binah.ai's native rPPG SDK for heart rate and SpO2 beat the alternative on reliability and user experience.
  • Strategy pattern for weight capture. Tenovi scale or manual entry, switched at runtime, so hardware availability never blocked patient onboarding.
  • Multi-account AWS through Terraform and Terragrunt. Dev, staging and prod in separate accounts with their own VPCs and EKS clusters, state in S3 with DynamoDB locks, HIPAA-eligible services only: RDS, KMS, WAF, Shield, Secrets Manager, Transfer Family SFTP, CloudTrail and Config.
  • Blue-green on Kubernetes plus a central FF4j flag service. Zero-downtime releases became routine, with role and environment based flags for canary and dark launches.
  • Observability before launch, not after. Prometheus, Grafana, Loki and Zipkin, with alerts to Slack and PagerDuty and written P0/P1 playbooks for 24/7 support.

Outcome

  • On timeMVP delivered on the fixed date and on budget
  • 100%HIPAA compliance scan pass across critical, high and low
  • Fundedthe round closed on the MVP; the partnership continued as keep-the-lights-on support
  • 8+ · 2 · 3microservices, portals, environments

Stack

Java, Spring Boot, Flutter, AWS Amplify and Cognito, EKS, RDS, ECR, Route53, CloudFront, WAF, Shield, KMS, Secrets Manager, HashiCorp Vault, Transfer Family, Terraform, Terragrunt, GitLab CI/CD, Prometheus, Grafana, Loki, Zipkin, PagerDuty, Appium, Jira.