Addendum to: HIFP-product-design-v3.1.md · HIFP-marketecture-v3.1.md
Date: 2026-09-02
Status: Locked. Reflected in POC /data restructure (Health / Wealth split).
Author path: Product decision by Brandon; sequencing recommendation confirmed.
HIFP will provision financial-data baselines via a tiered hybrid — never via direct credential-broker integration in MVP.
| Tier | Path | Phase | Owner |
|---|---|---|---|
| B | Self-report bucket model | MVP | Product / Eng |
| C | Advisor push (concierge channel) | MVP | Product / Practice-side eng |
| A′-Kubera | User-initiated OAuth to Kubera (aggregator partnership) | H1 | Product + BD |
| D | Read from advisor tech stacks (eMoney / RightCapital / Orion / Redtail) | H2 | BD-led |
| A′-Empower | Partnership data-share for co-registered users | H2 opportunistic | BD |
| A (Plaid / MX / Yodlee direct) | Direct credential-broker integration | Deferred indefinitely | — |
HNW 45–70 (per Gx + Boomers design brief) are the most Plaid-resistant demographic in retail finance. Self-report is not friction added, it is friction removed — because credential handoff to a new company is friction they refuse outright. Bucket entry with autocomplete on account types is a 90-second flow they will complete; a Plaid modal is a session-ender.
WA MHMDA + IL GIPA are the current extinction-risk lines. Adding GLBA-scoped data flows (plus the state financial-privacy stack — CA, NY, VT) inside MVP puts new compliance surface in the exact quarters SOC 2 Type II is landing. The tiered hybrid keeps GLBA outside the MVP boundary; Kubera Shape-1 in H1 keeps it at the partner, not at HIFP.
On health: "planning parameters, never clinical predictions." On wealth: "we don't hold your money and don't need direct account access to plan."
This parallelism is a pitch asset, not just a design constraint. It signals restraint at every layer — the same restraint that makes physicians and compliance officers say yes.
Inputs collected: - Totals by tax-treatment bucket: taxable brokerage, tax-deferred (401k/IRA/403b), Roth (IRA/401k), HSA, cash / equivalents. - Asset allocation: single slider or three-way split (equity / fixed income / cash). - Income streams: Social Security (est. start age + est. monthly), pension (monthly + COLA flag), annuity (monthly + term), rental (net monthly). - Current spending: monthly baseline + one-off expected large expenses (12-month horizon). - Real estate: primary residence est. value + mortgage balance; other RE net. - State of residency; filing status.
Model consumption: All fields feed the actuarial-model v1 published-tables SWR calculator (see HIFP-actuarial-model-spec-v0.1.md, §Two-stage delivery). Zero fields are optional-blocker — model degrades gracefully with sensible defaults surfaced to the user for confirmation.
UX pattern: Bucket page with inline-editable fields, autocalculated net-worth, quarterly refresh nudge. Explicit "Last updated: N days ago" freshness pill on every field group.
Eng lift: 1.5–2 weeks (form + validation + model input mapping). No infra.
Regulatory footprint: None new. Data classified as PII-financial-self-report under existing privacy notice.
Inputs collected: Same bucket schema as B, plus optional cost-basis lots per taxable position (for tax-aware withdrawal sequencing in H1 model v2).
Delivery mechanisms (any of):
- Practice-side advisor portal — advisor pastes / uploads snapshot on behalf of client at intake.
- CSV upload — standard schema published.
- Partner API — one-off POST /clients/{id}/baseline endpoint; documented for advisor-tech vendors that want to integrate.
UX pattern: Client sees baseline pre-populated at first login; explicit "provided by [Advisor Name] on [date]" attribution; can edit or accept.
Eng lift: 3 weeks (practice-portal intake UI + CSV parser + endpoint). Overlaps with existing practice-side dashboard work.
Regulatory footprint: Fits under BAA between HIFP and concierge chain; no new consumer-facing consent flow.
Shape: User-initiated OAuth. User taps "Connect Kubera → HIFP" on Data / Wealth page → redirects to Kubera OAuth → grants scoped read to portfolio, allocation, and net-worth roll-ups → HIFP pulls on cadence.
Why Kubera specifically: - HNW net-worth-native — the only major aggregator built for real estate, PE, art, crypto alongside brokerage. - Portable-data ethos matches HIFP brand. - Sub-$5M ARR sized firm — partnership conversation is a founder-to-founder call, not a 12-gate enterprise BD cycle. - Existing API surface — engineering integration is measured in weeks, not quarters, once the partnership is signed.
Eng lift: 3–4 weeks post-partnership. OAuth + polling + data-mapping to bucket schema.
BD lift: 4–8 weeks to first-partnership signature. Assumes founder-led outreach.
Regulatory footprint: GLBA obligations sit with Kubera as the aggregator. HIFP handles received data under its existing PII-financial-self-report classification, extended to cover partner-sourced data with an updated DPA.
Business value beyond data: Natural paid-tier trigger ("Upgrade to live tracking"). Mitigates the Plan-Delta staleness concern — biomarker shifts that move the plan hit a real balance, not a bucket typed six months ago.
Shape: HIFP → eMoney / RightCapital / Orion / Redtail partner API. One integration per platform serves every advisor on that platform who onboards.
Sequencing: Begin BD conversations post-Series A. eMoney and RightCapital are the two closest philosophical fits (both have advisor-published client portals; both have partner API programs). Redtail is the CRM-first candidate.
Eng lift per platform: 6–10 weeks. Higher variance than Kubera because each platform's data model differs.
BD lift per platform: 6–9 months. Enterprise sales cycle.
Regulatory footprint: BAAs + DPAs; fits under existing framework.
Shape: Partnership data-share for co-registered users. User consents once via Empower; Empower pushes data to HIFP for matched users; joint co-marketing.
Why it's smart: ~3M Personal Dashboard users, HNW-skewed, exact ICP. Distribution + data in one motion.
Why it's hard: - Structural incentive to say no. Empower Advisory Services ($1.7T AUM) exists to funnel Personal Dashboard users into their own RIA. HIFP through a physician-distributed channel is not a direct competitor to Empower Advisory but reads as a competitive funnel-drain from their vantage. - BD cycle: 9–18 months minimum. Not an MVP dependency. - Contract risk: Rev-share likely; watch for non-compete clauses that would block Y3 institutional data product (Variant B). - Copy risk: Once Empower sees HIFP's biomarker angle in a data-share context, they can build it themselves in year 2.
Verdict: Worth a BD track. Not worth a product dependency. Post-Series A start, when HIFP has traction leverage.
Not a fit for HIFP. Retained as an option only if: - (a) Kubera partnership collapses and advisor channels stall, and - (b) MHMDA / GIPA regulatory posture matures to the point that adding GLBA compliance surface is trivial.
Neither condition is expected in the 24-month window.
HIFP-advice-boundary-spec-v0.1.md §3 — flagged for review during H1 planning./data page in the POC restructured into Health and Wealth subsections.
- Health subsection: existing five source kinds (labs, wearables, self-report, EHR practice portal, advanced diagnostics).
- Wealth subsection: three new source kinds — Financial buckets (MVP), Advisor-provided baseline (MVP concierge), Aggregator connection (H1 · Kubera-first, Empower-later).
- Onboarding flow unchanged in this pass — wealth intake enters at first Home visit with a "complete your baseline" nudge card. Onboarding v2 will absorb it.
End addendum v0.1.