You're already on Cloudflare with a custom proxy · let's expand behind the AI care layer

You just won 2026 MedTech Breakthrough for Best Virtual Care.
The runtime underneath should match the clinical bar.

Vida Health delivers enterprise obesity and metabolic care — GLP-1 prescribing, behavioral health, continuous glucose monitoring integration, multicultural support — with HITRUST r2 certification and the 2026 MedTech Breakthrough Award for Best Virtual Care Platform. vida.com is already on Cloudflare DNS with a custom proxy. The expansion footprint is the developer platform underneath: AI Gateway for the GLP-1 + behavioral AI surface, R2 for the FHIR clinical corpus, Workers for Platforms for per-employer / per-health-plan tenancy, and Zero Trust for clinical staff access at HIPAA scale.

NS: fred / serena.ns.cloudflare.com · vida.com#upstream-id: vida-proxy-2-corporate-site-443 (custom CF proxy header!) · Anthropic verified on apex TXT · WP Engine origin, GCP app plane (35.237.x / 107.178.x / 34.120.x), Genesys PureCloud + Canvas Medical integration

Top of vida.com today
"🏆 Winner of the 2026 MedTech Breakthrough Award for Best Virtual Care Platform." + HITRUST r2 Certified Assessment Seal in footer.
— The award is a procurement moment. Every enterprise security review for the next 12 months will ask "show me the architecture diagram." That diagram should have Cloudflare as the perimeter and AI Gateway as the model layer — both of which give you defensible answers about PHI handling, audit trails, and per-payor isolation.

What's already running on Cloudflare today

DNS & ROOT ZONE
vida.com on Cloudflare DNS via fred / serena.ns.cloudflare.com
CUSTOM PROXY LAYER
vida.com#upstream-id: vida-proxy-2-corporate-site-443 — you've already built a custom CF proxy in front of WP Engine
EXPANSION PATH
Add AI Gateway + R2 + Workers for Platforms behind the same edge — same MSA, same SOC mapping, same BAA
2026
MedTech Breakthrough Award — Best Virtual Care
HITRUST r2
Highest-tier health-data security certification
GLP-1
Prescribing + behavioral health, integrated
3
Audiences: Employers, Health Plans, Individuals

Vida ships the clinical product. Cloudflare runs the HIPAA-grade perimeter.

You've already chosen Cloudflare for the edge — complete with a named custom proxy, which is unusual signal that someone on the platform team trusts the developer surface here. The next infrastructure layer is the part that needs to scale with the AI-care surface: the inference plane behind the AI coaching, the FHIR-grade content corpus, the per-employer / per-payor tenancy, and the clinical staff access plane that has to satisfy HITRUST auditors.

Vida builds

The clinical care product, the provider network, the outcomes

Enterprise obesity and metabolic care: GLP-1 prescribing, behavioral health, nutrition, sleep, chronic conditions, continuous glucose monitoring integration. The provider network, the clinical protocols, the outcomes data, the HITRUST r2 program. The Vida app on iOS + Android. Multicultural support across languages.

  • Clinically validated outcomes — weight loss, diabetes control, cost savings
  • GLP-1 prescribing with behavioral support layered on
  • Integrations: Genesys PureCloud (contact center), Canvas Medical (EMR)
  • HITRUST r2 certification + HIPAA + multicultural support
×

Cloudflare runs

The perimeter, the AI plane, the per-payor tenancy, the access layer

The custom proxy you already built can host AI Gateway, R2, Workers for Platforms, and Zero Trust on the same edge. Same MSA, same BAA, same SOC mapping. No new vendor introduction. The HITRUST auditor sees one perimeter, not three.

  • AI Gateway in front of Anthropic (already on your apex) for clinical AI surfaces
  • R2 + Workers for the FHIR + clinical content corpus, zero egress
  • Workers for Platforms = per-employer / per-health-plan isolation
  • Zero Trust for clinician + RPM device data access at HIPAA scale

Nine primitives, mapped to Vida's actual care surface.

Each maps to something you ship today (the AI app, the clinical content library, the payor integrations, the device/RPM telemetry, the HITRUST-grade access controls) or something on the published roadmap. Status tags show what's already live in your Cloudflare footprint.

PRIMITIVE 01 Live on CF

DNS + custom proxy for vida.com

Authoritative DNS via fred / serena.ns.cloudflare.com, and the response headers reveal a named custom proxy: vida-proxy-2-corporate-site-443. The platform team already builds on the Cloudflare developer platform — this isn't a cold conversation.

DNS Custom proxy WP Engine
PRIMITIVE 02 Highest-leverage next

AI Gateway in front of clinical AI

Anthropic is verified on your apex TXT. Every coaching-conversation summary, every visit-note draft, every GLP-1 candidate screening that runs through Claude is a call that should be cached, attributed, audit-logged, and budget-capped. AI Gateway gives you all of that in one header change.

AI Gateway Semantic cache BAA-ready
PRIMITIVE 03 Per-payor wedge

Workers for Platforms = per-employer / per-payor tenancy

Each enterprise customer (employer, health plan, partner) has different formularies, different program inclusion rules, different cost-of-care targets, different audit requirements. Workers for Platforms gives each one their own Worker namespace with isolated keys, egress, logs, and AI budget — on the same edge.

Workers for Platforms Per-payor Isolation
PRIMITIVE 04 Clinical corpus

R2 + Vectorize for FHIR + content library

Clinical content, care plan templates, multicultural language variants, FHIR resources, outcomes data. R2 holds it zero-egress; Vectorize indexes it for "find the closest care-plan template to this member's profile" in milliseconds. The retrieval layer for every Anthropic call.

R2 Vectorize FHIR
PRIMITIVE 05 Clinical access

Zero Trust for clinicians + admin consoles

HITRUST r2 requires audit-grade access controls to PHI-touching systems. Cloudflare Access gives identity-aware, audit-logged access to Canvas Medical, the Vida admin console, the AI experiment dashboards, and the Genesys PureCloud agent surface — without standing up a separate IdP stack.

Access Tunnel HITRUST r2
PRIMITIVE 06 Device telemetry

Workers + Queues for CGM + RPM ingest

Continuous glucose monitors (featured in your hero photo), wearables, scales — high-volume telemetry from member devices into the Vida care plane. Workers ingest at the closest of 330+ POPs to the device. Queues handle the async fan-out into clinical alerts, member dashboards, and outcomes pipelines.

Workers Queues CGM + RPM
PRIMITIVE 07 App distribution

R2 + Workers for the Vida app delivery

iOS + Android app updates, app-side ML models, member-facing rich-media content (videos, multicultural assets), care-plan PDFs. R2 zero-egress + Workers + Smart Placement serves from the closest POP to each member — especially important for the multicultural / international member base.

R2 Workers Smart Placement
PRIMITIVE 08 Edge audit

Workers for tamper-evident audit logs

HITRUST r2 + HIPAA require detailed, tamper-evident access logs for every PHI touch. Workers can stamp + hash every request at the edge before it ever touches an internal system. R2 with object versioning gives you immutable storage. Auditor-friendly by construction.

Workers R2 versioning Audit log
PRIMITIVE 09 Member protection

Bot Management + Turnstile on signup / eligibility

Eligibility-check forms, account creation, support portal — all high-value surfaces for synthetic-identity abuse, eligibility scraping by competitors, and credential stuffing on returning members. Bot Management at the edge stops the abuse before it touches Canvas Medical or any PHI-handling system.

Bot Management Turnstile WAF

A coaching conversation is a pipeline waiting to be audited.

"Member asks the Vida app about their GLP-1 dose" → an Anthropic call → FHIR + care plan retrieval → a behavioral-health-aware response → an audit trail every HITRUST auditor will want. Cloudflare runs each step on the same edge, on the same audit log, behind the same BAA.

A Vida coaching invocation, sketched on Cloudflare primitives

From "member opens the Vida app" to a clinical-grade response — cached, attributed, PHI-aware, audit-logged from request one.
MEMBER ACTION
Vida app on iOS / Android / web
message, voice, CGM event, etc.
PER-PAYOR EDGE
Workers for Platforms tenant
isolated by employer / health plan
RETRIEVAL + ROUTING
Vectorize + AI Gateway
FHIR + care plan retrieval, BAA-ready
RESPONSE + AUDIT
Workers + R2 versioning
tamper-evident audit log per call
What this changes: Every Vida AI invocation gets the same architectural shape — per-payor isolation, BAA-covered inference, retrieval against your FHIR + care-plan corpus, immutable audit log. When the HITRUST auditor or the next health-plan procurement asks "show me the diagram," it's one slide — not seven services across three clouds.

The economics of AI-driven coaching at payor scale.

Vida sells outcomes — weight loss, diabetes control, cost savings — not AI minutes. But the AI bill scales with member-engagement, not with outcomes. AI Gateway turns Anthropic spend from a monthly surprise into a per-payor, per-program, per-cohort cost line you can defensibly price into your enterprise contracts.

A back-of-the-envelope, not a quote
Modeled across coaching conversations + visit-note drafts + member-message triage at $5 / M blended tokens
SEMANTIC CACHE HIT RATE
45–65%
Member queries cluster hard: GLP-1 dose timing, side effects, "is this a hypo," CGM interpretation, food choices. The same coaching responses get drafted across thousands of members.
PER-PAYOR ATTRIBUTION
100%
AI Gateway gives per-employer, per-health-plan, per-cohort attribution — the data needed to price outcomes-based contracts with confidence instead of cost-plus.
AUDIT-LOG STORAGE EGRESS
40–60%
R2's zero egress vs. S3 + CloudFront for the HITRUST-mandated audit log retention — multi-year hot storage with zero cost-per-read.
The real win is enterprise pricing defensibility. When Anthem, Aetna, or a Fortune 100 employer asks "how do you price this if engagement doubles?" the answer needs to be: "here is the per-member-per-month inference + retrieval + audit cost line, broken out by program, by cohort." AI Gateway captures that data from request one. Without it, every new payor contract is priced on guesswork.

Three audiences, dozens of payors. Workers for Platforms is the boundary.

Employers want benefits-integrated obesity care. Health plans want medical-management partnership and outcome guarantees. Partners want embedded care delivery. Each one has its own contract terms, its own data residency, its own audit cadence, its own clinical formulary. That's not a feature flag — that's an isolation boundary.

Per-audience, per-payor tenancy, sketched

Each Vida audience (employer, health plan, partner) gets its own Worker for Platforms namespace. Each individual payor contract inside gets its own isolated tenant. Same edge, same observability, region-bound data residency.
🏢
Employers
🏥
Health Plans
🤝
Partners
👨‍💻
Individuals (D2C)
Shared control plane — Workers for Platforms + AI Gateway + Vectorize + R2
one runtime · one observability surface · PHI residency enforced by region binding, not by checkbox

Current stack, with Cloudflare overlaid.

Every row is sourced from public DNS records, the vida.com apex TXT, HTTP response headers, and the visible CSP allowlist. The magenta row is already running on Cloudflare today. The orange column is the expansion footprint.

What's running today, and where Cloudflare slots in

Magenta rows = already on Cloudflare. Orange column = the expansion path. No WP Engine, GCP, Canvas Medical, or Genesys rip-and-replace required.
LAYER
VIDA RUNS TODAY
CLOUDFLARE FIT
DNS + EDGE
Cloudflare (fred + serena.ns) + custom proxy vida-proxy-2
✅ Live — the foundation everything else snaps onto
CORPORATE SITE
WordPress on WP Engine (x-powered-by, x-cacheable)
No change — WP Engine fronts cleanly behind the existing CF zone
APP + API PLANE
GCP (35.237.x, 107.178.x, 34.120.x — us-central likely)
+ Cloudflare in front: WAF, Bot Mgmt, AI Gateway routing
CLINICAL AI
Anthropic Claude (verified on apex TXT)
+ AI Gateway: cache, attribution, BAA-covered, audit log from day one
EMR
Canvas Medical (CSP frame-ancestors *.canvasmedical.com)
No change — CF Tunnel exposes Canvas access via Zero Trust
CONTACT CENTER
Genesys PureCloud (CSP frame-ancestors *.pure.cloud)
+ Zero Trust SSO + Access in front of the PureCloud agent surface
FHIR + CARE CONTENT
Likely PostgreSQL + GCS for FHIR resources + care plan corpus
+ R2 (zero egress) + Vectorize for retrieval — faster, cheaper, BAA-ready
PAYOR TENANCY
Multi-tenant app with row-level isolation
+ Workers for Platforms — per-payor namespace by construction
DEVICE / CGM INGEST
Likely direct-to-GCP from device or partner
+ Workers + Queues at the edge POP closest to the member
EMAIL
Google Workspace + Zendesk + Mailgun + Pardot
+ CF Email Security as defense-in-depth (HIPAA-grade phishing protection)
CLINICAL ACCESS
Likely VPN + IdP for clinician access to Canvas + admin tools
+ Cloudflare Access — identity-aware, no VPN, audit-logged
SECURITY POSTURE
HITRUST r2 certified + DocuSign + Cisco + Atlassian verified
+ Bot Mgmt + WAF + Turnstile on eligibility / signup / member portal

Why this is the right quarter to start the conversation

The 2026 MedTech Breakthrough Award is a procurement moment. The award puts Vida in front of every Fortune 500 benefits team's "build the short list" exercise for 2026 RFPs. Every one of those RFPs will include a security architecture review. Cloudflare in front of the AI surface gives you a defensible answer the first time the question is asked.

You're already on Cloudflare with a custom proxy. vida-proxy-2-corporate-site-443 in the response headers tells me the platform team already trusts the developer-platform side. There's no procurement event to start, no security review to begin from zero, no MSA to negotiate. Expanding the footprint from DNS + custom proxy to AI Gateway + R2 + Workers for Platforms is the most natural roadmap conversation in the lineup.

The GLP-1 + AI coaching surface is exploding. Anthropic is already on your apex. Every new payor contract that wants outcomes guarantees means more AI calls per member. AI Gateway is the cheapest hour you can spend in front of that cost curve — before the per-payor margin math starts to matter at scale.

Worth a 30-minute conversation with the platform team?

The interesting conversation is which of these primitives is closest to your current sprint: AI Gateway behind Anthropic, R2 + Vectorize for the FHIR + care-plan corpus, Workers for Platforms for per-payor tenancy, or Zero Trust for the clinician access surface. I'd rather hear what's actually on your roadmap than guess.

Matt Holscher Calendar  → Reply by email