I own the architecture end to end. Clinical consultations are captured as audio, transcribed, scored and reported back to ophthalmology practices, so every layer touches protected health information, and every failure has a patient behind it.
The ingestion path is built to survive its worst day: chunked 30s writes to IndexedDB, resumable upload with retry and exponential backoff, server-side FFmpeg reassembly, real-time WebSocket streaming. It survives mid-session client crash and network loss with no unrecoverable sessions.
Underneath: SQS with dead-letter queues, idempotent consumers and poison-message handling, holding zero sustained queue backlog. PHI is sealed with AES-256-GCM envelope encryption through AWS KMS, isolated decryption boundaries, and PostgreSQL row-level security enforcing multi-tenant isolation on every read path.
Concurrency is handled optimistically rather than with a distributed lock. A recovery sweep claims a consultation by writing a claim token, and every later write asserts both the processing status and that the token is still the one it read, because status alone proves a row is claimed and never that the claim is ours. Idempotency is enforced at the database: unique constraints, with an explicit lost-race branch on constraint violation rather than an error path.
Two schedulers write the same columns: the Lambdas, and six pg_cron jobs running inside Postgres. Report listings use keyset pagination over a non-unique sort key, so the cursor is a composite of date and id; a single-column cursor silently skips rows at page boundaries. The queue is tuned the same way, with a visibility timeout set to six times the function timeout and a dead-letter queue fanned in from 56 functions.
I also built a hardware recorder integration end to end: a native iOS client in Swift, WiFi SDK device pairing and file sync, and the path that moves on-device audio into the PHI-safe transcription flow.
| Lambda functions / REST endpoints | 61 / 185 |
| Invocations per month | 255,000 |
| Error rate | 0.016% |
| Peak concurrent executions | 103 |
| Transcription path latency | p50 18s / p99 104s |
| PostgreSQL schema | 87 tables, 153 functions |
| Recordings / audio-hours per month | 1,900 / 785 |
| Practices / clinical users / patient records | 40 / 245 / 14,600+ |

















