HIPAA-Compliant Custom Backend for GLP-1 Telemedicine E-Commerce Site (Framer Frontend + Custom Payment API)
Budget: $1,500 – $3,000 USD
I'm seeking an experienced full-stack developer (preference for those with prior work in GLP-1, telemedicine, or healthcare e-commerce) to build a robust, HIPAA-compliant backend from scratch for our direct-to-consumer platform selling physical GLP-1 products. The frontend is built in Framer (API integration only), so focus on secure, maintainable backend with tight admin controls.
Core Requirements:
Product catalog, cart, and checkout for physical items (quantities, real-time stock, shipping options)
Secure integration with our in-house Deluxe Payment Processor API (end-to-end test transactions). Designed for easy future additions (Credit/Debit, PayPal, Bank transfers) without major changes
Inventory: stock tracking, auto-deductions, low-stock alerts
Shipping: label generation (USPS, UPS, FedEx), status sync to customer portal & admin dashboard
Finance: lightweight ledger for orders, refunds, fees; CSV exports; basic P&L snapshots in dashboard
HIPAA Compliance (mandatory): Full implementation of required safeguards (encryption at rest/transit, access controls, audit logging, secure authentication, etc.). Use HIPAA-eligible infrastructure (e.g., AWS HIPAA, Google Cloud with BAA). Developer must be familiar with PHI handling in telemedicine/healthcare contexts and willing to sign a Business Associate Agreement (BAA) if PHI is processed.
Secure customer accounts (order history, tracking)
Responsive, SEO-friendly customer flows (product pages, cart, checkout)
Admin dashboard for inventory, orders, finance, and compliance reporting
Preferred Tech Stack:
Backend: Node.js (Express/NestJS), Laravel (PHP), or Django (Python) — recommend based on HIPAA best practices (e.g., strong security features, good ecosystem for encryption/logging)
Database: PostgreSQL or MySQL (with encryption)
Other: REST/GraphQL API, JWT/OAuth auth, proper error handling/logging
Deliverables:
Fully integrated, HIPAA-compliant backend + API for Framer
Admin dashboard (simple, secure UI — React/Vue/Tailwind fine)
End-to-end Deluxe Payment integration (test mode)
Complete documentation (setup, env vars, API docs, HIPAA compliance notes/deployment guide)
Optional short walkthrough video/screenshots
One round of post-launch bug fixes (within 2 weeks of go-live)
Acceptance Criteria:
Test order flows end-to-end: product → cart → checkout → payment → stock deduct → shipping label → status updates (with HIPAA safeguards verified)
Transactions/refunds logged/exportable to CSV
Local setup one-command; clean deployment to HIPAA-compliant cloud
No critical security/HIPAA issues (e.g., PHI exposure risks)
Budget & Timeline:
Budget: Around $2000
Timeline: 6–10 weeks preferred (factoring in compliance reviews; discuss phasing)
Milestones (adjustable):
Architecture design, HIPAA planning, Deluxe API integration + basic secure backend (20–30%)
Inventory/shipping/finance + admin dashboard + compliance safeguards (40–50%)
Full testing (including security audit basics), customer flows, documentation + deployment (remaining + bug fix buffer)
If you've built e-commerce or telemedicine platforms with custom payment gateways and HIPAA compliance (especially in GLP-1/healthcare space), please share 1–2 relevant examples/links in your bid, along with:
Your recommended stack & HIPAA approach (e.g., hosting, encryption strategy)
Rough timeline, cost breakdown, and BAA willingness
Any questions about our Deluxe API or PHI scope
Serious bids from developers with proven GLP-1/telemedicine/healthcare backend experience only — thanks!
Core Requirements:
Product catalog, cart, and checkout for physical items (quantities, real-time stock, shipping options)
Secure integration with our in-house Deluxe Payment Processor API (end-to-end test transactions). Designed for easy future additions (Credit/Debit, PayPal, Bank transfers) without major changes
Inventory: stock tracking, auto-deductions, low-stock alerts
Shipping: label generation (USPS, UPS, FedEx), status sync to customer portal & admin dashboard
Finance: lightweight ledger for orders, refunds, fees; CSV exports; basic P&L snapshots in dashboard
HIPAA Compliance (mandatory): Full implementation of required safeguards (encryption at rest/transit, access controls, audit logging, secure authentication, etc.). Use HIPAA-eligible infrastructure (e.g., AWS HIPAA, Google Cloud with BAA). Developer must be familiar with PHI handling in telemedicine/healthcare contexts and willing to sign a Business Associate Agreement (BAA) if PHI is processed.
Secure customer accounts (order history, tracking)
Responsive, SEO-friendly customer flows (product pages, cart, checkout)
Admin dashboard for inventory, orders, finance, and compliance reporting
Preferred Tech Stack:
Backend: Node.js (Express/NestJS), Laravel (PHP), or Django (Python) — recommend based on HIPAA best practices (e.g., strong security features, good ecosystem for encryption/logging)
Database: PostgreSQL or MySQL (with encryption)
Other: REST/GraphQL API, JWT/OAuth auth, proper error handling/logging
Deliverables:
Fully integrated, HIPAA-compliant backend + API for Framer
Admin dashboard (simple, secure UI — React/Vue/Tailwind fine)
End-to-end Deluxe Payment integration (test mode)
Complete documentation (setup, env vars, API docs, HIPAA compliance notes/deployment guide)
Optional short walkthrough video/screenshots
One round of post-launch bug fixes (within 2 weeks of go-live)
Acceptance Criteria:
Test order flows end-to-end: product → cart → checkout → payment → stock deduct → shipping label → status updates (with HIPAA safeguards verified)
Transactions/refunds logged/exportable to CSV
Local setup one-command; clean deployment to HIPAA-compliant cloud
No critical security/HIPAA issues (e.g., PHI exposure risks)
Budget & Timeline:
Budget: Around $2000
Timeline: 6–10 weeks preferred (factoring in compliance reviews; discuss phasing)
Milestones (adjustable):
Architecture design, HIPAA planning, Deluxe API integration + basic secure backend (20–30%)
Inventory/shipping/finance + admin dashboard + compliance safeguards (40–50%)
Full testing (including security audit basics), customer flows, documentation + deployment (remaining + bug fix buffer)
If you've built e-commerce or telemedicine platforms with custom payment gateways and HIPAA compliance (especially in GLP-1/healthcare space), please share 1–2 relevant examples/links in your bid, along with:
Your recommended stack & HIPAA approach (e.g., hosting, encryption strategy)
Rough timeline, cost breakdown, and BAA willingness
Any questions about our Deluxe API or PHI scope
Serious bids from developers with proven GLP-1/telemedicine/healthcare backend experience only — thanks!