Case management and AI for the people you serve — built for HIPAA and 42 CFR Part 2.
We build and operate case management, referral, and clinical-operations systems for healthcare and human-services organizations, with consent handling and audit trails designed into the data model, not bolted on.
What we build
Four practice areas, one delivery standard.
Systems that hold up in live service delivery and under audit, with sensitive data handled the way the rules require. Each area below is something we have built and run.
Agentic case management
Centralize client records, automate routine workflows, and surface next-best actions with assistive AI. Referral networks, consented data sharing, and outcome tracking are built in, so your professionals spend more time on direct client care.
Secure referral networks
Community-facing resource networks built for safety, vetting, and privacy. Role-based access, audit trails, and moderation tools for sensitive domains like recovery, behavioral health, and victim services.
Accountable clinical AI
Decision support, triage, and retrieval over clinical and program data, with human-in-the-loop approval on every action, explainability, and full audit logging. Assistive AI that does supervised work, not a chatbot bolted onto an EHR.
Secure cloud for PHI
Production infrastructure for regulated health data: zero-trust identity, encryption in transit and at rest, and deployment inside your cloud tenant or on-premise. No patient data is pooled across customers.
Engagement model
How we work with care organizations.
A four-phase path from a fragmented system of record to a workload running in your environment, with the compliance package built alongside the system. The same principals stay on through all four phases.
Discovery and compliance gap analysis
Data inventory, system-of-record review, and a written gap analysis against HIPAA, 42 CFR Part 2, and the NIST AI RMF, mapped to the data you actually handle.
Pilot scope and governance setup
A narrow first use case, an AI governance memo your leadership can sign, a model risk framework, and the artifact checklist your compliance officer and IRB will ask for.
Production build and compliance artifacts
Build and ship inside your cloud tenant or on-premise environment. BAAs, model cards, access and audit logs, and consent-handling documentation are produced alongside the system, not reconstructed for the auditor later.
Operations and model governance
Monitoring, drift detection, periodic validation, and a reporting cadence aligned to your audit obligations. We own the run-rate; you own the mission.
From the field
A platform we built and still run.
Human-services data network · anonymized
A statewide victim-services network that put 600+ agencies and nonprofits on one governed system, with consented data sharing across organizations that previously had no common record. An assistive AI layer screens incoming reports and vets new provider organizations, work that used to be manual.
De-identified by design: operational records stay inside the authorization boundary, and a separate analytics environment holds only de-identified data. Consent and chain of custody are tracked at every hand-off.
Agencies & nonprofits
Sharing one consented record across the network.
How we deliver
Senior architects, from scope to production.
Senior architects, end to end
The architect in the room during discovery is the architect delivering in production. No handoffs, no translation layer between you and the people doing the work.
Time-to-production is the metric
Scoped production pilots that convert into multi-phase rollouts, measured in weeks of delivery rather than budget cycles. The pilot runs in your environment, not a sandbox.
Compliance from the first commit
HIPAA, 42 CFR Part 2, and consent handling are architected in from day one, so the auditor sees a system built for the rules rather than retrofitted to them.
Compliance posture
Named frameworks, named deliverables.
We architect to the rules your data falls under, whether that is a commercial cloud tenant, a state health environment, or an on-premise enclave. Every framework below maps to a specific artifact we hand you.
HIPAA
Privacy & Security Rules
Encryption at rest and in transit, BAAs with every subprocessor, minimum-necessary access controls, and audit logging retained per your retention policy.
42 CFR Part 2
Substance-use records
Consent-based disclosure tracking, segmentation of Part 2 data, and redisclosure controls built into the data model for recovery and behavioral-health programs.
HITECH Act
Breach notification & EHR
Breach-notification workflows, access and audit logs you can produce on demand, and an encryption posture that meets the safe-harbor standard.
NIST AI RMF 1.0
Govern · Map · Measure · Manage
A profile document per deployed model, bias and performance reporting on a fixed cadence, and human-in-the-loop approval on every clinical or eligibility decision.
NIST SP 800-53 / FedRAMP-aligned
State health & Medicaid
Moderate-baseline control implementation and inheritance-based authorization packages for state health authority and Medicaid workloads.
Section 508 / WCAG 2.1
Resident-facing intake
Accessibility conformance reporting (VPAT) delivered with every public-facing benefits, eligibility, or intake system.
FAQ
Questions your CIO and compliance officer will ask.
The ones we hear most on the first technical call.
Where does our patient data live during training and inference?
How do you handle 42 CFR Part 2 and consent for behavioral-health data?
Can you deliver an audit-ready system, not just a model?
Can you deploy in our environment, including on-premise?
Who owns the system, the data, and the documentation if we part ways?
Talk to the people who will build it.
Thirty minutes, straight to an architect. We will walk through your constraints, the data you handle, and what a first pilot would actually look like.