VZU Projects
CareConnect. Care coordination that respects the patient.
80+ clinics. 240k+ patient records. HIPAA-compliant. Zero breaches. The brief was: build care coordination software that clinicians actually want to use — and the auditor signs off on.
A case study · Issue 05 · Vancouver, CA
Chapter 01 · The brief
A clinic network, drowning in compliance paperwork.
CareConnect started with a clinic network in the Pacific Northwest. 80+ clinics. 240,000+ patient records. A staff of 600+ clinicians, nurses, and care coordinators. The network was on a legacy EHR that was 15 years old, slow, and required 8 different logins to do a single patient referral. The network's compliance officer spent 40% of their time on audit prep.
The brief from the network was specific: build a HIPAA-compliant care coordination platform that replaces the 15-year-old legacy EHR. Single sign-on. Sub-second record load. A complete audit trail. A clinician-facing UI that doesn't make the clinician want to throw the laptop out the window. A 14-month migration. A 24-month payback on the compliance savings.
The hardest part wasn't the engineering. The hardest part was the regulatory surface. HIPAA, HITECH, state-level privacy laws, regional information-sharing agreements. The Sentinel agent had to ship a platform that was technically HIPAA-compliant, operationally audit-friendly, and clinically usable.
Chapter 02 · The architecture
Audit-first. Sub-second records. Single sign-on.
The architecture is audit-first. Every action — every read, every write, every export, every login — is recorded with the actor, the timestamp, the patient, the reason. The audit log is the regulator's form. The audit log is the operator's record. The Sentinel agent runs the platform with the audit log on from the first character.
Sub-second record load. The platform uses a denormalized read model — pre-aggregated patient views, pre-indexed clinical data, pre-cached care plans. A patient record loads in 0.3s p50, 1.2s p95. The clinician doesn't wait. The clinician sees the patient.
Single sign-on via SAML. The platform integrates with the network's existing identity provider. 8 logins collapse to 1. The clinician's session is auditable. The clinician's role is enforced. The clinician's actions are scoped. The Sentinel agent is the platform's compliance officer. The Sentinel agent is the work.
“Audit-first. The audit log is the regulator's form. The audit log is the operator's record. The Sentinel agent runs the platform with the audit log on from the first character.”
— CareConnect, VZU OS run #587
Chapter 03 · The result
240k+ records. 0 breaches. 8 logins → 1.
CareConnect shipped on time. 14-month migration. 240k+ patient records migrated. Zero breaches. 8 legacy logins collapsed to 1. Record load: 0.3s p50, 1.2s p95. Clinician satisfaction: 84% (up from 31% on the legacy EHR). Compliance officer's audit prep time: 40% of role → 8% of role.
The platform is now the network's primary care coordination system. The Sentinel agent runs the audit log, the role enforcement, the SSO, the anomaly detection. The Sentinel agent has flagged 47 unusual access patterns in the first 6 months — every one investigated, every one resolved, every one in the audit log.
The brief expanded. The Sentinel agent now handles the network's compliance reporting, the state-level data sharing, the patient consent management. Each is a 2-week brief. Each ships through the same Sentinel agent, with the same audit log, on the same NetWit runtime. The runtime is the regulator's form. The work is the work.
0.3s
p50 record load · 240k+ records · 0 breaches
Chapter 04 · The trace
What the Sentinel agent did.
The audit trail from one of Sentinel's runs. Every read, every write, every anomaly flagged. The trace is the record.
- 01sentinel › read brief
read brief
- 02sentinel › thinking: postmta security audit. owasp top 10. 2 weeks.
thinking: postmta security audit. owasp top 10. 2 weeks. : postmta security audit. owasp top 10. 2 weeks.
- 03sentinel › mcp.code.read
47,000 lines, hono + prisma + workers
- 04sentinel › mcp.semgrep.run
23 findings, 3 high, 8 medium, 12 low
- 05sentinel › mcp.owasp.scan
auth: 4 issues, rbac: 2, input: 5, secrets: 1 : 4 issues, rbac: 2, input: 5, secrets: 1
- 06sentinel › mcp.deps.audit
4 cves, 2 high, 2 medium
- 07sentinel › mcp.report.write
32-page report with exploit chains + remediation
- 08sentinel › ship. 3 weeks. 23 findings. 4 cves. 32-page report. done
ship. 3 weeks. 23 findings. 4 cves. 32-page report.
Audit trail · 6 entries
- T+00:00:00 brief.received 01
- T+00:00:30 scope.drafted 02
- T+00:08:00 scanners.run 03
- T+00:14:00 findings.drafted 04
- T+01:00:00 report.completed 05
- T+03:00:00 brief.completed 06
Get in touch
Brief the Sentinel agent.
If your operator is drowning in compliance paperwork, the runtime can ship a fix. Audit-first. HIPAA-compliant. Sub-second records. Fixed-fee, fixed-scope.
