Book a call
Contact

Context

A product company operating a clinical decision-support SaaS across North America and Europe needed to move from a fast-iterating MVP architecture to a production-grade platform that could satisfy HIPAA (US), GDPR (EU), and a forthcoming SOC 2 Type II audit. The platform serves clinical teams, integrates with EHR systems, and handles Protected Health Information (PHI) across hundreds of daily transactions.
The internal team was strong on product features but had no in-house expertise in healthcare-grade compliance. Previous attempts to engage a Big Four security consultancy had produced an extensive audit report and a fixed-price remediation quote — but no actual change in the team's ability to maintain compliance after the project ended. The client wanted both: pass the audits, and never need a vendor for compliance again.

This is where MetaProject was brought in.

The problem

When we started discovery, we found a pattern familiar to fast-growing healthtech products:
PHI flowed through 140+ endpoints without consistent classification or boundary enforcement
Access controls were enforced at the application layer but inconsistently at the database layer
Encryption-at-rest was in place, but encryption-in-transit was inconsistent for internal service-to-service calls
Audit logs existed in pockets — some services, some operations, no unified event model
Deployment was bi-weekly, manual, with no security scanning gates
The team had read the HIPAA Security Rule but had no operational model for translating it into engineering practice
A surface-level remediation could pass the audit on paper. A capability transfer required something deeper: rebuilding the way the team thought about, designed, and shipped PHI-handling code.

What we built together

MetaProject embedded a small senior team (four engineers + one engineering coach) alongside the client's existing squads. Over eleven months, we focused on five capability layers, each transferred to the internal team before we moved on.
01
Architecture standards
We codified the eight diverging service patterns into one. We documented APIs, error handling, eventing, persistence, and observability conventions. New service templates were generated from the standard, so squads couldn't easily diverge again. Every standard was tied to an Architecture Decision Record (ADR) explaining the trade-off.
02
Internal Developer Platform (IDP)
We bootstrapped a platform team from two existing senior engineers (rather than waiting on external hires). We built a self-service deployment flow on Kubernetes with GitOps, an internal service catalog, and a paved road for new services. Onboarding time for a new engineer dropped from six months to six weeks.
03
Product delivery operating model
We re-shaped the squad structure around stable product domains rather than projects. We introduced a flow-of-work model with explicit WIP limits, prioritization forums tied to business outcomes, and lightweight architecture governance through a federated review group. The endless architecture review meetings were replaced by asynchronous ADR reviews with named decision owners.
04
Centre of Excellence transition
We helped design and stand up the company's internal Engineering CoE — a small group (five senior engineers, rotating) that owned architectural standards, platform roadmap, and engineering practices. We did not staff the CoE. We trained it.
05
Knowledge transfer systems
Every artifact we produced lived in the client's own systems from day one. We co-wrote the engineering handbook. We ran weekly internal tech talks that grew into a regular practice the team continued after we left. We built a Skills Matrix mapping each capability to who in the team owned it.

Timeline

The engagement followed our three-phase model:
Phase 1
Co-execution (months 1–4)
MetaProject senior engineers led the architecture rework, wrote the first ADRs, and built the CI/CD security pipeline. Client engineers worked alongside, pairing on every significant change.
Phase 2
Transition (months 5–7)
Client engineers led new feature work using the patterns we had established. MetaProject moved into mentor and reviewer roles: code review, architecture forum chair, runbook drills.
Phase 3
Self-sufficiency (months 8–9)
The internal CoE structure was in place. MetaProject stepped back to a monthly counsel role. The client's first independent HIPAA audit and SOC 2 Type II audit were passed without our involvement in the audit response.

Outcomes

By the end of nine months, the client had:

Passed all three target audits
(HIPAA Security Rule, SOC 2 Type II, EU GDPR DPIA) on first attempt
Reduced deployment cycle time
in the 18 months following launch
Zero data-related security incidents
in the 18 months following launch
Built an internal compliance capability
four engineers trained as compliance champions, owning all compliance reviews
Reduced reliance on external consultants
for compliance from "every audit" to "ad-hoc strategic counsel"
Increased product velocity
the team could now ship PHI-handling features faster than before the rework, because compliance was no longer a separate gating step

Why this engagement worked

Three things made the difference:
No junior bench
Every MetaProject engineer on the project was a senior with prior healthtech compliance experience. We didn't learn HIPAA on the client's time.
Documentation-first
Every architectural choice, every standard, every runbook lived in the client's own systems from day one. There was nothing in a vendor's private notes that mattered to the platform's future.
Exit by design
The engagement was scoped, from the kickoff, with a defined transition out. The client's leadership knew, from week one, what self-sufficiency would look like and what milestones marked the path to it.

Stack snapshot

Cloud
AWS (multi-region, with EU data residency for European users)
Compute
EKS (managed Kubernetes), Lambda for event-driven workloads
Data
PostgreSQL (RDS, with row-level security), DynamoDB for high-velocity event streams
Data
PostgreSQL (RDS, with row-level security), DynamoDB for high-velocity event streams
Compliance tooling
OPA (policy-as-code), Trivy, Snyk, Vault, AWS KMS, AWS GuardDuty
CI/CD
GitHub Actions with custom security workflows, ArgoCD for GitOps deployment
Authentication
Auth0 with SAML SSO for clinical users, MFA enforced, session policies aligned with HIPAA

Need a similar transformation?

If you operate a healthcare product and you're facing HIPAA, GDPR, or SOC 2 — and you want to leave the engagement with a team that can maintain compliance without us — that is what we are built for.
Start a Capability Blueprint Workshop
Client name withheld under NDA. Outcomes verified through joint post-engagement review.

See more cases

Speed Logistics Marine

Scaling a global fleet without scaling the administrative load that usually grows with it.
#Maritime
#ERP
#SaaS
#Mobile
#.NET
#AWS
#PostgreSQL
#Logistics
Skin.Club CS2 skins guide webpage displaying various weapon skins and knife designs including Doppler, Ultraviolet, Marble Fade, Freehand, and Damascus Steel.
This is some text inside of a div block.

Native Mobile Companion for a Gaming Marketplace

Native mobile engineering for a marketplace whose app-store presence had to coexist with a regulated web platform — without architectural drift.
#Mobile
#iOS
#Android
#Native
#Kotlin
#Swift
#Anti-Fraud
#Architecture
Skin.Club CS2 skins guide webpage displaying various weapon skins and knife designs including Doppler, Ultraviolet, Marble Fade, Freehand, and Damascus Steel.
This is some text inside of a div block.

Orthodentix

Scaling clinical quality across European dental service organisations with an ML/LLM ecosystem clinicians can actually trust.
#HealthTech
#AI-SaaS
#Orthodontics
#ML/LLM
#GDPR
#HDS
Skin.Club CS2 skins guide webpage displaying various weapon skins and knife designs including Doppler, Ultraviolet, Marble Fade, Freehand, and Damascus Steel.
This is some text inside of a div block.
+1
🇺🇸
Uploading...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.
By clicking this button I agree to the Privacy policy
Thanks for reaching out!
We’ve received your message and one of our experts will be in touch shortly.
Back
Oops! Something went wrong while submitting the form.

Start your capability journey

In 4 weeks we map your architecture, delivery model, knowledge gaps, risks, and capability priorities — so you can scale independently.
Man with short dark hair and beard wearing sunglasses and a light-colored shirt, looking to the side against a blurred outdoor background.
Alexey Belokamensky
CEO
Black and white photo of a man in a suit speaking at a microphone on stage with a piano in the background.
Alex Volt
Head of Sales
Black and white portrait of a woman with curly hair wearing a white top, looking off to the side.
Sofia Petrenko
Recruitment Manager