
Modernized Web Portal for Healthcare (PBM) with AI-Powered UX
Healthcare PBM Organization
Overview
Designed and delivered a modern, modular web portal for a large-scale PBM organization — replacing legacy reporting interfaces with a microfrontend architecture that supports per-customer feature enablement, AI-powered search and navigation, and role-based access across complex PBM hierarchies.

Client Profile
The Challenge
Creating a pluggable base architecture with independent module deployment
Unified authorization for both human users and M2M integrations
Granular access control aligned to PBM hierarchy (payer > employer group > plan > member)
Need for AI-powered search and intelligent navigation across millions of records
Solution Architecture
Implemented microfrontends with Single SPA — each module (Claims Search, Formulary Lookup, Reporting) developed as a standalone React app with its own CI/CD pipeline.
Built reusable API Gateway custom authorizer validating JWTs, loading permissions from MongoDB. Designed dual authentication model for human users (Cognito) and machine clients (OAuth2).
Integrated AI-powered search and smart filtering for rapid claim and member lookups across large datasets.

Architecture Diagram — Modernized Web Portal for Healthcare (PBM)
Features & Capabilities
Microfrontend Architecture
Independent React modules deployed and composed at runtime via Single SPA
Plug-and-Play Module System
Each feature is a standalone module with independent CI/CD
AI-Powered Search
Intelligent search across millions of claims and member records with smart filtering
Granular Access Control
Frontend feature-level UI visibility; Backend route-level authorization
Dual Authentication Model
Human users via Amazon Cognito (JWT); Machine clients via Cognito app clients (OAuth2)
M2M Integration Layer
Secure APIs exposed via API Gateway with consistent authentication
Tenant-Based Configuration
Module enablement, UI branding, and access rules dynamically configured per customer
Event-Driven Scalability
SQS and Kafka for async workflows
Real-Time Observability
Datadog RUM for frontend, CloudWatch for backend
Zero-Downtime Deployments
Serverless + immutable deployments
Technology Stack
Security & Compliance
Users via Cognito User Pool; Machines via Cognito App Client with OAuth2
Custom authorizer generates dynamic IAM policies based on user's PBM hierarchy
TLS 1.3 enforced across all endpoints; all data encrypted at rest
Microfrontends run in isolated contexts; authorization checked independently
HIPAA (with BAA), SOC 2 Type II, NIST SP 800-53, OWASP Top 10
Results & Impact
Feature Delivery Speed
0%
80% faster
Customer Enablement
0%
100% customer-specific configurations
Compliance
HIPAA-ready
Concurrent Users
Up to 10k (peak load)
Deployment Frequency
0+
20+ deploys/month (per module)
Team Size
0
6-8 developers (full-stack)
Duration
0
1.5 years (Aug 2025 completion)
Have a Similar Challenge?
We'd love to hear about your project and explore how we can help.