← Writing

Hiring a HIPAA-compliant developer: what to actually look for

I’ve shipped a HIPAA-compliant EHR holding 2M+ medical records at 99.99% uptime for ChiroSimple — a U.S. clinic network, on a Flutter + Firebase stack, migrating from a legacy WordPress + MySQL system. I’m not a compliance lawyer. But I know what separates developers who can actually ship HIPAA-ready systems from developers who say they can.

Here’s what you should be asking before you hire.

1. Ask about their threat model, not their certificate wall

“I’ve worked on HIPAA systems before” means almost nothing. What you want to hear is how they think about PHI (protected health information) flow. Ask:

2. Ask about the BAA chain

HIPAA requires a Business Associate Agreement with any vendor that touches PHI. The correct answer should include a mental map of every third party in the stack and whether each one signs a BAA.

Common gotchas a senior developer should flag:

If a candidate talks about HIPAA only at the framework level (“we used AWS, it’s HIPAA-compliant”) without mentioning the BAA chain, they haven’t shipped it.

3. Ask about audit trails

HIPAA requires audit logs of who accessed what PHI, when, and why. Too many devs treat this as a nice-to-have.

Questions to drill on:

4. Ask about offline and sync

This is where real-world healthcare systems live or die. Clinics in rural areas lose internet. Doctors see patients in rooms with bad Wi-Fi. An EHR that only works online is an EHR that’s abandoned.

A developer who’s shipped a real EHR will talk about:

If their answer is “we used Firestore’s offline cache,” dig deeper. It’s a fine primitive, but it’s not the whole story.

5. Ask about the migration

If you already have data in a legacy system (and most clinics do), migration is usually where the wheels come off. The developer should have opinions on:

6. Ask for a post-incident story

Every senior developer has one. “Tell me about a time something went wrong in a HIPAA-sensitive system you were responsible for. What did you do?”

Good answers:

Bad answers:

7. Watch for HIPAA theater

HIPAA theater is when a developer cites compliance language without understanding the underlying rule. Red flags:

What I’d pay for

A HIPAA-compliant Flutter or web + mobile EHR project, built end-to-end by a senior operator who’s shipped one before, reasonably scopes as:

If someone quotes you half these ranges, they’re likely either underscoping or planning to staff juniors. If someone quotes you double, they’re probably an agency with overhead you don’t need.

The plain close

If you’re hiring for a HIPAA project and these questions feel useful, let’s talk. I’ve shipped one. I know where the bodies are buried. My services page has the engagement shapes and ranges; my ChiroSimple case study is the specific project this post is drawn from.

And if I’m not the right fit, I’ll tell you that too — and point you at someone better.

← All writing Book a call →
Book a call → WhatsApp