Skip to main content
Industries · Healthcare and human services

Case management and AI for the people you serve — built for HIPAA and 42 CFR Part 2.

We build and operate case management, referral, and clinical-operations systems for healthcare and human-services organizations, with consent handling and audit trails designed into the data model, not bolted on.

What we build

Four practice areas, one delivery standard.

Systems that hold up in live service delivery and under audit, with sensitive data handled the way the rules require. Each area below is something we have built and run.

01

Agentic case management

Centralize client records, automate routine workflows, and surface next-best actions with assistive AI. Referral networks, consented data sharing, and outcome tracking are built in, so your professionals spend more time on direct client care.

02

Secure referral networks

Community-facing resource networks built for safety, vetting, and privacy. Role-based access, audit trails, and moderation tools for sensitive domains like recovery, behavioral health, and victim services.

03

Accountable clinical AI

Decision support, triage, and retrieval over clinical and program data, with human-in-the-loop approval on every action, explainability, and full audit logging. Assistive AI that does supervised work, not a chatbot bolted onto an EHR.

04

Secure cloud for PHI

Production infrastructure for regulated health data: zero-trust identity, encryption in transit and at rest, and deployment inside your cloud tenant or on-premise. No patient data is pooled across customers.

Engagement model

How we work with care organizations.

A four-phase path from a fragmented system of record to a workload running in your environment, with the compliance package built alongside the system. The same principals stay on through all four phases.

01

Discovery and compliance gap analysis

Data inventory, system-of-record review, and a written gap analysis against HIPAA, 42 CFR Part 2, and the NIST AI RMF, mapped to the data you actually handle.

02

Pilot scope and governance setup

A narrow first use case, an AI governance memo your leadership can sign, a model risk framework, and the artifact checklist your compliance officer and IRB will ask for.

03

Production build and compliance artifacts

Build and ship inside your cloud tenant or on-premise environment. BAAs, model cards, access and audit logs, and consent-handling documentation are produced alongside the system, not reconstructed for the auditor later.

04

Operations and model governance

Monitoring, drift detection, periodic validation, and a reporting cadence aligned to your audit obligations. We own the run-rate; you own the mission.

From the field

A platform we built and still run.

Human-services data network · anonymized

A statewide victim-services network that put 600+ agencies and nonprofits on one governed system, with consented data sharing across organizations that previously had no common record. An assistive AI layer screens incoming reports and vets new provider organizations, work that used to be manual.

De-identified by design: operational records stay inside the authorization boundary, and a separate analytics environment holds only de-identified data. Consent and chain of custody are tracked at every hand-off.

600+

Agencies & nonprofits

Sharing one consented record across the network.

How we deliver

Senior architects, from scope to production.

Senior architects, end to end

The architect in the room during discovery is the architect delivering in production. No handoffs, no translation layer between you and the people doing the work.

Time-to-production is the metric

Scoped production pilots that convert into multi-phase rollouts, measured in weeks of delivery rather than budget cycles. The pilot runs in your environment, not a sandbox.

Compliance from the first commit

HIPAA, 42 CFR Part 2, and consent handling are architected in from day one, so the auditor sees a system built for the rules rather than retrofitted to them.

Compliance posture

Named frameworks, named deliverables.

We architect to the rules your data falls under, whether that is a commercial cloud tenant, a state health environment, or an on-premise enclave. Every framework below maps to a specific artifact we hand you.

HIPAA

Privacy & Security Rules

Encryption at rest and in transit, BAAs with every subprocessor, minimum-necessary access controls, and audit logging retained per your retention policy.

42 CFR Part 2

Substance-use records

Consent-based disclosure tracking, segmentation of Part 2 data, and redisclosure controls built into the data model for recovery and behavioral-health programs.

HITECH Act

Breach notification & EHR

Breach-notification workflows, access and audit logs you can produce on demand, and an encryption posture that meets the safe-harbor standard.

NIST AI RMF 1.0

Govern · Map · Measure · Manage

A profile document per deployed model, bias and performance reporting on a fixed cadence, and human-in-the-loop approval on every clinical or eligibility decision.

NIST SP 800-53 / FedRAMP-aligned

State health & Medicaid

Moderate-baseline control implementation and inheritance-based authorization packages for state health authority and Medicaid workloads.

Section 508 / WCAG 2.1

Resident-facing intake

Accessibility conformance reporting (VPAT) delivered with every public-facing benefits, eligibility, or intake system.

FAQ

Questions your CIO and compliance officer will ask.

The ones we hear most on the first technical call.

Where does our patient data live during training and inference?
In your tenant, in your region. We deploy inside your Azure, AWS, or GCP environment under your IAM and run inference against private endpoints — no PHI leaves your cloud boundary. Training data stays inside the same tenant; we do not pool patient or client data across customers.
How do you handle 42 CFR Part 2 and consent for behavioral-health data?
Consent is tracked at the data model, not in a side spreadsheet. Part 2 records are segmented, every disclosure is logged against a consent record, and redisclosure controls are enforced in code. BAAs are in place with every subprocessor before a single record moves.
Can you deliver an audit-ready system, not just a model?
Yes. Every deployment ships with the compliance artifacts as deliverables — model cards, NIST AI RMF profiles, access and audit logs, a subprocessor and BAA list, and consent-handling documentation — written by the engineers who built the system, not backfilled by a separate compliance team six months later.
Can you deploy in our environment, including on-premise?
Yes. Our architecture is Kubernetes-native and infrastructure-as-code, designed to deploy across cloud, hybrid, or on-premise environments, with FIPS-validated cryptography and a zero-trust identity layer: mTLS, centralized identity, RBAC, and full audit trails.
Who owns the system, the data, and the documentation if we part ways?
You own all of it. Source code, model weights, pipelines, documentation, and runbooks are engagement deliverables that sit in your repos and your cloud account from week one. The exit clause in our agreement is concrete: structured knowledge transfer, no proprietary lock on artifacts, no holdback on access.

Talk to the people who will build it.

Thirty minutes, straight to an architect. We will walk through your constraints, the data you handle, and what a first pilot would actually look like.