Project Highlights
- The platform is fully HIPAA-compliant
- Highly-efficient and accurate prescriptions
- Unique dosage calculation system (for male, female, and transgender patients)
- Millions of diverse parameters are taken into account by the algorithm during the dosage calculation
- Successfully adopted by clinics in the US, Spain, and Brazil
Project Summary
About Client
The company’s founder created a remarkable method of natural hormone therapy based on the proprietary bio-identical pellet hormone delivery system. This method was successfully implemented within the platform.
Over the years, the company has helped more than 250,000 patients around the globe and building a strong digital presence for the brand helped to increase the outreach and expand the customer base even further.
Client Request
The system is for internal use only, which means patients that receive treatment do not have access to it. The platform should be HIPAA-compliant and fully meet all of the requirements in regard to protected health information processing.
As Light IT Global was working on this project for an extensive period of time, our experts were asked to help with the implementation of multiple aspects of the solution.
The Outcome
To meet all compliance requirements as well as the client’s business needs, Light IT Global took care of the following development aspects:
- Implement a complex calculation algorithm created by medical professionals. The algorithm is based on a multitude of physiological parameters like age, gender, previous injections, etc.
- Store medical data in an encrypted form to ensure PHI security
- Regularly update the hormonal dosage calculator functionality in accordance with the doctors’ feedback
- Introduce 5 unique user roles with separate access rights, permissions and different functionality available
- Incorporate easy-to-use chat functionality to streamline online consultations regarding BHRT and general medical questions
- Develop multiple additional security methods to prevent data breaches and unauthorized access (two-factor authentication, a profile auto-lock after 5 failed login attempts, etc.)
CarolAnn Tutera, CEO at SottoPelle: “I couldn’t be happier with everything they’ve done for us and with us. Everything has been delivered on time. Great bunch of people to work with. I highly recommend them.”
Project Details
Business Challenge
Because of the technical complexity of the project our client was willing to bring to life, they were looking for a well-equipped technical team that could handle a large amount of work, had experience developing HIPAA-compliant solutions, and could cooperate with other experts (like doctors and lawyers).
At the same time, the IT provider should not only have profound healthcare industry expertise and state-of-the-art technology mastery but also understand the needs of the target audience. The goal was to make the solution user-friendly and intuitive, even for doctors who have never used a digital hormone dosage calculator before, as the platform also helps to popularize bioidentical hormone replacement therapy.
Implementation
The algorithm itself was implemented as a separate system module with maximum test coverage. To guarantee the excellent quality of the digital product, we’ve utilized the following instruments:
- Test cases
- Autotests
- Unit test for critical system modules
- Manual testing
- Smoke and regression testing
- Software Composition Analysis via SonarQube
- Error tracking via Sentry
- Design the platform’s architecture according to AWS and HIPAA standards
- Set up two-factor authentication (password + SMS or email confirmation code)
- Check sessions from another IP and auto-lock the user after 5 failed login attempts
- Force logout after a period of being idle and force a password change every 3 months
- Implement data encryption and SSL/HTTPS traffic protection + database encryption in the rest
- Incorporate audit log to record and track access to protected health information
- Introduce 5 different user roles with different access levels to the platform’s functionality
- Cross-site scripting (XSS) protection
- Cross-site request forgery (CSRF) protection
- SQL injection protection
- Clickjacking protection
- Additional host header validation
Solution Delivered
The system was designed to be used by doctors and healthcare workers (practice administrators, support staff) and consists of generally accessible and private functionality. Features like a blog, provider search (including a filtering system), free educational resources, and company contact info are public. However, all of the complex functionality intended for internal use, like the hormonal dosage calculator, different types of reports, activities log, consultation requests, insertion note templates, etc., is available only upon authorization.
While the core of the application, which is a hormone dosage calculation algorithm, is very complex and depends on many changing parameters, the platform itself is very easy-to-use. All the medical professional has to do is log in, choose the patient type, fill in a simple form, and click “calculate.”The precise algorithm will come up with the correct dosage in a matter of seconds.
Depending on the user’s role, they get access to specific parts of the platform’s functionality. For example, doctors can manage patients and related information (e.g. labs, site notes, prescriptions), consult, calculate the hormone dosage, and manage insertion note templates and sticky notes. On the other hand, the support staff members (nurses, receptionists, etc.) are able to work with most of the features listed above but have no access to the dosage calculator. Such limitations, complemented by additional security measures like a forced log out after a period of being idle, help to prevent unauthorized access attempts and protect sensitive information.
To make the software even more convenient for the user, it supports multiple sought-after integrations like Cerbo EMR or Twilio for SMS notifications.
The introduction of additional services which complement the core functionality not only simplifies the interaction between physicians and patients but between our client and the healthcare providers as well. The medical facilities opting for this solution get access to a set of instruments that allow their practitioners deliver unique treatment plans based on the patients’ needs (therapy for men, women, transgender persons, people diagnosed with Parkinson’s disease or traumatic brain injury, etc.)

Business Outcome
The solution was carefully tested in different countries by hundreds of medical facilities. The physicians noted the system’s fail-safeness, robustness, and ease of use, which gave our client a significant competitive advantage and safeguarded the platform’s commercial success.
The platform’s quality was recognized by the healthcare professionals community and named the “Easiest HRT Dosing Platform.” For several years our client’s company remains one of the market leaders in bioidentical hormone replacement therapy, and the number of practices choosing to utilize their original HRT dosing method and a hormonal dosage calculator is constantly growing.
The fact that the system is fully HIPAA-compliant helps boost the audience’s loyalty and the solution’s credibility while flawless technical execution and constant control minimize the risks of error.