From MVP to Millions

HAD Digital's infrastructure blueprint for scaling home hospitalization care across France β€” from a single-patient pilot to a national platform serving hospitals, nurses, doctors, and patients.

10M+ Target Users
99.99% Uptime SLA
<200ms API Latency
50K Concurrent Users
01 β€” System Architecture

Six-Layer Production Architecture

Each layer is independently scalable, monitored, and replaceable. The design prioritizes patient data isolation, regulatory compliance (RGPD/HDS), and sub-second response times.

πŸ“±
Client Layer
EDGE
Patient Mobile App
React Native / Flutter
Clinician Web Portal
React / Next.js
Hospital Admin Panel
React / Next.js
Offline PWA
Service Workers
↕
🌐
CDN & Edge Layer
GLOBAL
CloudFront / CDN
Static Assets + Cache
WAF
DDoS + Bot Protection
Edge Functions
Auth + Rate Limiting
SSL/TLS
Let's Encrypt / ACM
↕
⚑
API Gateway Layer
STATELESS
API Gateway
Kong / AWS API GW
Load Balancer
ALB / Nginx
Auth Service
OAuth2 / JWT / OIDC
Rate Limiter
Redis + Token Bucket
↕
πŸ”§
Microservices Layer
K8s
Patient Service
Python / FastAPI
Symptom Engine
CTCAE Grading
Alert Service
Rule Engine + ML
Notification Service
Push / SMS / Email
Report Service
File Processing
Messaging Service
WebSocket / SSE
↕
πŸ’Ύ
Data Layer
HDS
PostgreSQL
Primary Database
Redis Cluster
Cache + Sessions
S3 / MinIO
File Storage
Elasticsearch
Search + Logs
↕
πŸ—οΈ
Infrastructure Layer
IaC
Kubernetes
EKS / AKS / GKE
Terraform
Infrastructure as Code
Prometheus + Grafana
Monitoring
ELK Stack
Centralized Logging
02 β€” Scaling Strategy

Three-Phase Growth Path

From a single-server MVP to a multi-region deployment serving every hospital in France. Each phase is designed to be self-funding from the previous phase's revenue.

Component Phase 1: MVP 0–10K Phase 2: Growth 10K–500K Phase 3: Enterprise 500K–10M+
Compute Single VM (4 vCPU, 16GB RAM)
Docker Compose
Kubernetes cluster (3–10 nodes)
Auto-scaling pods
Multi-region K8s (20–100 nodes)
Spot instances + reserved capacity
Database PostgreSQL (single instance)
Read replica for reporting
PostgreSQL (primary + 2 replicas)
Connection pooling (PgBouncer)
Citus distributed PostgreSQL
Sharded by tenant (hospital_id)
Cache Redis (single instance, 2GB) Redis Sentinel (3 nodes, 16GB) Redis Cluster (6+ nodes, 64GB)
Per-service cache namespaces
File Storage Local disk + daily backup S3-compatible storage
CDN for static assets
Multi-region S3
Geo-replicated + encrypted at rest
Search PostgreSQL full-text search Elasticsearch (3-node cluster) Elasticsearch (10+ nodes)
Dedicated search microservice
Auth JWT + bcrypt
Session-based fallback
OAuth2 / OIDC provider
MFA (TOTP + SMS)
Enterprise SSO (SAML)
Provisioning (SCIM)
Monitoring Docker logs + basic metrics Prometheus + Grafana
PagerDuty alerts
Full observability stack
APM (Datadog / New Relic)
CI/CD GitHub Actions
Manual deploy
GitHub Actions + ArgoCD
Staging + production
GitOps (Flux/ArgoCD)
Canary deployments
Backup Daily pg_dump
S3 offsite copy
Continuous WAL archiving
Point-in-time recovery
Cross-region replication
RPO < 1 min, RTO < 15 min
Cost/month €200–500 €2,000–8,000 €20,000–80,000
03 β€” Infrastructure Components

What You Need to Deploy

Every component listed here is required for production deployment. The MVP currently runs as a single-process Python server; this is what the production version looks like.

πŸ”
Authentication & Authorization

OAuth2/OIDC provider with role-based access control. Supports MFA, session management, and audit logging. HDS-compliant password policies.

Keycloak JWT RBAC MFA
πŸ“Š
Database & Persistence

PostgreSQL with read replicas, connection pooling, and automated backups. Encrypted at rest (AES-256) and in transit (TLS 1.3).

PostgreSQL 16 PgBouncer pgBackRest WAL
⚑
API Gateway & Load Balancing

Traffic management with rate limiting, request validation, circuit breaking, and health checks. Routes to healthy service instances.

Kong Nginx ALB gRPC
πŸ””
Notification System

Multi-channel notifications: push (FCM/APNs), SMS (Twilio), email (SendGrid), and in-app WebSocket. Priority-based routing for critical alerts.

FCM Twilio SendGrid WebSocket
πŸ“
File Storage & Processing

Secure file upload for lab results, imaging, and reports. Virus scanning, format validation, and thumbnail generation. GDPR-compliant retention policies.

S3 ClamAV ImageMagick PDF.js
πŸ“ˆ
Monitoring & Observability

Full-stack monitoring: infrastructure metrics, application traces, log aggregation, and alerting. SLO tracking for uptime and latency.

Prometheus Grafana Loki Tempo
πŸ€–
AI/ML Pipeline

Symptom pattern recognition, risk prediction, and clinical decision support. Runs inference on patient data to predict adverse events 24–48h early.

PyTorch MLflow ONNX Seldon
πŸ₯
HL7 FHIR Integration

Standard interoperability with hospital俑息系统 (HIS), electronic health records (EHR), and lab systems. Supports ADT, ORM, ORU messages.

FHIR R4 HAPI FHIR Mirth Connect DICOM
04 β€” Request Flow

How a Patient Report Travels

From a patient tapping "Report Symptom" on their phone to a doctor receiving a graded alert β€” the complete journey through the system.

01
Patient
Reports symptom
via mobile app
β†’
02
CDN/WAF
TLS termination
Bot detection
β†’
03
API Gateway
Auth validation
Rate limiting
β†’
04
Symptom Engine
CTCAE grading
Risk assessment
β†’
05
Alert Router
Severity check
Escalation rules
β†’
06
Notification
Push + SMS
to assigned nurse
β†’
07
Dashboard
Real-time update
for care team
05 β€” Capacity Planning

Performance at Scale

Projected capacity requirements for serving 10 million users across France. Based on typical healthcare usage patterns: 2–3 readings/day per patient, peak hours 8am–10am and 6pm–8pm.

50K
Concurrent Users
500K
API Requests/sec
2TB
Daily Data Ingestion
500TB
Total Storage (5yr)
Resource Calculation Phase 2 Phase 3
API Servers 500K req/s Γ· 5K req/s per pod = 100 pods 20 pods (8 vCPU, 16GB each) 100+ pods across 3 regions
Database 10M patients Γ— 3 readings/day Γ— 500 bytes = 15GB/day Primary: 32 vCPU, 256GB RAM
2 read replicas
Citus cluster: 8 nodes
Sharded by hospital
Redis Cache 10M sessions Γ— 2KB = 20GB
Hot data: 100GB
3-node Sentinel, 32GB 6-node Cluster, 128GB
File Storage 10M patients Γ— 5 reports Γ— 2MB = 100TB S3 Standard: 10TB S3 Intelligent Tiering: 100TB+
Bandwidth 500K req/s Γ— 10KB avg = 5GB/s 1 Gbps sustained 10 Gbps + CDN offload
06 β€” Cost Estimates

Infrastructure Investment

Monthly cloud costs for each phase. Prices based on AWS eu-west-3 (Paris) region. Includes compute, storage, networking, and managed services.

Phase 1 β€” MVP
€300 /month
Single hospital pilot
Up to 1,000 patients
  • 1Γ— t3.xlarge (4 vCPU, 16GB)
  • 1Γ— RDS db.t3.large (PostgreSQL)
  • 1Γ— ElastiCache cache.t3.medium
  • S3: 100GB
  • CloudWatch basic monitoring
  • Daily backups, 7-day retention
Phase 3 β€” Enterprise
€50,000 /month
National platform
10M+ patients
  • Multi-region EKS: 50+ nodes
  • Citus distributed PostgreSQL
  • Redis Cluster: 6 nodes, 128GB
  • S3: 100TB + global CDN
  • Full observability (Datadog)
  • Cross-region DR, RPO < 1min
07 β€” Implementation Roadmap

From Here to Production

A pragmatic 18-month path from the current MVP to a production-ready platform serving real patients in real hospitals.

Month 1–2 β€” Foundation
Production Infrastructure Setup
Provision Kubernetes cluster, PostgreSQL, Redis, and S3. Set up CI/CD pipeline with GitHub Actions + ArgoCD. Implement infrastructure as code with Terraform. Deploy staging environment.
Month 3–4 β€” Security & Compliance
HDS Certification & RGPD Compliance
Deploy Keycloak for authentication. Implement RBAC with 8 roles. Add MFA for clinicians. Complete RGPD data protection impact assessment. Begin HDS certification process.
Month 5–6 β€” Integration
Hospital System Integration
Implement HL7 FHIR R4 adapter. Connect to hospital EHR systems via Mirth Connect. Build ADT message handling for patient admissions/discharges. Test with 3 pilot hospitals.
Month 7–9 β€” Scale
Performance & Reliability
Load test to 10K concurrent users. Implement auto-scaling policies. Set up Redis Sentinel for HA. Configure continuous database replication. Deploy monitoring stack (Prometheus + Grafana).
Month 10–12 β€” Intelligence
AI/ML Pipeline
Train symptom prediction models on pilot data. Implement real-time risk scoring. Build clinical decision support alerts. Deploy ML inference service with ONNX Runtime.
Month 13–18 β€” National Rollout
Multi-Region Deployment
Deploy to 3 French regions. Implement tenant isolation per hospital. Add enterprise SSO (SAML). Complete HDS certification. Launch production with 50+ hospitals.