The Constraints
-
HIPAA Compliance
Zero tolerance for data leakage; all data at rest and in transit required bank-grade encryption.
-
Accessibility (AA)
The user base included elderly patients with visual impairments, mandating high-contrast and screen-reader support.
-
Device Fragmentation
Patients accessed the portal from budget smartphones, tablets, and old desktops.
The Approach
Security-First Architecture
We implemented a "zero-trust" frontend where sensitive data is never cached locally on the device. Session management relies on secure, short-lived tokens.
Accessible Design System
Built a custom UI library tested against WCAG 2.1 AA standards. Font scaling and touch targets were optimized for senior users with reduced dexterity.
Seamless EHR Sync
Utilized FHIR (Fast Healthcare Interoperability Resources) standards to read/write directly to the hospital's existing Epic/Cerner systems without lag.
Progressive Web App
Deployed as a PWA to ensure performance on low-bandwidth connections and allow for critical offline access (e.g., appointment details).
The Outcome
Security breaches post-launch.
Patient trust score (surveyed).
Reduction in help-desk calls regarding "login issues".
WCAG 2.1 AA Compliance Audit Pass.