Building Software that Helps People Live with Less Pain
Healing Track
Industry
HealthTech
Service
AI & Emerging Tech
Summary
-
AI helped us understand patients more deeply than research alone could.
Trained agents synthesized real clinical transcripts, surfacing the patterns and language that grounded the product in real patient experience.
-
When people and AI share control, trust becomes the central design challenge.
The team earned patient trust by screening every message, offering a crisis path, and keeping a human coach reviewing what the AI produced.
-
Moving fast did not mean compromising on patient safety.
Working side-by-side, we launched to real patients at the first clinic in six months without ever sacrificing the controls that protected their data.
I developed Pain Reprocessing Therapy after finding my own way out of chronic pain, and I've spent years bringing it to patients one at a time. The hard part wasn't the science, it was reach. 8th Light built the platform that finally helped us scale this treatment, and they built it the right way: they sought input from people living with chronic pain and our coaches before designing anything, and they protected the human relationship at the heart of the therapy instead of automating it away. What they delivered stays true to the therapy and the principles behind it.

Alan Gordon, LCSW, Founder and CEO,
author of The Way Out
The Healing Track Journey, In Brief
Healing Track had a clinically proven therapy to eliminate or significantly reduce chronic pain, but no way to deliver it beyond a therapist's caseload. They came to 8th Light to build a platform that could change the trajectory of pain management while securely integrating with core EHR data.
Collaborating closely with the Healing Track leadership team, 8th Light applied a human-centered design approach, starting with the patients and Pain Reprocessing Therapy ('PRT') coaches who would use it. Six months later the first clinic is live and a multi-tenant platform is ready for growth.
Here's how:
- Start with people. Use AI to understand their stories. Healing Track gave us a library of anonymized coaching-session transcripts from their clinical trials, more than any team could read by hand in the time we had. We used Claude to synthesize all of it, pulling out the behavioral patterns, the emotional turning points, and the exact words patients used to describe their pain. Those real stories became the evidence base for our personas, journey maps, and two rounds of research, and they set the line between what a human coach should handle and where AI could help.
- Provide an AI coach to supplement their human PRT coach. Patients trusted their human coach and were wary of the machine, so the AI coach stays a bounded helper between sessions, never a replacement for the person they rely on. That safety net contains moderation settings, a crisis path, and a human coach reviewing its output. In short, AI extends the expertise of pain management coaches well into the off-hours instead of standing in for them.
- Keep behavioral science at the core. The Adherence Loop, a behavioral science framework developed by Dr. Devorah Klein (Believe → Frame → Know → Prompt → Act → Reinforce), shaped every product decision, from onboarding to the AI coach's role between sessions.
- Build privacy into the schema. Protected health information never touches the app's own database, which keeps the operational systems outside the regulatory scope of healthcare data regulation by design.
- Match Anthropic's Claude models to each part of the job. The more powerful Claude Sonnet model holds the therapeutic conversation and calls program practices; the faster, lower-cost Claude Haiku runs the high-frequency moderation, crisis, and summary guardrails. One model family, tuned for cost, latency, and safety node by node. System monitoring is in place to allow for future tuning and adjustment as models evolve.
The Challenge
Chronic pain is treatable, but the therapy has always been trapped behind a bottleneck: it could only reach as many people as a handful of specialized coaches could see during the day. Healing Track's opportunity was to break this bottleneck and bring a proven program to a market of millions, and that is the platform they asked 8th Light to build.
Healing Track came to us to scale a therapy with remarkable clinical evidence. Pain Reprocessing Therapy, developed by founder Alan Gordon and laid out in his New York Times best selling book The Way Out, treats chronic pain as a learned brain signal that can be unlearned. A Mount Sinai randomized controlled trial demonstrated the approach: 53.7% pain reduction compared to 15.1% for conventional treatment, at roughly 60% lower cost. For the 65 million Americans living with chronic pain, many of whom doctors cannot diagnose and remain untreated, a program that works changes daily life.

Healing Track's early mockups described the vision well, but no real user had validated them, which left a gap in leadership's understanding of their impact on user adoption. Working closely with their Chief Product Officer (CPO), Miriam Beecham, 8th Light proposed that we should understand the people who would use the product first, before designing and building.
In a domain where trust and emotional safety predict whether someone stays in a program, building on assumption carries real business and reputational risk. The engagement carried three hard constraints from day one:
- Protected health information, under real regulation. Chronic pain care is healthcare. The platform handles PHI and has to stand up to HIPAA and the compliance review an insurance partner requires.
- Many customers from one product. The platform has to serve multiple health plans and employers, each with its own branding and configuration, without a separate build for each. Multi-tenancy is core to the success of the Healing Track platform.
- Expert coaching, amplified. Coaches are at the heart of the program, and human experts are scarce. The platform is built to extend their reach, with the AI companion carrying the self-guided hours between sessions so that each coach's expertise reaches more patients.
The real challenge was not "build these screens." It was: understand the people this therapy serves, then design and build a multi-tenant, HIPAA compliant health platform with AI that extends a scarce human resource, and do it fast enough to meet the rapid launch timetable.
The Solution
We used AI agents to understand patients first.
Before rendering a single screen, we needed to understand the world our users lived in. Healing Track had a library of anonymized coaching-session transcripts from clinical trials. We built and used trained AI agents to ingest and synthesize this evidence, surfacing behavioral patterns, emotional turning points, and the exact language patients used to describe their pain and progress. A team reading transcripts by hand could never have covered that much ground in the limited time available; our agentic workflow let us meet real patient needs more fully, not just move faster. From that synthesis, the team built a patient journey map and a set of personas that became the backbone of the project.

We then put evidence-based prototypes in front of real people: two rounds of moderated research sessions with people managing chronic pain. The second research round opened with a live patient intake session led by Healing Track's Chief Operating Officer, John Gasienica, which reframed the product's core market positioning and surfaced opportunities the original brief never anticipated. People managing pain want emotional support, but they trust evidence.
The deeper research work made the biggest insight clear: the lever was framing, not more features. One participant moved from "right now, it's not for me" to "if it's framed correctly, I would be very interested in this" in a single session.
We designed the AI coach for people in pain
Patients needed support between coaching sessions, not only during them. As one participant put it, "sometimes you need someone right then. Not next Tuesday." That finding pointed to a clear design opportunity, but the research also drew a hard line around it. Patients trusted the human coach and were wary of the machine, and one put it plainly: "if it was only AI and there wasn't a person, it might deter me. Why can't I do that with ChatGPT?"
Two design principles came out of that discovery. Tell people up front when AI is involved, because "if I'm not told, I feel like I'm getting lied to." And keep a coach in the loop reviewing what the AI produces autonomously. The AI earns its place as a safety net between sessions only once the human trust is already there.

This is the design challenge that the emerging discipline of Agentic Experience Design (AX Design) exists to address: when humans and AI agents share control, building trust becomes the central design challenge. The team's approach followed this principle throughout. Rather than designing a chatbot interface, we designed a trust layer: what the AI coaching companion can and cannot do, how it communicates its boundaries, how it escalates to a human, and how the human coach stays informed.
Those design boundaries also dictated the technical approach. The coach is built as a state machine, not a free-running chatbot. Every patient message passes through a moderation step and a dedicated crisis-response path before the assistant ever answers. If someone signals they are in crisis, the system routes to a safe response rather than improvising. Conversations are persisted so context carries across sessions, and every interaction is captured for evaluation so the team can measure quality instead of guessing at it.
We treated patient privacy as an architecture problem
A critical technical decision was to keep protected health information (PHI) out of the application's own database entirely. We cover how in the architecture section below. The short version: the clinical record of truth lives in a certified electronic health record system, and Healing Track's own databases hold only anonymized identifiers. That decision shaped the data model, the infrastructure, and the compliance roadmap all at once.
The Impact
Healing Track took its first clinic live within six months. That means:
- Caring for real patients. The platform is live in production, and patients at the first clinic are using it to work through their chronic pain with their coaches, the very outcome the whole program exists to deliver.
- A complete v1.0, nothing deferred. Starting from an empty backlog, the team shipped a full first version with no scope abandoned along the way, the kind of predictable, fully scoped delivery a regulated health platform depends on.
- A product shaped by research. Repositioning the product as a science-backed course rather than an app, showing patients "evidence" of effectiveness rather than "progress," and prioritizing the AI coaching companion all came directly from what participants told us. That is the difference between shipping the original mockups and shipping the right product.
- A privacy model built into the schema. Because clinical data never enters the operational databases, those databases sit largely outside the scope of health-data regulation by design, which lowers the long-term compliance and breach burden.
- A methodology future releases inherit. The AI-assisted approach the team built through the work on Healing Track, from research through prototyping into the MVP, is now a repeatable practice available for future releases of the platform. Every launch provides insights that carry into the next version.
The real outcome story will come from a few metrics: coach time per patient, patient outcomes, and patient satisfaction with the app versus those without it. Those numbers will tell the full story once the first clinic has run for a meaningful period of time.
Through every technical decision, the stakes stayed personal, because we heard them straight from the people the product is for.
This will be life-changing for a lot of people. It's going to save a lot of lives. I don't think people realize how dark and heavy living with chronic pain can be.
Healing Track Research Participant
The Technical Deep Dive
Delivering patient impact meant earning trust with the most sensitive data there is: patient health records. Every architecture decision that followed was made to protect that data and keep Healing Track's clinics free of new liability, without slowing the platform down.
A single-page web app sits in front of a modular monolith API, with one separate microservice, all living on AWS. This solution architecture approach holds sensitive data to a minimum and isolates the parts that have to interact with this data.
Keeping protected health information out of the database

Clinical and patient data lives in a modern, third-party electronic health record ("EHR") system that already carries the relevant healthcare and privacy certifications. That system is the source of truth. Healing Track's own application database stores only opaque identifiers, with no name, email, or date-of-birth columns anywhere in the data model. Where the app must reference a patient before they register, it stores a one-way hash of the external identifier rather than the identifier itself.
This separation is enforced in the schema itself, not left to policy. The user record holds only an authentication identifier and a status, documented in code as carrying no protected health information. Because the sensitive data simply never lives here, the operational databases stay clean by design, which shrinks the compliance and breach surface instead of expanding it.
The credential proxy
The most security-critical piece of the architecture is a small, separate service whose only job is to make the rest of the system incapable of leaking patient-system credentials.
The web app and the main backend never hold the keys to the EHR. Instead, those per-user keys live encrypted in a separate datastore that only one narrow service can read. When the app needs clinical data, the backend forwards the user's authentication token to this proxy, which validates the token, looks up the right credentials, substitutes them into the request, and talks to the EHR. The main backend never sees a patient identity or an API key.
At approximately two thousand lines of Golang running as a serverless function, the proxy is small enough to audit in full, and its single responsibility keeps the attack surface for patient credentials deliberately narrow. An architecture decision record documents the four alternatives we evaluated, why we rejected each, and the trust boundary tradeoffs behind the choice. Any security review finds the boundary and its rationale already presented in clear terms.
Inside the AI pain coach advisor
The coach runs on more than one Claude model, on purpose. A stronger model holds the back-and-forth dialogue with the patient and decides when to pull in a program practice through a tool call. The advice given by the coach stays inside the method rather than drifting into generic wellness talk. The coach is capable enough to hold a grounded therapeutic conversation and call the right tool at the right moment, without the cost and latency of running the largest model on every turn.

Around that conversation sits a ring of guardrails, and those run on a faster, lower-cost model. Every inbound message is screened by a moderation step before the conversation model ever sees it. A separate crisis node handles the case where a patient signals they are in danger, routing to a safe response rather than letting the main model improvise. A third node writes the session summaries. Putting the high-frequency, latency-sensitive work on the faster model and reserving the higher-end model for the conversation is what makes it affordable to screen every message without slowing the patient down.
Claude fit the bill because its models are available in different tiers on one API, so we could assign each job to the best-fit model instead of paying for the top tier on every message sent. For a product interacting with people in pain, how a model handles crisis and safety language matters as much as raw ability. And we don't trust the coach's output on faith, we test it: an evaluation harness replays real conversations and scores the answers. Any change made to the engine is checked against a standard set of criteria.
The stack
- Web app: React and TypeScript, built with Vite, styled with Tailwind, organized as independent feature modules with no cross-feature imports.
- Backend: Python with FastAPI, layered strictly as routers, services, and repositories, backed by PostgreSQL.
- AI coach: built on LangChain and LangGraph with a suite of Anthropic's Claude models, conversation state persisted in PostgreSQL, and full observability and evaluation tooling so quality is measured rather than assumed. See "Inside the AI pain coach advisor" above.
- Credential proxy: Golang, running as a serverless function.
- Infrastructure: AWS, defined entirely in Terraform across separate staging and production environments, with a web application firewall and an audit trail in place from early on.
Engineering discipline that lowers business risk
The engineering choices here are not stylistic preferences. Each one is a control that keeps a regulated product handling patient data dependable and defensible under scrutiny.
- More test code than production code keeps the patient-facing paths protected as the product changes. That lets a small team move fast on a health platform without shipping defects or security regressions.
- An event-sourced engagement timeline records pain management program milestones as a sequence of events. This auditable history of a patient's progress keeps sensitive data out of places it does not belong.
- Automated, role-based deployment gives each service its own delivery pipeline using short-lived credentials rather than long-lived keys. Following this best practice shrinks the attack surface considerably.
- Documented architecture decisions mean the reasoning behind the system far outlasts the people who built it in the first place. As the team changes, the platform stays maintainable and stable.
Let's Talk
The work we care about is the hard kind: sensitive data, vulnerable users, and stakes high enough that getting it right is our first priority. If that sounds like what you're facing, let's talk.