softwerkdirect-to-consumer · regulated industriesStart a discovery sprint →Sign in

Healthcare DTC

Patient-facing software that can prove itself.

Telehealth intake, patient portals, cash-pay checkout. Built through Softwerk's verification-gated factory, with the HIPAA and HITRUST profiles enforced in the gate for your engagement, so each release leaves a write-once record of what they found, tied to the exact source tree.

What this market has to prove.

01

A HIPAA audit never asks whether the app works. It asks you to prove no patient data ever leaked and every access was controlled, for every release.

02

The FTC's Health Breach Notification Rule reaches health apps outside HIPAA. GoodRx and Premom were pursued under it in 2023, BetterHelp and Cerebral under Section 5 for the same data-sharing pattern, and on 2026-07-29 the FTC, Utah, and California, through Los Angeles County, sued Hims & Hers over billing, cancellation, and data-sharing practices.

03

An aggregator tally puts pixel-tracking penalties and settlements against US hospitals, telehealth platforms, and health apps above $100 million since 2023. A consent form is not a defense if the architecture still lets health data reach an ad platform.

What a healthcare discovery sprint looks like

A sample scope, written the way an engagement is written. It is what Softwerk sells, not a case study of a past build.

What you bring
A sandbox EHR or scheduling API, or a documented intake flow. A de-identified sample of the record shapes involved. The consent language you use today. The person who signs off on releases.
The one surface
Patient intake and consent capture, wired to that sandbox.
What you leave with
A running intake flow against the sandbox. A fixed-price build proposal with acceptance criteria. A certificate for every build produced in the sprint: sha256 of the tree, the commit it was minted for, and the HIPAA and HITRUST verdicts. A written summary of what the profiles and the PHI guard flagged during the sprint, and how each finding was resolved.
Out of scope
Production PHI (no BAA is signed for a sprint, so sandbox or de-identified data only). Production credentials. Your marketing pixels: we document where they may not go, and the rest is a decision for you and counsel. FDA promotional review.
Terms
Fixed length and fixed price, agreed in writing before it starts.

The regime, live and not live.

Every framework below is labelled with whether it runs in the gate today. Nothing is described as live unless a checklist is live.

What the gate does, and what it does not.

A dedicated PHI-guard service scans every generated write for identifiers. Every detection is evented and audited, and in enforcing mode a write carrying a high-precision identifier is blocked: an SSN, an MRN, a card or bank number, an email address, a phone number. Names and dates are observed rather than blocked, because the detector is too noisy on source code to gate on them, and we say so rather than overclaim. The HIPAA and HITRUST profiles run the PHI-detection rules on the output; the access-control, encryption, session, and audit-trail checks run on every scan. What the gate does not do: detect third-party ad tags. That rule is a build commitment, checked at review.

How the engagement runs.

Four stages, one gate on every change. Priced and agreed before work starts.

  1. 1

    Discovery sprint

    Fixed length, fixed price, against a real intake flow or a sandbox EHR, on sandbox or de-identified data.

  2. 2

    Fixed-scope build

    The factory builds the patient-facing surface with the HIPAA and HITRUST profiles loaded from the first task.

  3. 3

    Verification gate

    We run your workspace with the gate enforced. Every diff gets an independent-model review, your compliance profile runs on the output, the PHI guard scans every generated write, and a merge needs a valid certificate for that exact tree.

  4. 4

    Operate

    Every post-launch change ships through the same gate, and the scope names what a human reviews and when.

Asked before every first call.

Are you a HIPAA covered entity? Do you sign a BAA?

Softwerk is a business associate when a build touches protected health information, and we sign a Business Associate Agreement before that happens. A discovery sprint runs on sandbox or de-identified data and needs no BAA. Once a BAA is in place, we run the engagement with the HIPAA profile enforced in the gate, and the certificate records the per-framework verdict. The certificate, not a badge, is what an auditor can check.

We're not a hospital or a health plan. Does any of this apply to us?

Probably yes. The FTC's Health Breach Notification Rule covers personal health record vendors and related apps outside HIPAA. The FTC used it against GoodRx (2023-02, $1.5 million) and Premom (2023-05, $100,000) under the original rule, and the amendment in effect since 2024-07-29 codified the reach: health apps, a 60-day notice duty, FTC notice at 500 or more affected people, and disclosure of any third party, ad platforms included, that received the data. BetterHelp (2023) and Cerebral (2024) were pursued under Section 5 of the FTC Act for the same pattern. Not being a HIPAA covered entity is not a safe harbor.

What about tracking pixels and sharing data with Meta or Google for ads?

This is where FTC enforcement in DTC health has concentrated: GoodRx, BetterHelp, and Premom in 2023, Cerebral in 2024, the 2026 suit against Hims & Hers, and an aggregator tally of more than $100 million in pixel-tracking penalties and settlements against US hospitals, telehealth platforms, and health apps since 2023. What we commit to as a service: analytics are consent-gated, no third-party ad or analytics tag is placed on a surface that carries health data, and that rule is written into the build spec and checked at review before merge. Separately, a dedicated PHI-guard service scans every generated write for identifiers and, in enforcing mode, blocks a write that carries one. Those are two different checks. We do not claim the PHI guard detects ad tags.

Is the gate switched on for our project, or is it a setting?

It is a setting, and the engagement scope names it. The verification gate, the compliance veto, and the PHI guard each carry their own enforcement flag in the factory, and each is off until an operator turns it on. Off, the checks still run and their findings are still recorded, but nothing is withheld. On, they refuse the merge or the write, and the safe state is stop. We turn all three on for the workspace that builds your software, we put that in writing in the scope, and you can ask to see the setting on your workspace at any point in the engagement.

Full FAQ →

A goal goes in. Provable software comes out.

Bring the goal and the compliance regime. The engagement brings the spec, the build, the independent review, and the certificate.

Start a healthcare discovery sprint →