Boston, MA · One-person senior software practice
One senior engineer.
From architecture to shipped code.
15+ years building software in domains where being wrong is expensive — government systems and HIPAA-compliant health platforms. I take two kinds of engagements: fractional CTO leadership, and hands-on contract engineering. IN2Labs is a one-person practice, so the engineer you meet is the one who designs your architecture and ships it.
Currently: fractional CTO of a HIPAA-compliant health platform running AI analysis over retinal imaging — PHI encryption, custom-claims access control, and audit trails built to be read by someone who is checking. How it's architected →
Client work
Built for clients. Running in production.
Preventa Wellness
A HIPAA-compliant health platform where I have served as fractional CTO since 2019, now through IN2Labs — first at Preventa Medical Corporation, continuing at Preventa Wellness. A live, multi-year engagement, not a finished-and-forgotten project. Health data is where "mostly secure" is not a defensible position, so Preventa was architected to handle protected health information the way regulators, hospital security teams, and patients expect.
If you are a health-tech founder evaluating partners, ask every one of them the same question: have you actually shipped HIPAA-compliant software? I have, and I will walk you through exactly how.
What HIPAA-compliant means here
- Encrypted PHI at rest and in transit
- Audit logging and access controls
- BAA-covered cloud infrastructure
Also co-developed: PriceHarvest · see all client work · read a published audit report · plus in-house products at IN2Labs Studio
Based in Boston · working nationwide
How an engagement starts
Most consultants describe a process. Here is what the first two weeks actually produce.
-
Day 1
I read the codebase and get it running locally
Repo access, local build, and a pass over the parts that decide everything else — data model, auth, deploy pipeline. If it will not run locally, that is finding number one.
-
Day 3
You get a written architecture assessment
What is sound, what is load-bearing and fragile, and what will break at 10x. Ranked by what it costs to fix now versus later. In writing, so you can forward it.
-
Week 2
First pull request merged
Something real, in production, early. Usually the highest-risk unknown rather than the easiest ticket — the point is to prove the assessment against your actual system.
-
Ongoing
Architecture decisions get written down
Every significant call is recorded with the alternatives considered and the reason. When I am gone, the reasoning is not.
Who you work with
One senior engineer. The same one, every time.
IN2Labs is a one-person senior practice, on purpose. The engineer you meet on the first call is the engineer who designs your architecture and writes your code, never handed off to a rotating bench.
Eric P. Hassey
Founder · Fractional CTO
15+ years of software experience. Fractional CTO of a HIPAA-compliant health platform since 2019.
Based in Boston, MA — working with clients nationwide
An engagement covers
Architecture · AI / ML · Mobile & web · Cloud & CI/CD · Security & compliance
Based in Boston, working nationwide. A deliberately small number of engagements at a time, so none of them gets a junior.
Not a startup? Research groups, labs, and established companies are often the better fit. The common thread is needing senior engineering judgment — in the CTO seat or at the keyboard — without a full-time hire. Contract engineering →
From the blog
Notes from production.
Astro's View Transitions Silently Broke My Booking Widget — and My Analytics Hid It
How data-astro-exec stops byte-identical inline scripts from ever re-running, why that killed a third-party embed, a mobile menu, and GA4 page_view at once, and the one attribute that fixes it.
Read more →RBAC for Healthcare Apps with Firebase Custom Claims: Roles, Tenants, and the 1,000-Byte Limit
How to enforce role-based access over protected health information using Firebase custom claims and Firestore security rules — including the token size limit, the propagation delay, and the failure mode that leaks records.
Read more →Designing a HIPAA Audit Trail in Firestore: Six-Year Retention Without a Runaway Bill
The rule says retain six years. It does not say how. A schema for PHI access logging in Firestore that stays queryable under pressure and does not cost more than the product it protects.
Read more →FAQ
Questions worth asking.
Do I need a technical co-founder? +
Usually not. That is largely why this practice exists: I act as your technical leadership, from architecture decisions through production deployment, and you keep full ownership of everything built. If your product genuinely needs a technical co-founder, I will tell you that too.
What if my project isn't a startup? +
Research groups, labs, and established companies are often a better fit than startups. Analysis pipelines, internal tools, technical audits, grant-funded software, and product rebuilds are all normal work here — the common thread is needing senior engineering judgment without a full-time hire. Institutional paperwork (PO, W-9, COI, BAA) is routine; say so on the first call and it moves in parallel.
What if I only have a rough idea? +
Perfect — a napkin sketch or a five-minute voice memo is a fine starting point. The discovery process exists to turn a rough idea into a scoped, buildable product, and it's the part where cutting scope saves you the most money.
How fast can you actually ship? +
Scoped features in days; a focused MVP in 8 to 12 weeks. Timeline depends entirely on scope, and you see working software every week rather than a status percentage — which is how scope problems surface in days instead of at the end.
Who will actually be working on my project? +
Eric Hassey — me. IN2Labs is deliberately a one-person senior practice in Boston, so the person you meet on the first call is the person who designs your architecture and writes your code. There is no bench, no hand-off, and nobody junior learning on your budget. Where a project genuinely needs a specialist I do not cover, I say so and help you find one rather than quietly staffing it.
Can you build HIPAA-compliant software? +
Yes — in production, and on an ongoing basis. Eric has served as fractional CTO of Preventa since 2019, now through IN2Labs: a HIPAA-compliant health platform with encrypted PHI, queryable audit logging, role-based access over health records, and BAA-covered infrastructure. Full disclosure, since it is the example I lean on most: I am a co-founder of Preventa and have a financial interest in it beyond the engagement fee, so it is not an arm's-length client reference. If your product touches health data, I already know what compliance actually requires.
How do you price engagements? +
Concretely: fractional CTO retainers run $5,000–$12,000/month depending on days per week, with regulated work (HIPAA, medical AI) at the upper end. A fixed-price Technology Health Check is $2,500 for a two-week review with written findings, credited against a retainer if you go ahead — details at /technology-health-check. Once we are both serious, I write a proper SOW before anything is signed — scope, deliverables, and exclusions in writing, so there are no surprises either way. Full MVP builds typically run $25,000–$80,000. You work directly with one senior engineer — no account managers, no bench overhead, no junior devs on your dime — so you are paying for engineering, not for the org chart around it.
You're one person — what happens if you're unavailable, or I outgrow you? +
Fair question, and worth asking directly. Two things make it manageable. First, you own everything from day one — the code, the repositories, the cloud accounts, the domain — and every engagement ends with documentation and a walkthrough, so nothing about your product depends on IN2Labs continuing to exist. Second, a one-person practice has hard capacity limits, which means I take a small number of engagements and say no when the calendar is full rather than quietly stretching. If your product outgrows what one senior engineer can carry, the right move is your own in-house hire — and helping you scope, interview, and onboard that person is part of the fractional CTO work, not a threat to it.
Can you work with my existing team? +
Often the best arrangement. I embed alongside your developers for code review, architecture, and the features nobody senior has time for — and a large part of the fractional CTO role is raising the bar of the team you already have.
Do you accept equity? +
Yes — cash, equity, or a combination, though equity works as an addition to a cash floor rather than as a discount. If I believe in what you are building, I am open to sharing the upside.
What happens after launch? +
I do not disappear at launch. Maintenance retainers cover monitoring, bug fixes, and feature work, and ongoing development is available if you want it. You are never locked in: you own the code and the accounts from day one, so continuing is a choice rather than a dependency.
Get in touch
Ready to build the right way?
Tell me where you're stuck. I'll tell you what it takes — honestly. No pitch deck, no sales script.
Book 30 minutesOr send me a message