Skip to main content
Healthcare CareConnect Health (HealthTech SaaS) USA 5 months

HIPAA-Compliant SaaS Platform for US HealthTech Startup

CareConnect Health, a US-based HealthTech startup, had validated their concept — a care coordination platform connecting primary care physicians, specialists, and patients — with a MVP built on a no-code tool (Bubble.

-78%
Page load time (vs Bubble)
10,000+
Concurrent users supported
Full BAA
HIPAA compliance status
Zero
Migration downtime
$12M
Series A valuation post-launch
91.4%
AI care pathway accuracy

The Challenge

CareConnect Health, a US-based HealthTech startup, had validated their concept — a care coordination platform connecting primary care physicians, specialists, and patients — with a MVP built on a no-code tool (Bubble.io). The Bubble MVP had served for validation but was hitting serious performance walls at 500 concurrent users, couldn't be made HIPAA-compliant (required by their hospital system clients), and had no viable path to the AI-powered care pathway recommendations that were central to their Series A pitch. The founder needed a complete rebuild on a production-grade, HIPAA-compliant stack within 5 months — before their Series A raise — and the rebuild had to be done without disrupting the 1,200 existing platform users.

Our Solution

We built a new HIPAA-compliant platform from scratch on a modern stack with zero downtime migration from the Bubble MVP. The platform included a care coordination dashboard for physicians, a patient-facing mobile app, secure messaging between care team members, AI-powered care pathway recommendations using GPT-4o with clinical decision support guardrails, and a real-time care event notification system. All data handling was built to HIPAA technical safeguards, with Business Associate Agreements in place for all sub-processors.

Technical Architecture

Next.js 15 frontend with server-side rendering for SEO and performance

React Native mobile app (iOS + Android) for patient-facing features

Node.js/Express API with PostgreSQL on AWS RDS (encrypted at rest with AES-256)

HIPAA-compliant AWS infrastructure: VPC isolation, CloudTrail logging, WAF, GuardDuty

AWS HealthLake for FHIR-standard clinical data storage and exchange

OpenAI GPT-4o with custom clinical guardrails for care pathway AI (no ePHI sent to OpenAI)

Twilio for secure messaging with end-to-end encryption

Audit logging service with tamper-evident logs for all PHI access events

Technologies Used

Next.js 15React NativeTypeScriptNode.js / ExpressPostgreSQL (AWS RDS)AWS (EC2, ECS, RDS, S3, CloudTrail, WAF, GuardDuty)AWS HealthLake (FHIR)OpenAI GPT-4oTwilioStripeRedisTerraform

Project Timeline

1

Architecture and HIPAA Design

3 weeks
  • HIPAA technical safeguards requirements analysis
  • AWS infrastructure architecture for HIPAA compliance
  • Data flow mapping for PHI identification and protection
  • Sub-processor BAA negotiations (AWS, Twilio, Stripe)
  • FHIR data model design with AWS HealthLake
2

Core Platform Development

10 weeks
  • Authentication (SAML SSO for hospital system integration, MFA required)
  • Care coordination dashboard for physicians
  • Patient record management with FHIR-compliant data model
  • Secure messaging with end-to-end encryption
  • Role-based access control (physician, specialist, care coordinator, patient)
3

AI Care Pathways and Mobile

8 weeks
  • GPT-4o integration with de-identification layer (no ePHI sent to OpenAI)
  • Clinical decision support guardrails and confidence thresholds
  • React Native iOS and Android patient app
  • Push notifications for care events and appointments
  • Appointment scheduling with real-time provider availability
4

Migration and Launch

3 weeks
  • Shadow migration from Bubble.io (new platform mirrors live data)
  • Feature parity verification and gap closure
  • Penetration testing by third-party security firm
  • DNS cutover with zero-downtime deployment
  • Bubble.io decommission after 2-week parallel running

Canny Technologies delivered the impossible: a complete platform rebuild in 5 months, HIPAA-compliant, with zero downtime for our existing users. The new platform was the centrepiece of our Series A deck. We closed the round at $12M, and the lead investor specifically called out the technical infrastructure as a differentiator. We're now at 8,000 active users and the platform has never had a performance issue.

Dr. Sarah Chen, CEO and Co-Founder, CareConnect Health

Long-Term Impact & ROI

The rebuild enabled CareConnect to close a $12M Series A — impossible with a Bubble MVP. The platform now serves 8,000 active users across 14 hospital systems with 99.99% uptime. The AI care pathway recommendations have been validated in a pilot study showing 23% reduction in unnecessary specialist referrals. Full HIPAA compliance enabled the first enterprise hospital system contract worth $1.8M ARR.

Want Results Like This?

Every case study started with a free discovery call. Let's explore what's possible for your business.

Book Free Consultation