logo
hamburger-menu-icon
Back to Projects

EpiToMe

DNA diagnostic testing

EpiTOme Genetics needed its offshore development team held to PIPEDA compliance while building a diagnostic tracking app for pharmacies and patients. Ollon served as fractional CTO, overseeing the offshore team's workflow, budget, and quality, and writing the policies needed to meet healthcare security requirements. EpiTOme launched its application nationally with documented compliance practices in place.

EpiTOme Genetics is a Canadian biotechnology company that provides individuals, businesses and healthcare providers with state of the art diagnostic and health screening tools. Working with an offshore dev team, they were developing a new application which enabled their service to scale and streamline, allowing pharmacies and patients to track the progress of samples being tested and see the results reported. The application also needed PIPEDA compliance to meet the security measures required by a number of clients.

Ollon was brought in to provide fractional CTO services; overseeing the offsite team, workflow, budgets, quality and compliances, as well as developing new policies and procedures. They worked directly with Epitome's clients while nurturing the dev team to ensure the security requirements would be met.

Given the critical nature of security compliance in the healthcare space, having the knowledge and expertise of Ollon's fractional CTO supervising the team and project provided confidence in the performance and delivery as well as the security and compliance required in order to launch the application nationally.

Java, AngularJS, Postgresql, Google Cloud

Our Expertise in Action

Fractional CTO

Building a new application with an offshore development team left EpiTOme without anyone in the CTO seat to manage that team's workflow, budget, or the quality of what they were producing. Ollon provided fractional CTO services to fill that role directly, taking ownership of the offshore team's day to day management alongside the quality and compliance standards the application needed to meet. That oversight meant EpiTOme had a single accountable technical leader instead of an offshore relationship running without anyone responsible for how it performed. The company launched its application nationally with the confidence that came from having that oversight in place throughout development, not added after problems appeared.

Security policy and procedure development

Handling sensitive personal health information meant EpiTOme's diagnostic application had to meet PIPEDA's requirements around consent, safeguards, and accountability before healthcare clients would accept it. Ollon developed the policies and procedures needed to satisfy those requirements, translating principles like limiting how personal information was collected and used into concrete practices the offshore team could build against. That policy work gave EpiTOme something specific to point to when clients asked how patient data was protected, not a general assurance that security mattered. The application launched with documented practices behind it, not just working code that happened to handle data responsibly.

Team mentoring and coaching

Building compliant, secure software was a new discipline for EpiTOme's offshore development team, who had the technical skill to write the application but not necessarily the rigor needed to build it to a healthcare compliance standard. Ollon worked directly with that team, coaching developers on why specific security requirements existed and how to build them into the application from the start. That hands on coaching meant the team's own understanding of secure development practices grew alongside the application itself. EpiTOme ended up with a team that could sustain the security standard on its own without needing an outside reviewer to check every release.

Software advisory and IT strategy

EpiTOme had already committed to running its diagnostic application on Google Cloud, but choosing the platform was only the starting point for meeting its healthcare and pharmacy clients' security expectations. Ollon set the IT strategy for how that environment actually got configured, segmenting each environment into its own VPC with firewalls scoped to only necessary access, enabling Cloud Armor against denial of service attacks, and setting up Security Command Center and Cloud Monitoring for ongoing benchmark checks and alerting. That configuration work turned Google Cloud from a hosting decision into a security control the company could point to, built specifically for the compliance bar its clients expected.