Telehealth Platform with Pharmacy Integration

Job ID: 39837371

Budget: $20,000 – $50,000 USD

1) Summary

Build a U.S. telehealth + partner‑pharmacy platform for GLP‑1 programs (focus semaglutide). MVP covers: patient onboarding & medical intake, clinician triage & e‑prescribing (via certified partner), pharmacy handoff with cold‑chain tracking, titration/reminder engine, adverse‑event (AE) capture, outcomes dashboard, and admin/audit. Cash‑pay first.

2) Roles (can be an agency)

Full‑Stack Lead (backend, data model, integrations, security)

Frontend Eng (Next.js/TS)

DevOps/SRE (AWS, Terraform, CI/CD, observability)

QA Lead (test plan + automation)

PM (agile, weekly demos)

(Optional) Compliance/CSV (Part 11 validation pack)

3) Preferred Stack

FE: Next.js (TS), Tailwind, TanStack Query, React Hook Form, Zod

BE: Node + NestJS or Python + FastAPI; REST (OpenAPI 3.1)

Data: Postgres (RLS, multi‑tenant), Redis, S3, Kafka/Redpanda (events)

Infra: AWS (EKS/ECS), RDS, CloudFront; Terraform, GitHub Actions

Auth: OIDC (Auth0/Cognito), MFA; RBAC; full audit trail

Msg: Twilio A2P 10DLC, SES/SendGrid

eRx/EPCS: Integrate a Surescripts‑connected vendor (sandbox first)

Ship/Cold‑chain: Shippo/EasyPost + temperature sensor API

Payments: Stripe (cash‑pay; HSA/FSA cards ok)

Obs/QA: OpenTelemetry, Prometheus/Grafana; Jest/PyTest, Cypress, k6

4) MVP Scope (what must work)

Patient Web

IDV, HIPAA consent, PHI forms; contraindication screen (MTC/MEN2, pancreatitis, pregnancy, etc.)

Cash‑pay checkout; invoices

Dosing calendar & reminders; missed‑dose logic; AE diary

Provider Console

Triage queue (eligibility score + red flags)

eRx composer with titration plan (0.25→0.5→1.0 mg weekly; editable)

SOAP notes, e‑sign, audit

Pharmacy Workspace

eRx intake; interaction check; lot/expiry; label/pack/ship

Temperature log ingest; excursion flags; delivery confirmation

Admin/Compliance

RBAC, org/site/provider; state licensure matrix (simple rules)

Audit event explorer; basic reports (time‑to‑Rx/ship, adherence)

Out of Scope (MVP): PA/payer integrations; native mobile; in‑house EPCS cert; full lab interfaces (upload only).

5) Compliance/Security (non‑negotiable)

HIPAA: BAAs; TLS 1.2+; AES‑256 at rest; least‑privilege RBAC; breach log

21 CFR Part 11: unique users, MFA, time‑stamped audit trails, e‑sign meaning, record retention, change control

A2P 10DLC registration + opt‑in language; no PHI in non‑prod

6) Milestones, Payments, AC

M0 Setup (1–2w, 10%)

Arch diagram, ERD, OpenAPI draft, backlog; AWS envs + CI/CD; security checklist

M1 Intake/Auth (3–4w, 15%)

Patient onboarding, consents, contraindication rules, provider triage; RBAC + audit MVP

M2 eRx & Provider (4–5w, 20%)

eRx sandbox flow (create/send/ACK), titration UI, SOAP notes, e‑sign; PDMP record fields

M3 Pharmacy/Cold‑chain (4w, 20%)

Pharmacy workspace, lot/expiry, shipment + temp logs, exceptions, delivery confirmation

M4 Titration/Adherence (3w, 20%)

Dosing calendar, reminders, AE diary, rules engine → {continue/increase/hold/decrease}; outcomes v1

M5 Hardening/Go‑Live (2–3w, 15%)

Perf/security, backup/restore drill, runbooks, UAT sign‑offs; Part 11 validation packet draft (URS→FS→DS→IQ/OQ/PQ templates + trace matrix)

General AC

OpenAPI complete; contracts tests green; P95 core API <300ms; zero P2 security findings

End‑to‑end demo: onboarding → provider approval → eRx → ship → dosing reminders

Audit events for login, PHI read/write, config changes; strict role isolation

7) Data Model (abridged)

Patient, Consent, Intake, Condition, Medication, Observation, Encounter, MedicationRequest, Pharmacy, InventoryLot, Shipment, TemperatureLog, AdverseEvent, CarePlan, Task, Payment, Invoice, Message, AuditEvent, User, Role, Organization, ProviderLicense. Use UUIDs; soft‑delete; RLS.

8) Integrations to Implement (MVP)

Auth0/Cognito; Twilio; Stripe; eRx vendor (sandbox); Shippo/EasyPost + sensor API

9) QA/Validation Deliverables

Test plan; unit/integration/e2e automation; coverage report

Security: SAST/DAST; dependency scan; secrets mgmt; SOC2‑style checklist

CSV: URS/FS/DS templates + IQ/OQ/PQ scripts; sample traceability matrix

10) Docs & Handover

README (bootstrap), env vars, seed data; runbooks (on‑call, incidents, backup/restore, eRx outage, temp excursion)

Admin SOPs (user provisioning, role edits, audit export, data deletion)

Architecture/ERD/sequence diagrams + 30‑min recorded walkthrough

11) Contract Terms (recommended)

IP assignment; NDA; no PHI in non‑prod; SSO for admin; disclose subcontractors; PR reviews; weekly demos; 10% holdback until 30‑day warranty ends

13) Bid Template (require this format)

Team & roles (+ LinkedIn, % allocation)

Relevant HIPAA/telehealth/eRx work (links)

Proposed architecture diagram + deviations

Timeline by milestone + start date

Compliance plan (HIPAA, Part 11, A2P 10DLC)

Preferred eRx + shipping/sensor vendors

Top 3 risks + mitigations

Communication cadence + demo schedule

Price: fixed per milestone + hourly OOS

Warranty/support after M5

14) Screening Questions (must answer)

How did you implement audit trails + RBAC on your last HIPAA project?

Which Surescripts‑connected eRx vendor have you integrated? Describe message flow.

Show a sample OpenAPI + ERD you authored.

How will you implement temperature excursion rules and evidence capture?

Provide a sample Part 11 traceability matrix (redacted is fine).

15) Attachments (we provide)

Level‑3 master spec (internal)

Wireframe list (Patient/Provider/Pharmacy/Admin)