Case Study - HIPAA-Compliant Case Note Platform for Behavioral Health
Designing and building a cross-platform, HIPAA-compliant case note application that replaced paper workflows across three community programs for a nonprofit behavioral health organization.
- Client
- Mental Health America
- Year
- Service
- Custom Application Development, HIPAA Compliance Engineering

The Challenge
Mental Health America of the Palm Beaches (MHA) - a nonprofit organization dedicated to creating a support community where all people can flourish - operates multiple community programs including Clubhouses, Mental Health Court, and Peer Place, serving hundreds of individuals across Palm Beach County, Florida.
MHA's staff were drowning in paper and manual processes. Case notes across three separate programs were being captured inconsistently - handwritten, emailed, or entered into disconnected spreadsheets. Supervisors had no centralized way to audit staff activity, and compliance reviews required hours of manual searching through records.
The specific pain points:
- No standardized data entry - staff typed names differently every time, making records nearly impossible to filter and search
- No audit trail - supervisors couldn't efficiently review which staff were documenting what, or export records for compliance
- Fragmented programs - three distinct programs each had different intake forms and case note workflows, with no unified view
- HIPAA exposure - paper forms and emailed PDFs created unnecessary risk for protected health information
- Field reliability - staff working in community settings often experienced connectivity issues, losing completed form data on submission
The Solution
We designed and built a HIPAA-compliant, cross-platform case note application from the ground up - replacing paper and patchwork systems with a single digital platform accessible on tablets, phones, and desktops.
Multi-Program Form System
Eight standardized digital forms spanning three programs, each tailored to its program's specific requirements - including Intake Forms, Case Notes, Authorization for Release of Information, Member Bill of Rights, Grievance Policy, Photo & Press Release, Financial Eligibility & Insurance, and Employment Questionnaire. Every form generates a formatted PDF on submission, stored securely in Firebase Storage.
HIPAA-Compliant User Management
A complete role-based access control system with four tiers - Super Admin, Admin, User, and Suspended - all managed through an admin interface. Every permission change is audit-logged with timestamps, user details, and change history.
Smart Dashboard with Multi-Select Filtering
A centralized dashboard where supervisors can filter case notes by client name, staff name, or date. Filters are case-insensitive and support multi-select, so name variations collapse into one entry. Filtering by multiple clients and staff members simultaneously is supported.
Batch Export with Audit Logging
An "Export Selected" function generates individual PDFs bundled into a single ZIP file - all processed client-side in the browser. No PHI ever touches an intermediate server. Every export action is logged with User ID, email, timestamp, and a list of exported record IDs, supporting HIPAA "Accounting of Disclosures" requirements.
All Notes Global View
A single screen - restricted to Admin and Super Admin roles - that surfaces every case note across all three programs with real-time search across client name, staff name, and discussion content.
Speech-to-Text Input
Staff working in the field can dictate case notes instead of typing them, using Google Cloud Speech-to-Text integrated directly into the form fields - dramatically reducing case note completion time in community settings.
Network Resilience
Automatic retry logic with exponential backoff on form submission. If there's a momentary connectivity issue, the app retries silently. Only after all retries fail does the user see a clear error message.
- Flutter (Dart)
- Firebase Firestore
- Firebase Auth
- Firebase Storage
- Firebase Hosting
- Firebase AI (Gemini)
- Google Cloud Speech-to-Text
- Client-Side PDF Generation
Results & Impact
- Reduction in case note completion time
- 60%
- Programs unified on one platform
- 3
- Standardized digital forms
- 8
- HIPAA audit trail
- Real-time
Case note completion dropped from 15–20 minutes with paper and manual data entry to 5–8 minutes with digital forms and speech-to-text. Audit preparation went from hours of manual searching to seconds with filtering and batch export. Data consistency issues from name variations were eliminated through normalized entries. And HIPAA compliance moved from inconsistent manual logs to an automatic, real-time audit trail.
Working with BeeNex and their team has been an exceptional experience! They have guided us seamlessly through a new platform, ensuring it met our budget and specific needs, not to mention listening to our feedback with opportunity for implementation. Their expertise and dedication have made the transition smooth, allowing us to focus on our impactful work of empowering the community through storytelling and connection. BeeNex truly understands mission-driven organizations, and their support has been invaluable!
