Clozure · TypeScript · private

From insurance verification to a complete claim package, in one place.

A platform where wound-care manufacturers and the care facilities they supply handle verification, orders, shipping and Medicare paperwork together, in place of spreadsheets, email and shared drives.

Where it came from

As COO of a medical distributor I ran this workflow by hand before I built anything. Each manufacturer had its own insurance-verification form. Nobody could see where an order stood without asking. I couldn't find a product that covered the whole path, so I designed and built one for the business.

Clozure is that platform rebuilt as a product other companies can use. Manufacturers and facilities each get their own account, and they work together only where a contract between them says they do.

What it does, in order

  1. Patient and wound. The facility records the patient and the wound being treated.
  2. Insurance verification. The facility completes the manufacturer's own verification form inside the platform.
  3. Order. The order is priced from the contract and checked against Medicare's local coverage rules before it can be placed.
  4. Fulfilment. The manufacturer allocates a lot and ships.
  5. Delivery. Carrier tracking follows the shipment through to proof of delivery.
  6. Documentation. A checklist shows what the coverage rule requires and what is still missing.
  7. Claim package. The platform exports the complete set of documents a biller needs: the order, the clinical note, proof of delivery, the invoice and the claim form.

It stops at the claim package on purpose. Submitting claims electronically and handling payments and appeals are not built.

Who uses it

On the facility side: skilled nursing, long-term care, wound clinics, hospital outpatient departments and physician practices. Each has roles for administrators, directors of nursing, clinical leads, physicians, staff and billing, and each role sees only what it needs.

On the manufacturer side: the people who fill and ship the orders.

Built for HIPAA

  • Access by role, down to the field. Permissions are set per role and per field, and one organization cannot see another's records without a contract linking them.
  • Patient data encrypted field by field, with the keys held in a managed key service, separate from the database.
  • An audit log that shows tampering. Each entry is chained to the one before it, an automated job checks the chain, and records are kept for seven years.
  • Multi-factor sign-in required for every operational role, and sessions that time out when idle.
  • A documented path for emergencies: support access to an account goes through a recorded elevation, with a written break-glass procedure.

How it is built

  • 1,300+Commits in five months
  • About 100Data models
  • WebReact on a NestJS and tRPC API
  • CloudPostgres on Google Cloud, defined in Terraform

I designed the product, the data model and the security approach, and built it with AI coding agents working under review. The code is private.