Strategy brief · Pilot: United States

The patient walks in.
The record is already there.

Carter Med is an offline-first, FHIR-native EHR designed so any participating provider — first across the U.S., then globally — can securely access and contribute to a patient's record, even when the internet is flaky, metered, or gone.

Offline-first
Local SQLite + delta sync. The clinic keeps working when the internet doesn't.
Portable by design
FHIR R4 / US Core. TEFCA, Carequality, CommonWell from day one.
HIPAA-grade
Granular consent, audit-by-default, encryption everywhere — including the cached record on a kiosk.
01 · Product vision

One record. Wherever the patient is.

Clinicians collaborating around a connected patient record

Vision

Carter Med is a cloud-connected, offline-first EHR that lets any participating clinician — starting in the U.S. and extending globally — securely access and contribute to a patient's longitudinal record. We don't replace hospital systems; we ride on top of TEFCA, Carequality, CommonWell, and FHIR US Core so the record actually moves.

Non-goals

  • — Not a billing/RCM platform. We integrate; we don't compete with Epic Resolute.
  • — Not a hospital-replacement EHR for large IDNs. MVP targets ambulatory, community, and rural settings.
  • — Not a national HIE. We use the ones that exist.
  • — Not a research/AI data lake. Secondary use comes later, with explicit consent.
Patients

Own and carry their history. Contribute symptoms, vitals, allergies offline.

Clinicians

Credentialed via NPI / state license / DEA. Document encounters, place orders.

Facilities

Edge node keeps the clinic running when the WAN drops.

NGOs / Labs

FHIR endpoints to publish results and consume public-health signals.

02 · Personas

Four users. One record between them.

Each persona is on the critical path of the marquee journey. Anyone we drop, the journey breaks.

Maya · 34 · patient
Maya · 34 · patient
Moves between Atlanta and rural Georgia for seasonal work
Today

Re-tells her asthma history at every new clinic. Carries paper printouts that get lost.

With Carter Med

Carries a QR card. New clinics see her meds and allergies before she sits down.

Dr. Patel · family medicine
Dr. Patel · family medicine
Two-provider clinic, intermittent fiber, mostly Medicaid panel
Today

Spends 20 min/visit faxing for outside records. Can't trust med lists.

With Carter Med

Pulls a TEFCA record in 3 seconds, charts offline when the line drops.

Community clinic IT lead
Community clinic IT lead
FQHC with 6 sites, no in-house dev team
Today

Epic is too expensive; current system has no portability.

With Carter Med

Deploys an edge node per site, syncs to cloud, integrates one lab feed.

Public health / NGO consumer
Public health / NGO consumer
State immunization registry, disaster response NGOs
Today

Manual CSV exports, weeks of lag, no consent provenance.

With Carter Med

FHIR endpoint with consented, real-time feeds tagged by source.

02 · Marquee journey

An unknown patient. A new clinic. No prior link.

This is the make-or-break flow. If this works, the product works.

  1. 01

    Patient walks in

    No prior connection to this clinic. They present a Carter Med QR card (or just their name + DOB).

  2. 02

    Identity resolved

    Local MPI matches probabilistically on demographics + QR token. If the WAN is up, query QHIN/Carequality for a federated match.

  3. 03

    Record retrieved

    FHIR bundles pulled from the patient's home network or cached on the edge node. Imaging on-demand, text-first.

  4. 04

    Encounter documented

    Clinician charts offline against US Core resources. Orders, problems, meds, allergies — all queued for sync.

  5. 05

    Synced when possible

    Delta sync over CRDT-friendly version vectors. Conflicts surfaced to clinician, never silently overwritten.

  6. 06

    Patient leaves with their record

    QR/wallet updated. Next provider — across town or across a border — can repeat the cycle.

03 · MVP & roadmap

Ruthless scope, two pilots, one discipline.

Each MVP item earns its place by being on the critical path of its pilot. US: Carter Med · TEFCA-ready. Burkina: Sankofa FOS · off-grid by construction. Everything else waits behind explicit acceptance criteria.

MVP · US (Carter Med) · 6–9 months
  • Patient PWA
    Account, demographics, allergies, meds, history; QR identity card; offline cache.
  • Clinician PWA
    Encounter note, problems, meds, allergies, orders (lab + Rx); offline-first.
  • FHIR core server
    US Core resources via Medplum or HAPI FHIR — adopt, don't build.
  • Edge clinic node
    Single-tenant local FHIR replica + sync agent (Docker, runs on a $400 mini-PC).
  • MPI + QR identity
    Probabilistic match (demographics) + patient-held UUID token.
  • Provider credentialing
    NPI lookup + state license + DEA verification at onboarding.
  • Consent ledger
    Patient-controlled share grants, default deny, audit trail.
  • TEFCA query stub
    One QHIN integration (treatment purpose) to retrieve external records.
MVP · Burkina (Sankofa FOS · Guéré) · 18 weeks · $120k fixed
Layers 1–3 · OpenMRS · DHIS2 · Sankofa OS
  • Patient PWA + QR card
    Offline-first PWA · French + local language · QR identity card for lookup at any Sankofa clinic.
  • Clinician PWA on rugged tablets
    Locked Android tablets · OpenMRS encounter writes via FHIR · works through Starlink blackouts.
  • OpenMRS clinical core
    Adopt OpenMRS as the record engine · Sankofa OS branded UI overlay.
  • AWS Outpost edge node
    Local OpenMRS replica + telemetry DB + sync agent · survives WAN loss indefinitely.
  • DHIS2 sync agent
    Aggregate indicators · notifiable disease push · alignment with BDHI national registries.
Pillar 01 · Starlink QoS routing
  • Starlink QoS routing
    Linux TC rules · Tier 1 clinical / Tier 2 admin / Tier 3 IoT.
Pillar 02 · Infrastructure telemetry
  • FOS telemetry dashboard
    Single-pane-of-glass · Tesla Powerwall · solar · generator ATS · Watergen AWG.
Pillar 03 · Event-driven diagnostics
  • i-STAT HL7 daemon
    MLLP listener on port 2575 · injects CHEM8+ / CG4+ / cTnI results directly into OpenMRS.
  • TytoCare webhook bridge
    JSON telemetry → FHIR · otoscope / stethoscope / tongue depressor capture.
Pillar 04 · AI Triage Kiosk with offline fallback
  • AI Triage Kiosk (TRG-301/302/303)
    Patient-facing PWA · LLM ESI scoring · local algorithmic fallback tree on grid loss.
Phase 2+ · both pilots
  • Imaging (DICOMweb viewer, deferred fetch)
  • ePrescribing — Surescripts (US) / national e-Rx (BF)
  • Surgical scheduling, anesthesia, oncology pathways
  • Multi-clinic regional rollout (BDHI Phase 3 national scaling)
  • Biometric (fingerprint) patient identity
  • openEHR archetype layer for clinical longevity
  • Secondary-use / research data marts
  • Bahmni-style admin/billing overlay for revenue-cycle clinics

Defense: imaging, ePrescribing, and full lab interface engines each carry months of integration and compliance work. Including any of them in either MVP guarantees we ship none of them well. We pilot read-only on records and basic charting first, with i-STAT + TytoCare as the diagnostic surface in Guéré.

04 · Hybrid open-source architecture

Three layers, four pillars, on purpose.

The most resilient architecture for BDHI is a hybrid open-source strategy — rather than bending a single software package into something it wasn't designed to be. Three layers carry the data; four engineering pillars carry the facility.

Sankofa FOS · Guéré pilot

An offline-first Facility Operating System for a clinic the grid forgot.

The Burkina Digital Health Initiative (BDHI) brief is unambiguous: 100% operational uptime for clinical care, regardless of municipal grid failures or internet blackouts. We've mapped our build to the four engineering pillars and the hybrid OSS stack already chosen by the Sankofa / BDHI team.

Design constraint, not a feature
100% clinical uptime — through grid loss, Starlink blackout, or both.
Off-gridEdge-computedOffline-firstSovereign

Guéré is the proving ground. The architecture assumes municipal power is unreliable, Starlink is metered and intermittent, and cold-chain logistics for cartridges and meds is non-trivial. The platform's job is to keep the clinic running anyway — and to look identical to staff whether the WAN is up or down.

Hybrid open-source stack · adopt, don't rebuild

We're aligned with the Sankofa / BDHI strategic call: no monolithic EHR. Three layers, each chosen for what it already does best in a low-resource, multi-facility African deployment.

  • Sovereign experience
    Sankofa OS
    FHIR-native microservices · branded UI · SAHEL / YILFU modules · advanced lab trackers · FOS telemetry dashboard.
  • Clinical foundation
    OpenMRS
    Multi-facility, offline-capable clinical record engine. Charting, orders, problem list, meds, encounters at the facility.
  • National intelligence
    DHIS2 + ENDOS
    Aggregate indicators, notifiable disease reporting, alignment with Burkina MoH national registries.
  • Edge compute
    AWS Outposts
    Local OpenMRS replica + sync agent + telemetry DB. Survives WAN loss indefinitely. Snowball Edge / mini-rack acceptable fallback.
The four engineering pillars
Pillar 01
Network QoS routing
Starlink bandwidth manager · AWS Outposts edge

Linux traffic-control rules on the local Outpost enforce hard QoS over Starlink. Tier 1: clinical (OpenMRS sync, HL7, FHIR). Tier 2: admin sync. Tier 3: IoT telemetry. Clinical payloads never compete with administrative or telemetry traffic during low-bandwidth windows.

Pillar 02
Infrastructure telemetry (pull/poll)
15-min cron · Tesla, solar, generator, AWG

Python microservices poll the off-grid hardware every 15 minutes against a unified infrastructure_telemetry SQL schema. Tesla Gateway via local Ethernet API + bearer token, generator ATS via Modbus TCP (holding registers 40001/40002), Watergen GEN-M Pro AWG via REST for humidity, filter saturation, and production volume.

Pillar 03
Event-driven clinical diagnostics (push)
Abbott i-STAT · TytoCare · OpenMRS injection

Persistent Python systemd daemon on port 2575 intercepts MLLP/HL7 payloads from the Abbott i-STAT 1 analyzer (CHEM8+, CG4+, cTnI cartridges). A secure webhook bridge translates TytoCare JSON telemetry — otoscope, stethoscope, tongue depressor — into standard FHIR resources and writes directly into OpenMRS with real-time provider alerts.

Pillar 04
AI triage kiosk + grid-free fallback
PWA · LLM middleware · ESI scoring

Patient-facing PWA on locked rugged tablets. Node.js middleware routes symptoms to a HIPAA-compliant LLM to generate Emergency Severity Index (ESI) scores. If Starlink drops, the kiosk transparently fails over to a local algorithmic decision tree so triage never halts. Results push into OpenMRS via the Clinical Decision Support integration (TRG-303).

What we provision · what BDHI provides
Frenchy / Sankofa OS deliversBDHI provides (or we procure as pass-through)
Sankofa OS edge image (Outpost AMI)AWS Outpost rack power & rack space
Telemetry Python services, HL7 daemon, webhook bridgesTesla Powerwall + solar inverters (already on site)
Triage PWA + LLM middleware + offline fallback treeGenerator + ATS controller (Modbus TCP reachable)
OpenMRS configuration + DHIS2 sync agentWatergen GEN-M Pro AWG (REST-reachable on LAN)
Rugged clinical tablets (procurement pass-through)Starlink terminal + local network switch
i-STAT MLLP listener + TytoCare webhook configAbbott i-STAT 1 + TytoPro workstation + refrigerated cartridge storage
Power
Tesla Gateway · solar inverter · generator ATS (Modbus TCP)
Water
Watergen GEN-M Pro · humidity · filter saturation · up to 1,000 L/day
Connectivity
Starlink primary · LTE / VSAT failover · QoS-policed
Compute
AWS Outpost · local OpenMRS replica · 15-min telemetry cron
Facility tiers

One platform, four facility realities.

Chris's on-the-ground observation in Burkina Faso: hospitals and clinics don't live on a single rung. Sankofa FOS deploys the same software stack across four tiers, with the hardware footprint, sync model, and training load tuned per tier. Guéré sits at Tier 4 — the hardest case, on purpose.

Tier 1
Mega hospital

Bobo-Dioulasso class · capital regional center

Connectivity
Fiber or commercial broadband · existing IT staff
Hardware
Existing server room · full rack space · UPS already deployed
Software footprint
Full Sankofa OS · all SGH module groups · multi-tenant OpenMRS + DHIS2 + Bahmni overlay
Sync model
Real-time bidirectional · sub-second to other Tier 1 nodes
Training load
Train-the-trainer · existing clinical informatics team takes over
Cost delta
Phase 2 · ~Guéré baseline + $20–40k (reused hardware, more module config)
Tier 2
Teaching / capital hospital

Paper-based today · 1950s/60s workflows · 1–3 per country

Connectivity
Limited broadband · intermittent Wi-Fi · spotty power
Hardware
Add Outpost or Snowball Edge + UPS + Starlink failover
Software footprint
Full OpenMRS clinical core · DHIS2 sync · Sankofa OS · selected specialty modules (LIS, OB, pharmacy)
Sync model
Hourly bulk + real-time clinical events · degrades gracefully on outage
Training load
On-site 2-week embed · paper-to-digital change-management included
Cost delta
Phase 2 · roughly Guéré baseline · main cost is digitization + training, not hardware
Tier 3
District outpatient clinic

5–10 staff · no Wi-Fi, no cloud · district health office

Connectivity
Starlink + LTE failover · no LAN beyond what we install
Hardware
Mini-rack edge node · 4–6 rugged tablets · UPS · Watergen + generator optional
Software footprint
OpenMRS clinical core · Triage Kiosk · selected diagnostics (i-STAT or TytoCare) · DHIS2 push
Sync model
Daily bulk + real-time triage events · queue-on-disconnect, replay on reconnect
Training load
1-week on-site for clinical lead + 2 nurses · runbooks left behind
Cost delta
Phase 2 · −$20k vs Guéré (smaller hardware footprint, fewer telemetry sources)
Tier 4
Village rural clinic · Guéré
Guéré pilot

Fully off-grid · no municipal power, no broadband · the pilot

Connectivity
Starlink primary · LTE backup · weeks-long blackouts assumed
Hardware
AWS Outpost or Snowball mini-rack · Tesla Powerwall + solar · generator + ATS · Watergen GEN-M Pro · Abbott i-STAT 1 · TytoPro workstation · 4 rugged tablets
Software footprint
OpenMRS clinical core · Sankofa OS branded UI · AI Triage Kiosk with grid-free fallback · full FOS telemetry dashboard · DHIS2 + ENDOS push
Sync model
Local-first writes · opportunistic bulk sync when Starlink is up · zero data loss across 72h disconnect
Training load
1-week train-the-trainer on-site · 30-day hypercare with 2 engineers on rotation
Cost delta
Phase 1 pilot · $120k fixed software + hardware pass-through · 18 weeks (see Engagement)
Multi-facility visibility

Bobo sees Guéré drop off the grid in real time.

Phase 2 capability previewed during the Guéré pilot. Chris asked for it in plain terms on the call: 'sitting in the mega hospital in Bobo-Dioulasso, the clinic in Guéré village five hours south goes offline — we can be proactive about the data, the downtime, the syncing and the recovery.' Phase 1 lights up the Guéré node; the fleet view is built and scoped separately as Tier 2/3 sites come online.

Nodes online
4
Degraded
1
Offline · local-only
1
Fleet uptime (30d)
98.7%
Sankofa FOS · facility fleet
Live status from every connected node · refreshes every 30s · degraded and offline nodes alert via SMS to the regional on-call
Live · 30s refresh
  • Bobo-Dioulasso General
    Tier 1 · Hauts-Bassins
    Online
    Fiber
    Last sync: live
    Uptime: 99.94%
    Queue
    14
  • Ouagadougou Teaching Hosp.
    Tier 2 · Centre
    Online
    Broadband
    Last sync: live
    Uptime: 99.71%
    Queue
    8
  • Banfora District Clinic
    Tier 3 · Cascades
    Degraded
    Starlink (low BW)
    Last sync: 12 min ago
    Uptime: 98.4%
    Queue
    3
  • Guéré Village Clinic
    Tier 4 · Sud-Ouest
    Offline · queueing locally
    Starlink down
    Last sync: 4h 22m ago
    Uptime: 94.1% (30d)
    Queue
    2
  • Tenkodogo Outpatient
    Tier 3 · Centre-Est
    Online
    LTE failover
    Last sync: 2 min ago
    Uptime: 99.2%
    Queue
    1
  • Kaya Maternal Clinic
    Tier 3 · Centre-Nord
    Online
    Starlink
    Last sync: live
    Uptime: 99.0%
    Queue
    5
What this enables
  • Regional supervisor sees the outage before the clinic calls in — and dispatches a tech with parts already loaded.
  • Patient records charted offline at Guéré are queued locally and replay automatically on reconnect — zero data loss.
  • DHIS2 / ENDOS national feeds keep flowing from healthy nodes even while one site is dark.
  • Telemetry alerts (low battery, low water filter, generator fuel) escalate to the on-call before they become outages.
EHR module mapping

~50 SGH modules. A Tier 4 pilot ships ~15.

The Sankofa Appendix lists ~50 modules across the full SGH ecosystem. For Guéré, ruthless scope: build only what the pillars require, adopt OpenMRS and DHIS2 where they already do the job, defer the rest behind explicit acceptance criteria. Tier 1/2 deployments unlock more of the matrix.

Build (Frenchy)Adopt · OpenMRSAdopt · DHIS2Sankofa OS layerPhase 2+
Core clinical & patient care
Ref · SGH Ambulatory & Inpatient
6 modules
  • SGH Ambulatory
    Adopt · OpenMRS
    OpenMRS encounter + visit module · Sankofa OS UI overlay
  • SGH Inpatient clinical documentation
    Adopt · OpenMRS
    OpenMRS forms + note templates
  • SGH Emergency Management
    Build (Frenchy)
    Driven by AI Triage Kiosk (ESI scoring + offline fallback)
  • SGH Surgical Scheduling
    Phase 2+
    Out of Guéré pilot · roadmap for Tier 1/2 facilities
  • SGH Anesthesia
    Phase 2+
    Out of pilot · single-OR or no-OR clinics only
  • SGH Infection Control
    Adopt · DHIS2
    Notifiable conditions push to DHIS2 / ENDOS
Specialties & ancillaries
Ref · Ancillary systems
7 modules
  • SGH Obstetrics
    Adopt · OpenMRS
    OpenMRS OB module + Sankofa SAHEL maternal tracker
  • SGH Oncology
    Phase 2+
    Phase 3 — needs imaging + chemo pathway
  • SGH Laboratory (LIS)
    Build (Frenchy)
    Abbott i-STAT HL7 daemon · MLLP listener on port 2575
  • SGH Radiology (RIS)
    Phase 2+
    DICOMweb viewer on-demand · Phase 2
  • SGH Cardiology
    Build (Frenchy)
    TytoCare stethoscope + cTnI cartridge ingestion
  • SGH Pharmacy
    Adopt · OpenMRS
    OpenMRS pharmacy module + cold-chain telemetry
  • SGH Ophthalmology / Orthopedics / Endoscopy / Dental / Nephrology / Transplant / Fertility
    Phase 2+
    Not in Guéré pilot scope
Revenue cycle & patient access
Ref · Registration & billing
5 modules
  • SGH Patient Registration
    Adopt · OpenMRS
    OpenMRS registration + Sankofa QR identity card
  • SGH Outpatient Scheduling
    Adopt · OpenMRS
    OpenMRS appointment module
  • SGH Bed Management (ADT)
    Adopt · OpenMRS
    OpenMRS bedside module · light-weight for Guéré
  • SGH Hospital / Professional Billing
    Phase 2+
    BDHI grant-funded pilot · billing deferred
  • SGH Managed Care
    Phase 2+
    Not applicable to public clinic pilot
Patient engagement & CRM
Ref · Portal & CRM
3 modules
  • SGH Patient Portal / PHR
    Build (Frenchy)
    Offline PWA · QR identity card · French + local language
  • SGH Kiosk
    Build (Frenchy)
    AI Triage Kiosk (TRG-301) · grid-free fallback (TRG-302/303)
  • SGH Healthcare CRM
    Phase 2+
    Phase 2
Population health & care coordination
Ref · Health tracking
3 modules
  • SGH Population Health
    Adopt · DHIS2
    DHIS2 aggregate indicators · regional rollups
  • SGH Care Coordination (SDOH)
    Build (Frenchy)
    Sankofa YILFU module · household-level context
  • SGH Home Health / Hospice
    Phase 2+
    Phase 3 community health worker module
Interoperability & integration
Ref · Integration engines
4 modules
  • SGH Integration Engine
    Build (Frenchy)
    FHIR microservices + HL7 v2 + Modbus/REST telemetry
  • SGH Health Information Exchange
    Adopt · DHIS2
    DHIS2 / ENDOS national exchange
  • SGH Community Provider Portal
    Adopt · OpenMRS
    OpenMRS provider directory
  • SGH Payer Portal
    Phase 2+
    Not applicable to pilot
Data, analytics & reporting
Ref · Analytics engines
4 modules
  • SGH Enterprise Dashboards
    Build (Frenchy)
    Single-pane-of-glass FOS dashboard + facility-network view
  • SGH Enterprise Data Warehouse
    Adopt · DHIS2
    DHIS2 + Postgres warehouse on Outpost
  • SGH Operational Reporting
    Build (Frenchy)
    Node.js /api/telemetry/latest + clinical KPIs
  • SGH Visual Data Discovery
    Phase 2+
    Metabase / Superset overlay · Phase 2
System architecture & mobile
Ref · Database, UI & portable solutions
5 modules
  • SGH Core DBMS
    Adopt · OpenMRS
    OpenMRS Postgres + unified infrastructure_telemetry schema
  • SGH Universal Frontend (GUI)
    Sankofa OS layer
    Sankofa OS branded React shell · Bahmni-style overlay
  • SGH Web-based Client
    Build (Frenchy)
    Browser PWA · offline-first
  • SGH Mobile Physician App (tablet / phone)
    Build (Frenchy)
    PWA on rugged Android tablets · locked-down kiosk mode
  • SGH Mobile Clinical Staff App
    Build (Frenchy)
    Same PWA · role-scoped views
04 · Using the demo

Five roles. One walk-through each.

The demo is wired for every user type. Sign up as each role, see their profile, upload a document, check the calendar, browse their views. Mock data, no PHI.

Patient

Owns the record. Carries it everywhere.
Sign-up flow
  • Verify identity with email + phone OTP (ID.me / Login.gov in prod).
  • Generate a portable QR card + Apple/Google Wallet pass.
  • Grant first consents (treatment, lab, public-health).
Profile page

Demographics, allergies, meds, problem list, immunizations — pulled from every connected source and de-duplicated.

Document uploads

Upload prior records (PDFs, CCDAs, lab images). OCR + FHIR-mapping queued; raw file kept for provenance.

Calendar

Upcoming visits across clinics, lab draws, refills due. Add a visit manually when offline.

Views in this role
Record timelineConsents & sharingDocumentsQR / Wallet card

Clinician

Charts in 3 clicks. Works offline.
Sign-up flow
  • NPI lookup + state license + DEA verification.
  • Attach to a facility (or request one).
  • Choose specialty templates (FM, peds, urgent care).
Profile page

Provider profile (NPI, taxonomy, licenses, DEA) — surfaced to patients before they consent.

Document uploads

Drop in encounter notes, attach scanned forms, sign orders. All resources US Core compliant.

Calendar

Today's panel with offline indicator, CDS alerts inline, room status, and walk-in slots.

Views in this role
Today's panelPatient chartOrders & e-RxCDS HooksSync queue

Facility / IT

Edge nodes, sync health, credentialing.
Sign-up flow
  • Register clinic NPI + tax ID + sites.
  • Provision an edge node per location (one-line installer).
  • Invite clinicians; bulk-import via CSV.
Profile page

Facility profile: addresses, hours, services, accepted insurance, TEFCA participation.

Document uploads

Policies, BAAs, OCR-uploaded credentialing PDFs, lab interface configs.

Calendar

Site-wide schedule grid across providers and rooms; on-call rotations; downtime windows.

Views in this role
Edge node healthSync conflictsCredentialingConnectorsBulk export ($export)

Public health / NGO

Consented signals. Never raw PHI.
Sign-up flow
  • Register agency with NPI / DUNS + jurisdiction.
  • Scope the read: immunizations, ILI, reportable conditions.
  • Sign DUA — automatic consent enforcement.
Profile page

Agency profile + scoped data-use agreement on file, visible to every contributing patient.

Document uploads

Outbreak briefs, DUAs, exported aggregate reports (CSV / FHIR Bundle).

Calendar

Reporting cadence (daily ILI, weekly imms), DUA renewal dates, scheduled exports.

Views in this role
Coverage mapSignal feedReporting endpointsAudit log

Super admin (Carter Med)

Tenants, incidents, networks, billing.
Sign-up flow
  • Invite-only. Hardware key (WebAuthn) required.
  • Role-scoped: support, SRE, compliance, finance.
  • Every action audited; break-glass requires justification.
Profile page

Internal staff profile with role, on-call status, last access, last key rotation.

Document uploads

Tenant contracts, BAAs, SOC2 evidence, post-mortems, key-rotation logs.

Calendar

On-call schedule, release windows, audit reviews, customer business reviews.

Views in this role
Tenants & MRRIncidentsNetwork statusAudit logFeature flags
How to run the full tour
  1. Start as Patient — generate a QR, upload a prior record, grant consent to "Westside Clinic".
  2. Switch to Clinician — scan the same patient, chart an encounter offline, sign an e-Rx.
  3. Switch to Facility — watch the sync queue drain and resolve a merge conflict.
  4. Switch to Public health — see the immunization count tick up under the consented scope.
  5. Switch to Super admin — open the audit log; every step above is there.
Guided journeys
04 · Technical architecture

Offline is the default state.

Built so a clinic with one bar of LTE feels the same as one on fiber — just slower to sync.

┌─────────────────────────────────────────────────────────────────────┐
│  PATIENT DEVICE (PWA)         │   CLINICIAN DEVICE (PWA)            │
│  ─ IndexedDB / SQLite WASM    │   ─ IndexedDB / SQLite WASM         │
│  ─ Service worker, queue      │   ─ Service worker, queue           │
│  ─ Local FHIR cache           │   ─ Local FHIR cache + drafts       │
└────────────┬──────────────────┴──────────────┬──────────────────────┘
             │                                  │
             │  ⇅  Delta sync (CRDT / vector)   │  ⇅  USB / Wi-Fi / WAN
             ▼                                  ▼
        ┌────────────────────────────────────────────┐
        │  CLINIC EDGE NODE  (Docker, $400 mini-PC)  │
        │  ─ Local FHIR replica (HAPI / Medplum)     │
        │  ─ Sync agent, conflict log                │
        │  ─ Cached value sets (SNOMED/LOINC/RxNorm) │
        └────────────────────┬───────────────────────┘
                             │  ⇅  TLS, OAuth2/SMART
                             ▼
        ┌────────────────────────────────────────────┐
        │  CARTER MED CLOUD  (US region · HIPAA)     │
        │  ─ FHIR R4 / US Core (Medplum or HAPI)     │
        │  ─ MPI · Consent ledger · Audit            │
        │  ─ Identity (SMART on FHIR, OIDC)          │
        └──┬───────────────┬──────────────┬──────────┘
           ▼               ▼              ▼
       TEFCA/QHIN     Carequality     CommonWell
       (treatment)    (broker)        (broker)
Sync

Conflict-aware delta sync

Per-resource version vectors with CRDT semantics for append-only resources (observations, notes). Conflicts on mutable resources (problem list, meds) are surfaced to a clinician — never silently merged.

Payload

Text-first, image-last

Bundles gzip + CBOR over the wire. Large binaries (DICOM, PDFs) are referenced, not embedded; fetched on tap. Value sets pre-cached on the edge node.

Degradation

Graceful tiers

Tier 1: rich PWA. Tier 2: stripped low-end Android view. Tier 3: SMS/USSD lookup ("CMED LOOKUP <token>"). Tier 4: physical sneakernet via signed USB bundles.

05 · Interoperability

We ride the rails that already exist.

In the US, that's TEFCA. In Burkina, it's OpenMRS + DHIS2 + ENDOS. Building a new national network from scratch is a 10-year, $100M project. We aren't doing that — in either country.

Standard / networkRoleBuild · adopt · integrate
FHIR R4 + US Core / USCDIPrimary API and data model for the US pilot. Sankofa OS microservices speak FHIR everywhere.Adopt
OpenMRSClinical record engine for the Sankofa FOS pilot. Multi-facility, offline-capable, low-resource native.Adopt (Burkina pilot)
DHIS2Aggregate national health intelligence layer. Indicators, dashboards, regional rollups.Adopt (Burkina pilot)
BahmniUI/UX overlay over OpenMRS for charting + registration where useful. Branded by Sankofa OS.Adopt (Burkina pilot)
ENDOS · Burkina national registryNotifiable conditions + national identifier sync per BDHI compliance posture.Integrate (Burkina pilot)
WHO SMART Guidelines + ICD-11Computable clinical guidelines + global terminology roadmap.Adopt (Burkina pilot)
HL7 v2 (MLLP)Ingest legacy ADT/ORM/ORU feeds + Abbott i-STAT diagnostics on port 2575.Adopt
DICOMwebImaging fetch on-demand; never embedded in encounter bundles.Adopt (Phase 2)
TEFCA / QHINTreatment-purpose record retrieval at national scale in the US pilot.Integrate (US pilot)
Carequality / CommonWellBrokered record location and exchange — most existing US EHRs are on these.Integrate (US pilot)
SMART on FHIR + OAuth2/OIDCProvider auth, app launch, scoped access.Adopt
ICD-10-CM / SNOMED CT / LOINC / RxNormCoded terminologies, offline-cached value sets.License + cache
openEHRArchetype-based clinical modeling for long-term semantic stability.Roadmap

US build vs. adopt

Adopt Medplum as the FHIR backend for the U.S. MVP. TypeScript-native, US-Core conformant, MIT-licensed, SMART on FHIR built in. Fall back to HAPI FHIR (Java) if Medplum's hosted constraints conflict with our edge-node story.

Burkina build vs. adopt

Adopt OpenMRS as the clinical record engine and DHIS2 as the aggregate layer per the BDHI strategy. Sankofa OS sits above as FHIR-native microservices — branded UI, telemetry dashboard, AI triage, i-STAT / TytoCare ingestion. We don't rebuild what the global health community already maintains.

06 · The hardest problem

Patient identity without a national ID.

The U.S. legally bans a national patient identifier. Probabilistic matching isn't a fallback — it's the design.

A four-layer identity stack

  1. 1 · Patient-held token (QR card or wallet pass)

    A Carter Med UUID signed by our root. Scannable offline. Works on paper. Re-issuable but the prior token is revoked, not orphaned.

  2. 2 · Master Patient Index with probabilistic matching

    Demographics-based (name, DOB, sex, address history, last-4 SSN where consented). Scoring tuned with held-out evaluation set. Match / possible-match / no-match thresholds reviewed by a human queue.

  3. 3 · Optional biometric (Phase 2)

    Fingerprint or face template stored as a hash, never raw. Opt-in only. Disabled by default in jurisdictions that restrict it.

  4. 4 · Federated reconciliation

    When online, query TEFCA/Carequality/CommonWell matching. Reconcile their UUIDs to our patient. Same mechanism extends internationally — swap the broker, keep the token.

Offline match flow

Clinic edge node holds an MPI shard for the region. New patient: scan QR → exact UUID match against shard. No QR: probabilistic match against cached demographics. Unresolved patients get a provisional ID and reconcile upstream on next sync.

Anti-fraud / anti-duplicate

Every encounter signed by a credentialed provider. Token re-issuance requires either prior provider attestation or a step-up identity proof. Duplicate detection runs nightly server-side and proposes merges, never auto-merges.

07 · Security, privacy & compliance

Compliance is an architectural property, not a checklist.

HIPAA, by construction

AES-256 at rest, TLS 1.3 in transit, access-controlled per resource, audit log on every read/write. BAAs with every infra vendor. Breach-notification runbook from day one.

Provider trust chain

Onboarding verifies NPI (NPPES), state medical licensure (state boards / FSMB), and DEA registration for prescribers. Trust is rooted in our CA and travels via signed JWTs when the provider operates outside their home org.

Granular, portable consent

Patient-controlled share grants per data category (e.g., behavioral health, reproductive, HIV) and per recipient. Grants are FHIR Consent resources, portable across networks, and evaluable offline.

Cached-record encryption

Records cached on shared/kiosk devices are encrypted with a key derived from the clinician's session + device attestation. Logging out wipes the cache. Stolen kiosk = useless data.

Data residency hooks now, federation later

Single-region U.S. cloud at MVP, but the API surface assumes a region attribute on every patient. Phase 3 deploys EU and other regional instances; data crosses borders only via consented exchange, not replication.

Burkina sovereignty & compliance addendum

Sovereignty · BDHI owns the data

All third-party APIs (AWS, OpenMRS hosting, LLM gateway, Twilio, observability) are provisioned under BDHI-owned accounts from day one. Frenchy operates as a user with revocable access — never the account owner. Source code lives in BDHI's GitHub org.

Data residency · Contabo Germany or EU sovereign

Off-Outpost workloads (analytics, DHIS2 mirror, backups) hosted in Contabo Germany or Scaleway Paris by default — low-latency to West Africa, GDPR perimeter. Replaceable with an in-country sovereign host once available, without code changes.

Compliance posture beyond local law

SOC 2 controls applied throughout the SDLC. ISO 27001 certification track. HIPAA/FERPA-equivalent controls applied even where Burkina law is silent — we standardize up, not down.

Penetration testing before beta, not after

Two passes: (1) automated scanning at T+12 wks; (2) external manual red-team (ex-offensive-security operators) at T+14 wks. Findings remediated before beta testers in two countries get keys. No 'pen test on launch day' theatre.

Optional non-US contracting entity

If procurement prefers a non-US counterparty for sovereignty reasons, the engagement can be signed with Frenchy Digital France (Paris), Switzerland (Geneva), or Algeria. Same team, same code, same SLAs — different paper.

08 · Build & operate

Contract signed to turnkey in Guéré — 18 weeks.

The Sankofa / BDHI team asked for a timeline mapped from contract signature to a working clinic. Seven milestones, 18 weeks, $120k fixed software billed against each one — including the demo milestone we committed to on the call.

Contract → turnkey · Guéré pilot · $120k fixed
  1. T+0
    Contract signed · 20% upfront
    Sankofa MSA, BDHI DUA, and BAA-equivalents executed. Repo provisioned in client GitHub org. AWS / Contabo accounts linked under BDHI tenancy. $24k upfront invoice ($120k × 20%) triggered on signature.
  2. T+2 wks
    Module Matrix lock + connectivity audit
    SDP reviewed · Module Matrix locked line-by-line (build / adopt / Phase 2) · on-site or remote Starlink + power + hardware inventory audit. This is what makes the $120k defensible — anything that drifts here is a change request, not a scope creep.
  3. T+8 wks
    DEMO MILESTONE · 40% billed
    OpenMRS + DHIS2 standup complete on Contabo (DE) · Burkina implementation guide loaded · offline sync layer passing 72h soak in staging · clinician PWA + Triage Kiosk walkthrough recorded. Matches the 'demo in two months' commitment from the kickoff call. Triggers $24k milestone (cumulative 40%).
  4. T+12 wks
    Hardware telemetry adapters + sovereignty wiring
    Powerwall · Modbus · Watergen · i-STAT adapters ingesting into the FOS telemetry dashboard. BDHI-owned cloud tenancy live with revocable key management. Automated pen test #1 executed; remediations merged.
  5. T+14 wks
    Hardware shipped to Guéré · 70% billed
    Outpost / mini-rack + rugged tablets + UPS shipped, customs-cleared, racked on-site. LTE/VSAT failover commissioned. Smoke tests pass from local LAN. Hardware is billed pass-through at cost — software milestone triggers $12k (cumulative 70%).
  6. T+16 wks
    UAT + manual red-team pen test · train-the-trainer
    External red-team penetration test by ex-hacker firm · all findings closed. One on-site week with clinical + technical leads: triage flow, encounter charting, telemetry dashboard, fallback procedures. Runbooks + on-call escalation finalized.
  7. T+18 wks
    Go-live · first consented encounter · final 30% billed
    Live patient triaged through the kiosk, charted in OpenMRS, diagnostic injected from i-STAT, indicator aggregated into DHIS2. 30-day hypercare begins. Final $36k invoice (cumulative 100%) due on go-live. Source code + runbooks handed to BDHI ops.
18 weeksDemo at T+8 wksPen tested before go-live30-day hypercareSource-code handover at T+18

Team shape (Sankofa pilot)

1.0 FTE
Full-stack engineer / tech lead
0.5 FTE
Edge / DevOps engineer (Outposts, Starlink QoS, telemetry)
0.5 FTE
Product / clinical informaticist
0.25 FTE
Compliance + BDHI liaison

If real team size is smaller, we drop the AI-triage offline-fallback ML tuning and defer the second telemetry source. If larger, we pull a Tier 3 second clinic into Phase 1.

09 · Top 10 risks

What will kill this if we ignore it.

  1. 01
    MPI accuracy

    Mismatched or merged charts are the worst-case clinical event. Mitigation: conservative thresholds, human-in-the-loop merge queue, audit every match.

  2. 02
    TEFCA integration drag

    QHIN onboarding is months and lawyer-heavy. Mitigation: start in Phase 0, treat it as a parallel workstream, ship pilot without it if it slips.

  3. 03
    Offline conflict resolution UX

    CRDTs are easy; clinical merge UX is hard. Mitigation: limit conflicts by making most resources append-only; design merge UI with pilot clinicians.

  4. 04
    Provider credentialing fraud

    An imposter writing notes is catastrophic. Mitigation: NPI + state board + DEA verification at onboarding, signed encounters, periodic re-verification.

  5. 05
    HIPAA breach via kiosk

    Shared devices leak data. Mitigation: session-scoped cache encryption, auto-wipe, device attestation, no PHI in browser localStorage.

  6. 06
    Vendor lock-in to Medplum

    If we adopt Medplum and outgrow it, migration is real work. Mitigation: keep all data in standard FHIR — Medplum's gift is that exit is just an export.

  7. 07
    Clinical liability ambiguity

    Who's responsible when a federated record is wrong? Mitigation: clear provenance on every resource; display source + last-verified date in the chart.

  8. 08
    Team capacity collapse

    One developer leaves and the project halts. Mitigation: adopt over build, document ruthlessly, no bespoke infrastructure.

  9. 09
    Regulatory drift (state-by-state)

    42 CFR Part 2, state reproductive-health laws, minor consent — all vary. Mitigation: consent engine is data-driven, not coded per state.

  10. 10
    Sustainability / business model

    EHRs that don't get paid die. Mitigation: not a tech problem — surface to founders as a Phase 2 decision (per-provider SaaS vs. grant-funded vs. health-system contract).

10 · Open decisions

What only you can decide.

Each comes with my recommendation. You overrule, you don't ask permission.

DECISION 01

Build vs. adopt the FHIR foundation?

My recommendation

Adopt Medplum.

Why

TypeScript, MIT-licensed, US Core conformant, SMART on FHIR built in. A one-dev team cannot also build a FHIR server. HAPI as a fallback if edge-node licensing is awkward.

DECISION 02

Centralized vs. federated data architecture?

My recommendation

Centralized U.S. region for MVP — but assume regional federation in the schema.

Why

Every resource carries a region attribute from day one. We don't deploy EU until we need to, but we never have to retrofit the data model.

DECISION 03

Connect to TEFCA/Carequality/CommonWell from MVP, or run a closed pilot first?

My recommendation

Closed pilot first; TEFCA in parallel.

Why

Pilot proves the offline + chart loop. TEFCA onboarding runs as a 6-month parallel track. We connect when the paperwork lands, not when we're ready to demo.

DECISION 04

MVP user scope — also lab/imaging on day one?

My recommendation

No. Patients + 2–3 pilot clinics only.

Why

Lab and imaging are each a 3-month integration with its own compliance and vendor surface. Ship the chart loop first; integrations come in Phase 3.

DECISION 05

Funding / runway and real team size?

My recommendation

Open question for the founders.

Why

This plan assumes ~4 people / 1 FTE dev for ~9 months to pilot. If runway is shorter, drop the edge node and consent UI. If longer, pull lab forward.

DECISION 06

Biggest load-bearing assumption?

My recommendation

Pilot clinics will tolerate a thin chart in exchange for portability.

Why

If pilot clinicians demand feature parity with Epic before they'll use us, the MVP scope is wrong and we need a different beachhead (free clinics, NGO sites, refugee health) where portability is itself the killer feature.

"The patient walks in. The record is already there."

If we can't deliver that one sentence in the pilot, nothing else matters.

Scope & engagement

What's included, and what it costs to start.

Fixed-fee build with milestone-based delivery. All payment due at publish. Edits during the first month of maintenance are included.

Engagement tiers
Recommended
Hands-on, solo
$120,000
USD · fixed

We run the full build end-to-end. No external dev team to coordinate with, no committee approvals between milestones. Fastest path to publish.

  • Single point of contact
  • Direct decisions with founder
  • Fixed scope from locked SOW
+ Your developer
$130,000
USD · fixed

We build alongside a developer on your team. Adds code reviews, paired sessions, hand-off documentation, and integration overhead.

  • Paired reviews & PR cycles
  • Shared repo conventions
  • Onboarding & handoff docs
+ Dev + stakeholders
$140,000
USD · fixed

We work with your developer and wait on multi-stakeholder sign-off before each milestone advances. Adds meeting load and idle time.

  • Stakeholder approval gates
  • Extended decision cycles
  • Meeting & alignment time
Consulting / oversight
$150,000
USD · 12 months

You build it. We act as embedded consultants — reviewing architecture, auditing code, validating FHIR & security work, and unblocking decisions.

  • Weekly reviews & QA
  • Architecture & security audits
  • 12-month retainer

All tiers follow the same milestone structure below, anchored on the $120k Sankofa FOS base scope. Fixed-price tiers include 10% monthly maintenance ($12k–$14k/mo) once published, with first-month edits included. The consulting tier is a 12-month retainer paid monthly.

Anchor scope (Tier 1)
$120,000 USD
20% upfrontMilestone-basedDue at publish10% monthly maintenance

$24,000 due at signing. Remaining $96,000 paid against milestones, with full balance due on publish to production. After the domain is live, a 10% monthly maintenance fee ($12,000/mo) begins in month 1 and covers hosting oversight, dependency updates, security patches, and platform support. Edit requests submitted during the first month of maintenance are included at no extra cost.

Sankofa FOS · Guéré pilot · fixed software
$120,000 USD · 18 weeks
Tier 4 village clinicHardware pass-through · at cost30-day hypercare
Why $120k, not $80k — the scope bridge

The US pilot anchor is $80k. Guéré adds four line items the FOS email made non-negotiable. Every dollar of the delta maps to a specific capability — nothing aspirational is folded in here.

  • US pilot baseline carried forward
    $80,000
    Medplum-class hosted core, identity, dashboards, marketing site — unchanged scope
  • + Swap Medplum → OpenMRS + DHIS2 standup & module config — Layers 1 & 2
    + $15,000
    Self-hosted record engine · ~20 modules to enable, configure, and test vs. a hosted API
  • + Offline-first sync layer (queue + conflict resolution) — prerequisite for Pillar 1 (QoS) & Pillar 4 (AI Triage fallback)
    + $12,000
    Required for intermittent Starlink uplink · 72h disconnect, zero data loss
  • + Hardware telemetry adapters (Powerwall · Modbus · Watergen · i-STAT) — Pillars 2 & 3
    + $8,000
    Four device classes · dashboard surface · alerting
  • + Data sovereignty wiring (Contabo DE, BDHI-owned tenancy, DPA) — Layer 3 (Sankofa OS)
    + $5,000
    Separate cloud account model · key management · revocable access
  • Total fixed software
    $120,000
    18-week engagement · milestone-billed
Pass-through (not in the $120k)

AWS Outposts hardware, Starlink terminals + service, Tesla Powerwalls, Watergen GEN-M Pro, Abbott i-STAT cartridges, on-site networking. BDHI procures direct, or we procure at cost with no markup.

Phase 2 — scoped separately when Phase 1 lands
  • · 100% uptime SLO + 24/7 on-call posture (~$30–40k / yr retainer)
  • · Full ENDOS / WHO SMART / ICD-11 terminology mapping beyond core modules
  • · Multi-site rollout beyond Guéré (Tier 1–4 facility network)
  • · Burkina regulatory filings beyond the DUA template

Tier 2/3 deployments cost roughly the Guéré baseline ± $20k–40k depending on hardware reuse and module footprint — see Facility Tiers above. Those are Phase 2 expansions, not Phase 1 commitments.

Information we need from you

Quick checklist to firm the estimate above into a signed SOW. None of this is a blocker for the Friday follow-up — these are the inputs we'd ingest after.

  • Full SDP + System Architecture Plan (to validate edge / cloud split and Outpost spec)
  • BDHI National Project Overview (DHIS2 / ENDOS scope, data residency, MoH compliance posture)
  • Proof of Concept Outline (success metrics + hardware constraints in Guéré)
  • EHR Module Mapping spreadsheet (so we lock build / adopt / defer per row of the matrix above)
  • On-site connectivity audit (Starlink bandwidth profile, LTE backup, power reliability) — remote or we send a tech
  • BDHI / MoH regulatory contacts for the Data Use Agreement
  • Existing Tesla / generator / Watergen / i-STAT / TytoCare inventory + firmware versions
  • Preferred contracting entity (Frenchy US / France / Switzerland / Algeria) for sovereignty alignment
Cross-border contracting · sovereignty option

If BDHI's procurement posture prefers a non-US counterparty for sovereignty or perception reasons, we can sign through any of our cross-border entities. Same team, same code, same SLAs — different paper.

Frenchy Digital US
Los Angeles, CA · HIPAA / SOC 2 default
Frenchy Digital France
Paris · GDPR perimeter · EU procurement
Frenchy Digital Switzerland
Geneva · neutral jurisdiction · global health NGOs
Frenchy Digital Algeria
Algiers · North African sovereign comfort · regional ops
Onboarding & scope confirmation

Every engagement starts with a short discovery loop. The $80,000 figure is our anchor estimate for the scope on this page — final pricing is confirmed only after these three steps are complete and both sides sign the locked SOW. No build work or upfront invoice until then.

  1. 01
    Onboarding call
    Intro, stakeholder map, working agreements, NDA.
    Week 0
  2. 02
    Discovery & design workshops
    User-journey deep-dive per role, EHR/aggregator decisions, brand & UI direction.
    Week 0–1
  3. 03
    Scope confirmation & pricing lock
    Final SOW, fixed-fee pricing confirmed, signature required before any build work begins.
    End of week 1
Scope of work
  • FHIR-native data model & US Core R4 resources
  • Patient, clinician, facility, public-health & owner dashboards
  • Signup & identity flows (NPI, license, DEA, MFA, WebAuthn)
  • Aggregator connectors (Metriport, Health Gorilla, Particle, Zus)
  • SMART on FHIR & CDS Hooks demo surfaces
  • Consent engine, tamper-evident audit log, Inferno conformance views
  • Labs (HL7 v2 → FHIR), e-Prescribing, X12 eligibility/prior-auth
  • Marketing site, SEO, sitemap, responsive design system
Build milestones (after scope lock)
  • Kickoff & upfront
    Signed SOW (after scope lock)
    $24,000
    20%
  • Design system & dashboard prototypes
    Week 2–3
    $24,000
    20%
  • Core platform & dashboards
    Week 4–7
    $24,000
    20%
  • Integration & trust layer
    Week 8–11
    $24,000
    20%
  • Publish to production
    Launch day
    $24,000
    20%
Payment terms

20% ($24k) upfront after scope is confirmed and SOW is signed. Balance billed by milestone and fully due at publish.

Processing fees

A 3% processing fee is added to all invoices and paid by the client (card, ACH, wire, or platform fees).

3rd-party services

All API, hosting, and SaaS subscriptions (e.g., Metriport, Health Gorilla, AWS, Twilio, Stripe) are provisioned under client-owned accounts for easy handover and direct billing.

Maintenance & revisions

10% of total ($12k/mo) starting month 1 once live. Edits during month 1 included; later change requests scoped separately.

Revisions & change requests (after month 1)

Month 1 of maintenance covers unlimited small edits to the shipped scope so the platform settles cleanly into production. From month 2 onward, ongoing maintenance keeps the lights on; anything that changes what the product does is scoped and billed separately as a change request.

Included in monthly maintenance
  • Bug fixes on shipped, in-scope features
  • Copy, label, and image swaps on existing pages
  • Minor style tweaks (spacing, color, typography within the design system)
  • Dependency updates, security patches, hosting oversight
  • Monitoring, backups, and platform support
  • Up to 2 hours/month of ad-hoc edits to existing flows
Counts as a change request
  • +New pages, dashboards, roles, or user types
  • +New integrations or third-party connectors
  • +Schema / data model changes and migrations
  • +Redesigns, rebrands, or new design components
  • +Compliance or certification work outside the original SOW
  • +Any edit estimated above 2 hours of build time
How requests are submitted

Email or shared tracker. Each request gets a written estimate (scope, hours, fixed price, ETA) within 3 business days.

Pricing

Fixed-price per request, or $175/hr blended rate for ad-hoc work. Pre-paid blocks (10h / 25h / 50h) discounted 5–15%.

Approval & start

Work begins after written approval of the estimate. Urgent (<48h) requests carry a 1.5× rush multiplier when capacity allows.

Unused maintenance hours do not roll over. Pausing or cancelling maintenance is allowed with 30 days' notice; source code and infrastructure handover terms follow the Frenchy Digital Terms of Service.

What it looks like to work with us

Milestone payments tied to code that ships.

Every payment unlocks against a concrete, verifiable deliverable in the repo — not a slide deck. You see the commits, click the preview, and approve before the next milestone starts.

Code-deliverable milestones
$80,000 · 5 × $16,000
Tied to PRs mergedPreview URL per milestoneClient sign-off to advance
  1. M01
    20%
    Kickoff & repo bootstrap
    Signed SOW · Week 0
    • GitHub repo provisioned, CI/CD pipeline live (preview + prod)
    • Design tokens, Tailwind theme, shadcn/ui baseline committed
    • TanStack Start scaffold with __root, routing, and auth shell
    • Environment + secrets management wired (Lovable Cloud / Supabase)
    $16,000
  2. M02
    20%
    Design system & dashboard prototypes
    Week 2–3
    • Reusable Section, Panel, Stat, Tag primitives shipped
    • Five role shells (patient, clinician, facility, public-health, admin) navigable
    • Marketing site published to preview domain with SEO meta + sitemap
    • Component library documented in repo (Storybook-style index page)
    $16,000
  3. M03
    20%
    Core platform & dashboards
    Week 4–7
    • FHIR-native data model + US Core R4 resources implemented
    • All persona dashboards built (≈120 routes) with seeded demo data
    • Server functions: createServerFn for reads, RLS-aware mutations
    • Auth flows: signup wizards, NPI/license verification stubs, MFA
    $16,000
  4. M04
    20%
    Integration & trust layer
    Week 8–11
    • Aggregator connectors (Metriport / Health Gorilla / Particle) wired
    • SMART on FHIR launch + CDS Hooks demo surface
    • Consent engine, tamper-evident audit log, Inferno conformance views
    • X12 eligibility/prior-auth + HL7 v2 → FHIR lab pipeline
    $16,000
  5. M05
    20%
    Publish to production
    Launch day
    • Custom domain live with TLS, CDN, and edge functions deployed
    • Lighthouse / a11y / SEO audits ≥95 on all marketing pages
    • Runbook, on-call docs, and rollback procedure handed off
    • Source code transferred to client-owned GitHub org
    $16,000
How we operate
Async-first, weekly demo

Most work happens in Linear + Loom + GitHub PRs. One live demo per week (30 min), one written status update every Friday. No standing daily meetings.

Every change is a PR

You see every commit. Preview URLs auto-deploy per branch so you can click through changes before they hit main. Your team can review or merge directly if they want.

You own the code, day one

Repo lives in your GitHub org from week zero. All third-party services (Supabase, Stripe, Twilio, aggregators) are provisioned under your accounts — we just have access.

Security & compliance baked in

BAA-ready hosting, RLS on every table, audit log on every mutation, secrets in Cloudflare/Supabase vaults — not in code. We document it as we ship it.

Publish, then maintain

Full payment at publish. Month 1 of maintenance is included — unlimited small edits while the platform settles. From month 2: $8k/mo for hosting oversight, patches, and ad-hoc edits.

Who you'd be working with

Built by Frenchy Digital — Hollywood & Paris.

A 49-person mobile & web app studio founded in 2019. 4.8★ on Clutch, 50+ apps and 100+ web platforms shipped across healthcare, wellness, education, and professional associations.

Headquarters

1517 S Bentley Ave, Unit 204
Los Angeles, CA 90025

European hub: Paris, France · North Africa delivery

Team

49 designers & engineers across iOS, Android, React Native, web, and AI integration.

Track record

HIPAA-compliant work for CGSA, ClinicalEdify, National Dental Association, IglowMed, plus Y Combinator startups and Fortune 500 brands.

Your core pod
Chris Machetto
Chris Machetto
Co-Founder & President
Strategy, scope, architecture

Founded Frenchy Digital in 2019. Leads engagement strategy, technical architecture, and stakeholder alignment. Direct point of contact for the $80k tier.

Yasmine Benmaiza
Yasmine Benmaiza
Head of User Experience
UX, delivery, design system

Co-founder. Runs UX research, design systems, and delivery quality across LA and Paris. Oversees milestone reviews and acceptance.

Theo V. / Michael K. / Rachel
Theo V. / Michael K. / Rachel
Project Manager (one assigned)
Day-to-day, sprints, async standups

Your dedicated PM keeps sprints on rails — agendas, recaps, design reviews, QA passes, and the weekly status note. One PM, named at kickoff.

On the $80k tier you work directly with Chris and a dedicated PM. Yasmine signs off on contracts, billing, and delivery. Engineers and designers are pulled from the 49-person bench as the milestone requires — no offshore handoffs.

Meeting cadence — Tier 1 ($80,000)

A live call rhythm by phase, plus daily async. Every call has an agenda 24h in advance and a written recap within 24h after.

  • Onboarding & scope lock
    Two 60-min discovery workshops + one 30-min stakeholder sync. Daily async on Slack/Loom. Ends with signed SOW.
    3× / weekWeek 0–1
  • Design system & prototypes
    Monday kickoff (45 min) + Thursday design review (60 min). Figma walkthroughs recorded. Async feedback in under 24h.
    2× / weekWeek 2–3
  • Core build & dashboards
    Monday sprint planning (30 min) + Friday demo (45 min). Daily Loom standups from the PM. Milestone sign-off at end of week 7.
    2× / week + daily asyncWeek 4–7
  • Integration & trust layer
    Mid-week integration review + Friday demo. Security & FHIR conformance walkthroughs at week 10 and 11.
    2× / weekWeek 8–11
  • Publish & handoff
    Pre-launch checklist call, publish day war-room, post-launch retro. First-month maintenance edits start immediately after.
    Daily during launch weekWeek 12
Contract signing
  1. 01Discovery loop completes (week 0–1). Scope, deliverables, and milestones locked in writing.
  2. 02SOW + Master Services Agreement issued, referencing the Frenchy Digital Terms & Conditions (effective Jan 1, 2024, last updated Dec 17, 2025).
  3. 03Both sides sign digitally. The 20% upfront invoice ($16,000) is issued only after signature.
  4. 04Per the Terms, payment by any method (wire, ACH, card) constitutes full acceptance of the Agreement. No oral modifications — changes go through written amendment signed by an authorized officer.

Governing law: California. Mandatory arbitration on an individual basis applies to disputes (per §2 and §15 of the Terms).

Source code & IP delivery

Per §3.3 of the Frenchy Digital Terms, on full payment you receive a limited, non-exclusive, non-transferable, revocable license to the Developed IP for your internal business purposes as scoped in the SOW.

  • At each milestone: code is pushed to a private GitHub repo you have read access to from day one.
  • At publish (final 20% paid): repo ownership transferred to your GitHub org, environment variables and credentials handed over, deployment runbook delivered.
  • What's included in the license: all custom application code, design files, FHIR mappings, and documentation produced under the SOW.
  • What stays with Frenchy: internal frameworks, reusable libraries, methodologies, and the Frenchy Brand Assets (§4).

Source code is not released before the final invoice clears. Reverse engineering of Frenchy's internal tooling is prohibited under §3.2. Full Terms: frenchydigital.com/terms-and-conditions.