# HIFP Financial-Data-Baseline Addendum — v0.1

**Addendum to:** `HIFP-product-design-v3.1.md` · `HIFP-marketecture-v3.1.md`
**Date:** 2026-09-02
**Status:** Locked. Reflected in POC `/data` restructure (Health / Wealth split).
**Author path:** Product decision by Brandon; sequencing recommendation confirmed.

---

## 1. Decision (locked)

HIFP will provision financial-data baselines via a **tiered hybrid** — never via direct credential-broker integration in MVP.

| Tier | Path | Phase | Owner |
| --- | --- | --- | --- |
| **B** | Self-report bucket model | **MVP** | Product / Eng |
| **C** | Advisor push (concierge channel) | **MVP** | Product / Practice-side eng |
| **A′-Kubera** | User-initiated OAuth to Kubera (aggregator partnership) | **H1** | Product + BD |
| **D** | Read from advisor tech stacks (eMoney / RightCapital / Orion / Redtail) | **H2** | BD-led |
| **A′-Empower** | Partnership data-share for co-registered users | **H2 opportunistic** | BD |
| **A (Plaid / MX / Yodlee direct)** | Direct credential-broker integration | **Deferred indefinitely** | — |

---

## 2. Rationale — three reasons this shape wins

### 2.1 It respects the target demographic

HNW 45–70 (per Gx + Boomers design brief) are the *most* Plaid-resistant demographic in retail finance. Self-report is not friction *added*, it is friction *removed* — because credential handoff to a new company is friction they refuse outright. Bucket entry with autocomplete on account types is a 90-second flow they will complete; a Plaid modal is a session-ender.

### 2.2 It preserves HIFP's regulatory concentration

WA MHMDA + IL GIPA are the current extinction-risk lines. Adding GLBA-scoped data flows (plus the state financial-privacy stack — CA, NY, VT) inside MVP puts new compliance surface in the exact quarters SOC 2 Type II is landing. The tiered hybrid keeps GLBA outside the MVP boundary; Kubera Shape-1 in H1 keeps it *at the partner*, not at HIFP.

### 2.3 It parallels the product's architectural red line

On health: *"planning parameters, never clinical predictions."*
On wealth: *"we don't hold your money and don't need direct account access to plan."*

This parallelism is a pitch asset, not just a design constraint. It signals restraint at every layer — the same restraint that makes physicians and compliance officers say yes.

---

## 3. What each tier requires

### 3.1 B — Self-report buckets (MVP)

**Inputs collected:**
- Totals by tax-treatment bucket: taxable brokerage, tax-deferred (401k/IRA/403b), Roth (IRA/401k), HSA, cash / equivalents.
- Asset allocation: single slider or three-way split (equity / fixed income / cash).
- Income streams: Social Security (est. start age + est. monthly), pension (monthly + COLA flag), annuity (monthly + term), rental (net monthly).
- Current spending: monthly baseline + one-off expected large expenses (12-month horizon).
- Real estate: primary residence est. value + mortgage balance; other RE net.
- State of residency; filing status.

**Model consumption:** All fields feed the actuarial-model v1 published-tables SWR calculator (see `HIFP-actuarial-model-spec-v0.1.md`, §Two-stage delivery). Zero fields are optional-blocker — model degrades gracefully with sensible defaults surfaced to the user for confirmation.

**UX pattern:** Bucket page with inline-editable fields, autocalculated net-worth, quarterly refresh nudge. Explicit "Last updated: N days ago" freshness pill on every field group.

**Eng lift:** 1.5–2 weeks (form + validation + model input mapping). No infra.

**Regulatory footprint:** None new. Data classified as PII-financial-self-report under existing privacy notice.

### 3.2 C — Advisor push (MVP, concierge channel)

**Inputs collected:** Same bucket schema as B, plus optional cost-basis lots per taxable position (for tax-aware withdrawal sequencing in H1 model v2).

**Delivery mechanisms (any of):**
- Practice-side advisor portal — advisor pastes / uploads snapshot on behalf of client at intake.
- CSV upload — standard schema published.
- Partner API — one-off `POST /clients/{id}/baseline` endpoint; documented for advisor-tech vendors that want to integrate.

**UX pattern:** Client sees baseline pre-populated at first login; explicit "provided by [Advisor Name] on [date]" attribution; can edit or accept.

**Eng lift:** 3 weeks (practice-portal intake UI + CSV parser + endpoint). Overlaps with existing practice-side dashboard work.

**Regulatory footprint:** Fits under BAA between HIFP and concierge chain; no new consumer-facing consent flow.

### 3.3 A′-Kubera — Aggregator partnership (H1)

**Shape:** User-initiated OAuth. User taps "Connect Kubera → HIFP" on Data / Wealth page → redirects to Kubera OAuth → grants scoped read to portfolio, allocation, and net-worth roll-ups → HIFP pulls on cadence.

**Why Kubera specifically:**
- HNW net-worth-native — the only major aggregator built for real estate, PE, art, crypto alongside brokerage.
- Portable-data ethos matches HIFP brand.
- Sub-$5M ARR sized firm — partnership conversation is a founder-to-founder call, not a 12-gate enterprise BD cycle.
- Existing API surface — engineering integration is measured in weeks, not quarters, once the partnership is signed.

**Eng lift:** 3–4 weeks post-partnership. OAuth + polling + data-mapping to bucket schema.

**BD lift:** 4–8 weeks to first-partnership signature. Assumes founder-led outreach.

**Regulatory footprint:** GLBA obligations sit with Kubera as the aggregator. HIFP handles received data under its existing PII-financial-self-report classification, extended to cover partner-sourced data with an updated DPA.

**Business value beyond data:** Natural paid-tier trigger ("Upgrade to live tracking"). Mitigates the Plan-Delta staleness concern — biomarker shifts that move the plan hit a *real* balance, not a bucket typed six months ago.

### 3.4 D — Advisor-tech platform reads (H2)

**Shape:** HIFP → eMoney / RightCapital / Orion / Redtail partner API. One integration per platform serves every advisor on that platform who onboards.

**Sequencing:** Begin BD conversations post-Series A. eMoney and RightCapital are the two closest philosophical fits (both have advisor-published client portals; both have partner API programs). Redtail is the CRM-first candidate.

**Eng lift per platform:** 6–10 weeks. Higher variance than Kubera because each platform's data model differs.

**BD lift per platform:** 6–9 months. Enterprise sales cycle.

**Regulatory footprint:** BAAs + DPAs; fits under existing framework.

### 3.5 A′-Empower — Big-fish partnership (H2 opportunistic)

**Shape:** Partnership data-share for co-registered users. User consents once via Empower; Empower pushes data to HIFP for matched users; joint co-marketing.

**Why it's smart:** ~3M Personal Dashboard users, HNW-skewed, exact ICP. Distribution + data in one motion.

**Why it's hard:**
- **Structural incentive to say no.** Empower Advisory Services ($1.7T AUM) exists to funnel Personal Dashboard users into their own RIA. HIFP through a physician-distributed channel is not a *direct* competitor to Empower Advisory but reads as a competitive funnel-drain from their vantage.
- **BD cycle:** 9–18 months minimum. Not an MVP dependency.
- **Contract risk:** Rev-share likely; watch for non-compete clauses that would block Y3 institutional data product (Variant B).
- **Copy risk:** Once Empower sees HIFP's biomarker angle in a data-share context, they can build it themselves in year 2.

**Verdict:** Worth a BD track. Not worth a product dependency. Post-Series A start, when HIFP has traction leverage.

### 3.6 A (Plaid / MX / Yodlee direct) — Deferred indefinitely

Not a fit for HIFP. Retained as an option only if:
- (a) Kubera partnership collapses **and** advisor channels stall, **and**
- (b) MHMDA / GIPA regulatory posture matures to the point that adding GLBA compliance surface is trivial.

Neither condition is expected in the 24-month window.

---

## 4. What this means for other artifacts

- **Product design v3.1** — Data-intake section needs updated diagram showing Health + Wealth as parallel top-level categories, with the tier ladder on the Wealth side.
- **Marketecture v3.1** — Data-source layer diagram needs Wealth-source subcategory added; Kubera Shape-1 called out as H1 partnership swim-lane.
- **Advice-Boundary spec v0.1** — Add clause: real-time balance ingestion (H1+) obligates faster Plan-Delta recomputation cadence and may narrow the "planning parameter" language in `HIFP-advice-boundary-spec-v0.1.md` §3 — flagged for review during H1 planning.
- **Financial model v0.1** — Kubera partnership fee (if any) enters Y2+ COGS; Empower rev-share modeled as Y3 sensitivity only.
- **Chain partnership playbook v0.1** — Add C-tier advisor-push flow to standard chain onboarding kit; specify data-schema published as v1.
- **Open items ledger v0.1** — Add three: (1) Kubera outreach owner, (2) Fatima's eMoney/RightCapital network mapping, (3) Advice-Boundary recomputation-cadence review.

---

## 5. POC reflection (delivered same session)

`/data` page in the POC restructured into **Health** and **Wealth** subsections.
- Health subsection: existing five source kinds (labs, wearables, self-report, EHR practice portal, advanced diagnostics).
- Wealth subsection: three new source kinds — **Financial buckets** (MVP), **Advisor-provided baseline** (MVP concierge), **Aggregator connection** (H1 · Kubera-first, Empower-later).
- Onboarding flow unchanged in this pass — wealth intake enters at first Home visit with a "complete your baseline" nudge card. Onboarding v2 will absorb it.

---

*End addendum v0.1.*
