Senior AI Developer - HIPAA-Compliant Healthcare AI Platform
Worldwide
Type: Contract / Freelance with potential for long-term engagement Location: Remote Focus: AI/LLMs, Healthcare, HIPAA Compliance, RAG & Secure Application Development About the Project We are developing a private AI-powered healthcare platform that enables authorized users to securely interact with AI, proprietary knowledge bases, and uploaded documents. The platform includes conversational AI, Retrieval-Augmented Generation (RAG), document analysis, voice functionality, and secure user-specific data storage. A critical component of the platform involves users uploading and working with medical records and other documents that may contain Protected Health Information (PHI). We are looking for a highly experienced Senior AI Developer / Full-Stack AI Engineer who has genuine, hands-on experience designing and developing HIPAA-compliant applications that process PHI. This is not simply an AI development role. We need someone who understands the intersection of: AI Engineering + Healthcare Data + Security + HIPAA Compliance You will initially review our existing architecture, identify potential security and compliance gaps, recommend the appropriate architecture, and help implement those improvements. Current Technology Stack Our current stack includes: AI & LLM * Anthropic Claude API * Retrieval-Augmented Generation (RAG) * Vector search / embeddings * Proprietary knowledge bases * Document and image understanding * Voice AI / speech functionality Frontend * Next.js * React * Tailwind CSS Backend * Python * FastAPI * Streaming AI responses * Server-side API integrations Database & Infrastructure * PostgreSQL * PostgreSQL vector search * Redis where appropriate * Railway * GitHub / automated deployments * Separate frontend and backend services Authentication & Security * JWT-based authentication * Server-side API key management * Private user accounts * User-specific chat and document storage Document Processing The platform supports processing of files including: * PDFs * Word documents * Excel files * Images * CSV * JSON * Markdown * Text files Some uploaded documents may contain PHI and highly sensitive medical information. Key Responsibilities You will help us: * Conduct a technical and HIPAA-focused audit of the existing application. * Map the complete PHI data lifecycle across the platform. * Identify potential HIPAA, security, infrastructure and privacy vulnerabilities. * Design and implement a HIPAA-appropriate technical architecture. * Review third-party services that may receive, process, transmit or store PHI. * Determine where Business Associate Agreements (BAAs) are required. * Ensure only appropriate vendors/services are included within PHI workflows. * Build secure medical-record upload and processing pipelines. * Implement appropriate encryption at rest and in transit. * Implement secure authentication, authorization and access controls. * Implement audit logging and access tracking. * Prevent PHI from leaking into application logs, analytics, monitoring or unsupported third-party services. * Review database security, backups, retention and deletion processes. * Secure LLM integrations involving PHI. * Improve our existing RAG and vector-search architecture. * Improve AI response quality, reliability and grounding. * Develop backend functionality using Python/FastAPI. * Work with our Next.js/React frontend where required. * Improve application scalability, reliability and performance. * Document the architecture and security controls. HIPAA Experience Is Essential Please do not apply unless you have hands-on experience developing HIPAA-compliant applications or healthcare software that handles PHI/ePHI. We are specifically looking for someone who understands: * HIPAA Privacy Rule * HIPAA Security Rule * PHI / ePHI * Business Associate Agreements (BAAs) * HIPAA-eligible cloud services * Encryption at rest and in transit * Role-Based Access Control (RBAC) * Principle of least privilege * Audit controls and audit trails * Secure authentication and session management * Secure medical-record storage * Secure document processing * Data retention and secure deletion * Backup and disaster recovery * Secrets management * Database security * Logging and monitoring involving PHI * Third-party/subprocessor risk * Incident response * Secure AI/LLM implementation involving PHI You should understand that HIPAA compliance involves significantly more than simply encrypting a database or signing a BAA with an AI provider. We need someone capable of reviewing the entire PHI lifecycle, including: User → Application → API → File Processing → Storage → LLM → RAG/Vector Database → Response → Logging/Monitoring → Backups → Deletion AI / LLM Experience You should also have strong experience building production AI applications, ideally involving: * Anthropic Claude API * OpenAI or comparable LLM APIs * RAG architectures * Vector databases / pgvector * Embeddings * Document ingestion pipelines * Chunking and retrieval strategies * Prompt engineering * Context management * Streaming * Structured outputs * Tool/function calling * AI hallucination reduction * Secure AI architecture Experience building AI applications where users upload large or sensitive documents for analysis is particularly valuable. Technical Experience Strong experience with several of the following is expected: * Python * FastAPI * PostgreSQL * pgvector / vector search * Next.js * React * TypeScript / JavaScript * Tailwind CSS * REST APIs * JWT / authentication * Redis * GitHub * Cloud infrastructure * Secure file storage * Encryption * Secrets management * Logging / monitoring * CI/CD Experience designing HIPAA workloads on AWS, Azure or Google Cloud is highly desirable. Initial Scope The first stage of the engagement will focus on technical architecture and HIPAA readiness. You will be expected to: 1. Review the existing architecture. 2. Map where PHI could be transmitted, processed, stored or logged. 3. Review infrastructure and relevant third-party vendors. 4. Identify HIPAA/security gaps and high-risk areas. 5. Determine which services can remain and which should be replaced or reconfigured. 6. Recommend an appropriate production architecture. 7. Produce a prioritized remediation roadmap. 8. Help implement the agreed changes. 9. Establish development practices to help maintain compliance as the platform evolves. Ideal Candidate We would particularly like to hear from developers who have previously: * Built healthcare SaaS applications handling PHI. * Built AI applications involving healthcare or sensitive data. * Led or contributed to HIPAA technical readiness. * Designed secure medical-document processing pipelines. * Integrated LLMs into applications handling PHI. * Implemented RAG systems for confidential documents. * Worked with BAAs and HIPAA-eligible cloud infrastructure. * Participated in healthcare security/compliance reviews. When Applying Please answer the following questions in your application: 1. Describe a HIPAA-compliant application you have personally helped architect or develop. 2. What types of PHI/ePHI did the application process? 3. What technical controls did you implement to protect PHI? 4. Which cloud infrastructure did you use? 5. Have you worked with BAAs and evaluated third-party vendors that process PHI? 6. Have you built production applications using LLMs or RAG? Please describe them. 7. How would you approach reviewing an existing AI application for HIPAA readiness? 8. What is your experience with Python, FastAPI, PostgreSQL and Next.js? 9. What is your current availability? Generic applications stating only that you are “familiar with HIPAA” will not be considered. We are specifically looking for someone with demonstrable, hands-on experience. Bonus Experience Experience with any of the following is advantageous: * SOC 2 * HITRUST * NIST security frameworks * Healthcare SaaS * Medical-record processing * Healthcare AI * Penetration testing / vulnerability management * Infrastructure-as-Code * AWS/Azure/GCP HIPAA architectures * Secure AI agent architecture * LLM observability and evaluation * Voice AI What Success Looks Like Our goal is to build a secure, scalable AI platform capable of handling sensitive healthcare information appropriately. We are looking for someone who can combine senior-level AI engineering expertise with genuine healthcare security and HIPAA experience - and who can both advise on the correct architecture and implement it.
- More than 30 hrs/weekHourly
- 6+ monthsDuration
- ExpertExperience Level
$15.00
-
$25.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:50+
- Last viewed by client:3 days ago
- Interviewing:0
- Invites sent:0
- Unanswered invites:0
About the client
- GBRBasildon3:50 AM
- $111 total spent3 hires, 2 active
- 9 hours
- Tech & ITSmall company (2-9 people)
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by