Fractional CTO · Healthtech
Fractional CTO for healthtech startups
Build HIPAA-compliant products without the architectural debt that strangles your roadmap.
The case
Healthtech engineering is not generic engineering.
Healthtech founders inherit a stack of regulations, vendors, and integration standards nobody outside the industry takes seriously until it costs them a deal. The decisions that determine whether you survive an enterprise security review are made in the first weeks of the build, not retrofitted before the audit. I currently serve as fractional CTO of a preventive-health platform running AI analysis over 4000x4000-pixel retinal images — custom-claims RBAC across three user types, OTP verification, short session timeouts, multi-year audit trails, and FHIR-inspired collections. I know which of those decisions are load-bearing and which are theatre, because I have had to defend them.
Most healthtech founders are clinicians, scientists, or operators — not engineers. The gap is not generic engineering management; it is someone who has drawn a PHI boundary before and knows what it costs to draw it wrong. A fractional CTO who has shipped regulated software fills that gap without a $300k hire.
The first 90 days
What a healthtech engagement actually looks like
A fractional CTO for healthtech draws the PHI boundary before you build, so compliance is architectural rather than a rewrite before your first hospital contract — and so your AI pipeline does not quietly widen regulatory scope.
- 01
Weeks 1–2: PHI boundary mapping
Identify precisely which data elements are protected health information and which services touch them. Everything downstream depends on this line being drawn correctly and early.
- 02
Weeks 3–4: Vendor and BAA review
Audit every vendor in the stack for BAA coverage. Anything that cannot be covered gets designed out of the PHI path rather than granted an exception you will have to defend later.
- 03
Weeks 5–8: Integration strategy
Decide between Redox, Particle, and direct FHIR based on your actual customer pipeline rather than on architectural preference. Almost always start with a vendor abstraction; direct FHIR is simpler to describe and brutal to operate.
- 04
Weeks 9–12: Security review readiness
Implement queryable audit logging, role-based access over PHI, and de-identification for analytics. Then pre-answer the enterprise hospital security questionnaire, which is 200 questions mapping to roughly 20 real controls.
What we cover
Healthtech-specific decisions I help you make
Tools I use in healthtech
Not ready to talk yet
The HIPAA architecture checklist
The decisions on this page, written out in the order they come up, with what goes wrong when each is answered late. Free, ungated, and useful whether or not we ever work together.
Read it →Request a triage
Talk through your healthtech problem.
Free, 30 minutes. Tell me where you're stuck — I'll tell you what it takes. I confirm every request within 24 hours.
FAQ
Healthtech questions founders ask
Have you built HIPAA-compliant products before? +
Yes — patient-facing apps, provider tools, and AI analysis over medical imaging, from HIPAA work at Preventa Medical to the current Preventa Wellness platform, where Eric has been CTO since 2019 and which handles sensitive health data to the highest standard. I know the difference between "encrypted" and "audit-defensible," and BAA review is a step in how I evaluate vendors, not an afterthought.
Should we use Redox, Particle, or build FHIR direct? +
Almost always start with an integration vendor (Redox or Particle). Direct FHIR is technically simpler but operationally brutal — every health system implements the standard slightly differently. The vendor abstraction is worth the cost until you have a multi-million-dollar deal that demands a direct connection.
Can you help us prepare for an enterprise hospital security review? +
Yes. Most reviews are 200-question spreadsheets that map to the same 20 underlying controls. I have answered enough of them to know which answers actually matter and which boxes can be checked by configuration alone.