AI-Assisted Injection Mapping
Interactive SVG anatomy maps across neurotoxin, filler, and body modes, with facial-landmark tracking and a ghosted overlay of a client's past injection sites.
A full operating system for medspas and aesthetic clinics — clinical charting with AI-assisted injection mapping, front-desk scheduling, an AI growth engine, a branded patient app, and HIPAA-conscious payments, replacing paper forms, spreadsheets, and a patchwork of disconnected tools.
Private client project — shared here with permission.
Medspas run on relationships — a client's treatment history, preferences, and upcoming appointments all need to be at a provider's fingertips, and the business behind it needs a real growth engine, not a spreadsheet. ADEPT MedSpa OS is being built as one connected platform covering all of it: an operator portal for the clinic, a branded app for patients, an AI-powered CRM and marketing engine, and payments — replacing the usual mix of paper forms, a generic calendar, a separate booking app, and a spreadsheet for packages.
I'm building it end to end — the data models and infrastructure, the clinical charting and AI injection-mapping tools providers use chairside, the patient-facing mobile app, and the AI-driven CRM and campaign engine that runs the clinic's growth.
Front-desk staff and providers needed a single source of truth for client records, treatment history, and scheduling — without juggling paper intake forms, a separate calendar app, and a spreadsheet for billing and packages. Injection sites and dosages were tracked on paper diagrams, with no historical overlay to reference at a follow-up visit. Marketing and lead follow-up were manual and inconsistent, patient communication had no dedicated channel, and payment processing had no clear separation between financial and health data — a real compliance risk as the clinic grows.
The build is structured as a 32-week, 16-sprint roadmap across four phases: a foundation phase (auth, infrastructure, the operator shell, and clinical charting with the injection mapper); a CRM and patient app phase (lead pipeline, payments, and the first version of the patient mobile app); an AI and campaigns phase (AI-generated marketing campaigns, predictive analytics, and prescription workflows); and a final polish and launch phase (security hardening, a HIPAA compliance review, accessibility audit, and production launch).
Underneath, it's React Native and Node.js on PostgreSQL and AWS RDS, with row-level security policies enforced at the database layer, Stripe Connect handling payments with no PHI ever touching Stripe's side, and Claude AI powering the patient chat assistant, campaign content generation, and lead scoring.
Interactive SVG anatomy maps across neurotoxin, filler, and body modes, with facial-landmark tracking and a ghosted overlay of a client's past injection sites.
Patient charts with clinical, profile, and billing tabs, structured treatment records, before/after photo uploads, and a running timeline of tasks and notes.
A face/body/virtual time-grid schedule, a searchable patient registry with status pills, and staff management with role-based access.
A lead pipeline Kanban with AI lead scoring, an AI campaign studio generating email/SMS/push content, and predictive treatment-demand forecasting.
A 4-step booking flow, treatment history, an AI chat assistant, push notifications, and the Glow Club loyalty program with tiers and referrals.
Stripe Connect checkout with no PHI ever touching Stripe, gift cards and a wallet system, prescription PDF generation, and per-provider revenue analytics.
Client and treatment data are sensitive by nature, so compliance isn't a phase bolted on at the end — it's built in from Sprint 1. Row-level security policies are enforced at the database layer, every action is written to an audit log, and error monitoring has PII scrubbing verified before any provider ever sees a stack trace. Business Associate Agreements are being put in place with every vendor that could touch patient data, including AWS and Anthropic. The launch phase includes a third-party penetration test, a formal HIPAA compliance review, and a WCAG 2.1 AA accessibility audit — not just a feature checklist, but an actual pre-launch gate the platform has to pass.
The foundation, clinical charting, and injection mapper are built and demoed; the CRM, payments, and the first version of the patient app are in progress now. What's ahead: the AI campaign studio and predictive analytics, prescription workflows, then a dedicated security-hardening and compliance-review sprint before a planned production launch — App Store submission, DNS cutover, admin training, and a delivered HIPAA compliance binder.
Development is fully remote, with scheduling built around each client's own timezone. I currently work with medspa and aesthetic clinic owners in:
CRMs built around how your team actually works, not a generic template — let's talk about yours.
Start a Project