Telehealth Platform with Pharmacy Integration
Budget: $20,000 – $50,000 USD
1) Summary
Build a U.S. telehealth + partner‑pharmacy platform for GLP‑1 programs (focus semaglutide). MVP covers: patient onboarding & medical intake, clinician triage & e‑prescribing (via certified partner), pharmacy handoff with cold‑chain tracking, titration/reminder engine, adverse‑event (AE) capture, outcomes dashboard, and admin/audit. Cash‑pay first.
2) Roles (can be an agency)
Full‑Stack Lead (backend, data model, integrations, security)
Frontend Eng (Next.js/TS)
DevOps/SRE (AWS, Terraform, CI/CD, observability)
QA Lead (test plan + automation)
PM (agile, weekly demos)
(Optional) Compliance/CSV (Part 11 validation pack)
3) Preferred Stack
FE: Next.js (TS), Tailwind, TanStack Query, React Hook Form, Zod
BE: Node + NestJS or Python + FastAPI; REST (OpenAPI 3.1)
Data: Postgres (RLS, multi‑tenant), Redis, S3, Kafka/Redpanda (events)
Infra: AWS (EKS/ECS), RDS, CloudFront; Terraform, GitHub Actions
Auth: OIDC (Auth0/Cognito), MFA; RBAC; full audit trail
Msg: Twilio A2P 10DLC, SES/SendGrid
eRx/EPCS: Integrate a Surescripts‑connected vendor (sandbox first)
Ship/Cold‑chain: Shippo/EasyPost + temperature sensor API
Payments: Stripe (cash‑pay; HSA/FSA cards ok)
Obs/QA: OpenTelemetry, Prometheus/Grafana; Jest/PyTest, Cypress, k6
4) MVP Scope (what must work)
Patient Web
IDV, HIPAA consent, PHI forms; contraindication screen (MTC/MEN2, pancreatitis, pregnancy, etc.)
Cash‑pay checkout; invoices
Dosing calendar & reminders; missed‑dose logic; AE diary
Provider Console
Triage queue (eligibility score + red flags)
eRx composer with titration plan (0.25→0.5→1.0 mg weekly; editable)
SOAP notes, e‑sign, audit
Pharmacy Workspace
eRx intake; interaction check; lot/expiry; label/pack/ship
Temperature log ingest; excursion flags; delivery confirmation
Admin/Compliance
RBAC, org/site/provider; state licensure matrix (simple rules)
Audit event explorer; basic reports (time‑to‑Rx/ship, adherence)
Out of Scope (MVP): PA/payer integrations; native mobile; in‑house EPCS cert; full lab interfaces (upload only).
5) Compliance/Security (non‑negotiable)
HIPAA: BAAs; TLS 1.2+; AES‑256 at rest; least‑privilege RBAC; breach log
21 CFR Part 11: unique users, MFA, time‑stamped audit trails, e‑sign meaning, record retention, change control
A2P 10DLC registration + opt‑in language; no PHI in non‑prod
6) Milestones, Payments, AC
M0 Setup (1–2w, 10%)
Arch diagram, ERD, OpenAPI draft, backlog; AWS envs + CI/CD; security checklist
M1 Intake/Auth (3–4w, 15%)
Patient onboarding, consents, contraindication rules, provider triage; RBAC + audit MVP
M2 eRx & Provider (4–5w, 20%)
eRx sandbox flow (create/send/ACK), titration UI, SOAP notes, e‑sign; PDMP record fields
M3 Pharmacy/Cold‑chain (4w, 20%)
Pharmacy workspace, lot/expiry, shipment + temp logs, exceptions, delivery confirmation
M4 Titration/Adherence (3w, 20%)
Dosing calendar, reminders, AE diary, rules engine → {continue/increase/hold/decrease}; outcomes v1
M5 Hardening/Go‑Live (2–3w, 15%)
Perf/security, backup/restore drill, runbooks, UAT sign‑offs; Part 11 validation packet draft (URS→FS→DS→IQ/OQ/PQ templates + trace matrix)
General AC
OpenAPI complete; contracts tests green; P95 core API <300ms; zero P2 security findings
End‑to‑end demo: onboarding → provider approval → eRx → ship → dosing reminders
Audit events for login, PHI read/write, config changes; strict role isolation
7) Data Model (abridged)
Patient, Consent, Intake, Condition, Medication, Observation, Encounter, MedicationRequest, Pharmacy, InventoryLot, Shipment, TemperatureLog, AdverseEvent, CarePlan, Task, Payment, Invoice, Message, AuditEvent, User, Role, Organization, ProviderLicense. Use UUIDs; soft‑delete; RLS.
8) Integrations to Implement (MVP)
Auth0/Cognito; Twilio; Stripe; eRx vendor (sandbox); Shippo/EasyPost + sensor API
9) QA/Validation Deliverables
Test plan; unit/integration/e2e automation; coverage report
Security: SAST/DAST; dependency scan; secrets mgmt; SOC2‑style checklist
CSV: URS/FS/DS templates + IQ/OQ/PQ scripts; sample traceability matrix
10) Docs & Handover
README (bootstrap), env vars, seed data; runbooks (on‑call, incidents, backup/restore, eRx outage, temp excursion)
Admin SOPs (user provisioning, role edits, audit export, data deletion)
Architecture/ERD/sequence diagrams + 30‑min recorded walkthrough
11) Contract Terms (recommended)
IP assignment; NDA; no PHI in non‑prod; SSO for admin; disclose subcontractors; PR reviews; weekly demos; 10% holdback until 30‑day warranty ends
13) Bid Template (require this format)
Team & roles (+ LinkedIn, % allocation)
Relevant HIPAA/telehealth/eRx work (links)
Proposed architecture diagram + deviations
Timeline by milestone + start date
Compliance plan (HIPAA, Part 11, A2P 10DLC)
Preferred eRx + shipping/sensor vendors
Top 3 risks + mitigations
Communication cadence + demo schedule
Price: fixed per milestone + hourly OOS
Warranty/support after M5
14) Screening Questions (must answer)
How did you implement audit trails + RBAC on your last HIPAA project?
Which Surescripts‑connected eRx vendor have you integrated? Describe message flow.
Show a sample OpenAPI + ERD you authored.
How will you implement temperature excursion rules and evidence capture?
Provide a sample Part 11 traceability matrix (redacted is fine).
15) Attachments (we provide)
Level‑3 master spec (internal)
Wireframe list (Patient/Provider/Pharmacy/Admin)
Build a U.S. telehealth + partner‑pharmacy platform for GLP‑1 programs (focus semaglutide). MVP covers: patient onboarding & medical intake, clinician triage & e‑prescribing (via certified partner), pharmacy handoff with cold‑chain tracking, titration/reminder engine, adverse‑event (AE) capture, outcomes dashboard, and admin/audit. Cash‑pay first.
2) Roles (can be an agency)
Full‑Stack Lead (backend, data model, integrations, security)
Frontend Eng (Next.js/TS)
DevOps/SRE (AWS, Terraform, CI/CD, observability)
QA Lead (test plan + automation)
PM (agile, weekly demos)
(Optional) Compliance/CSV (Part 11 validation pack)
3) Preferred Stack
FE: Next.js (TS), Tailwind, TanStack Query, React Hook Form, Zod
BE: Node + NestJS or Python + FastAPI; REST (OpenAPI 3.1)
Data: Postgres (RLS, multi‑tenant), Redis, S3, Kafka/Redpanda (events)
Infra: AWS (EKS/ECS), RDS, CloudFront; Terraform, GitHub Actions
Auth: OIDC (Auth0/Cognito), MFA; RBAC; full audit trail
Msg: Twilio A2P 10DLC, SES/SendGrid
eRx/EPCS: Integrate a Surescripts‑connected vendor (sandbox first)
Ship/Cold‑chain: Shippo/EasyPost + temperature sensor API
Payments: Stripe (cash‑pay; HSA/FSA cards ok)
Obs/QA: OpenTelemetry, Prometheus/Grafana; Jest/PyTest, Cypress, k6
4) MVP Scope (what must work)
Patient Web
IDV, HIPAA consent, PHI forms; contraindication screen (MTC/MEN2, pancreatitis, pregnancy, etc.)
Cash‑pay checkout; invoices
Dosing calendar & reminders; missed‑dose logic; AE diary
Provider Console
Triage queue (eligibility score + red flags)
eRx composer with titration plan (0.25→0.5→1.0 mg weekly; editable)
SOAP notes, e‑sign, audit
Pharmacy Workspace
eRx intake; interaction check; lot/expiry; label/pack/ship
Temperature log ingest; excursion flags; delivery confirmation
Admin/Compliance
RBAC, org/site/provider; state licensure matrix (simple rules)
Audit event explorer; basic reports (time‑to‑Rx/ship, adherence)
Out of Scope (MVP): PA/payer integrations; native mobile; in‑house EPCS cert; full lab interfaces (upload only).
5) Compliance/Security (non‑negotiable)
HIPAA: BAAs; TLS 1.2+; AES‑256 at rest; least‑privilege RBAC; breach log
21 CFR Part 11: unique users, MFA, time‑stamped audit trails, e‑sign meaning, record retention, change control
A2P 10DLC registration + opt‑in language; no PHI in non‑prod
6) Milestones, Payments, AC
M0 Setup (1–2w, 10%)
Arch diagram, ERD, OpenAPI draft, backlog; AWS envs + CI/CD; security checklist
M1 Intake/Auth (3–4w, 15%)
Patient onboarding, consents, contraindication rules, provider triage; RBAC + audit MVP
M2 eRx & Provider (4–5w, 20%)
eRx sandbox flow (create/send/ACK), titration UI, SOAP notes, e‑sign; PDMP record fields
M3 Pharmacy/Cold‑chain (4w, 20%)
Pharmacy workspace, lot/expiry, shipment + temp logs, exceptions, delivery confirmation
M4 Titration/Adherence (3w, 20%)
Dosing calendar, reminders, AE diary, rules engine → {continue/increase/hold/decrease}; outcomes v1
M5 Hardening/Go‑Live (2–3w, 15%)
Perf/security, backup/restore drill, runbooks, UAT sign‑offs; Part 11 validation packet draft (URS→FS→DS→IQ/OQ/PQ templates + trace matrix)
General AC
OpenAPI complete; contracts tests green; P95 core API <300ms; zero P2 security findings
End‑to‑end demo: onboarding → provider approval → eRx → ship → dosing reminders
Audit events for login, PHI read/write, config changes; strict role isolation
7) Data Model (abridged)
Patient, Consent, Intake, Condition, Medication, Observation, Encounter, MedicationRequest, Pharmacy, InventoryLot, Shipment, TemperatureLog, AdverseEvent, CarePlan, Task, Payment, Invoice, Message, AuditEvent, User, Role, Organization, ProviderLicense. Use UUIDs; soft‑delete; RLS.
8) Integrations to Implement (MVP)
Auth0/Cognito; Twilio; Stripe; eRx vendor (sandbox); Shippo/EasyPost + sensor API
9) QA/Validation Deliverables
Test plan; unit/integration/e2e automation; coverage report
Security: SAST/DAST; dependency scan; secrets mgmt; SOC2‑style checklist
CSV: URS/FS/DS templates + IQ/OQ/PQ scripts; sample traceability matrix
10) Docs & Handover
README (bootstrap), env vars, seed data; runbooks (on‑call, incidents, backup/restore, eRx outage, temp excursion)
Admin SOPs (user provisioning, role edits, audit export, data deletion)
Architecture/ERD/sequence diagrams + 30‑min recorded walkthrough
11) Contract Terms (recommended)
IP assignment; NDA; no PHI in non‑prod; SSO for admin; disclose subcontractors; PR reviews; weekly demos; 10% holdback until 30‑day warranty ends
13) Bid Template (require this format)
Team & roles (+ LinkedIn, % allocation)
Relevant HIPAA/telehealth/eRx work (links)
Proposed architecture diagram + deviations
Timeline by milestone + start date
Compliance plan (HIPAA, Part 11, A2P 10DLC)
Preferred eRx + shipping/sensor vendors
Top 3 risks + mitigations
Communication cadence + demo schedule
Price: fixed per milestone + hourly OOS
Warranty/support after M5
14) Screening Questions (must answer)
How did you implement audit trails + RBAC on your last HIPAA project?
Which Surescripts‑connected eRx vendor have you integrated? Describe message flow.
Show a sample OpenAPI + ERD you authored.
How will you implement temperature excursion rules and evidence capture?
Provide a sample Part 11 traceability matrix (redacted is fine).
15) Attachments (we provide)
Level‑3 master spec (internal)
Wireframe list (Patient/Provider/Pharmacy/Admin)