Military Health Contact Tracing banner

Global-scale contact tracing for every U.S. military installation, built to work offline and protect privacy

Services Provided

Web Development, Staff Augmentation, Systems Integration

Project Technologies

AngularJS | TypeScript | Cumulocity IoT | webMethods | Custom ETL Middleware

Industry Served

Government, Defense, Healthcare

Team Composition

2-4 Developers

Project Duration

Multi-year engagement

TLDR

Twin Sun partnered with a systems integration firm to build a contact tracing system for a U.S. military health agency, designed to protect service members across every U.S. military installation worldwide during the COVID pandemic. The system had to function offline on ships and facilities without internet access, comply with HIPAA while handling classified personnel data, support multiple wearable device types, and preserve privacy through audit-logged searches. We built the web interface and business logic layer on top of the Cumulocity IoT platform, using AngularJS and TypeScript. When scale testing revealed performance limitations in Cumulocity's query capabilities, we designed and built custom ETL middleware that restructured IoT data for optimized queries without compromising the platform's upgrade path. The architecture successfully balanced competing constraints: national security, health data privacy, offline functionality, and real-time performance at military-installation scale.

The Challenge

At the height of the COVID pandemic, a U.S. military health agency needed a contact tracing system that could protect service members across every U.S. military branch, facility, and ship around the globe. The requirements were formidable: the system had to comply with HIPAA regulations while handling classified personnel information. It needed to function offline on ships in the middle of the ocean and sync data back to command when connectivity returned. It had to support multiple types of wearable devices and preserve privacy so that tracking individual movements required auditable authorization.

The core use case was straightforward in concept but complex in execution: when a service member tested positive for COVID, medical officers needed to quickly identify everyone who had been in close contact with that person. The system had to answer questions like “Who spent more than 10 minutes with this individual in the past 24 hours?” across populations that could number in the thousands per facility.

Our Solution

Twin Sun joined the effort as a subcontractor under a systems integration partner, building the web interface and business logic layer on top of the Cumulocity IoT platform. We had previously worked with the same partner on a federal healthcare agency project using the same product family, so we understood the platform’s capabilities and constraints.

Our team built a custom web application in AngularJS and TypeScript that ran as an installable application within Cumulocity. The interface served medical officers at each facility, allowing them to query contact data using configurable search criteria. To protect privacy, we designed a system using randomly generated unique identifiers that could not be associated with any other personnel data. Medical officers could only reconcile these IDs to actual names through a separate offline mapping table, and all search operations were logged in an auditable trail.

We took an iterative approach, starting with a bare-bones version that performed simple close-contact searches and progressively adding complexity: contact rate analytics, average contact duration reports, device health monitoring, and data synchronization back to central command.

The biggest technical hurdle emerged during scale testing. Cumulocity’s native query capabilities could not return results fast enough when simulating representative population sizes. Caching was not viable because contact tracing queries are essentially one-off searches. Pre-warming a cache for every possible search condition would have exceeded the compute and storage constraints of shipboard installations.

We built custom middleware to solve the performance problem. An ETL layer continuously ingested proximity data from Cumulocity, restructured it into optimized table formats with appropriate indexing, and exposed the transformed data through a webMethods API gateway. This architecture let us deliver fast query responses without modifying Cumulocity itself, preserving the platform’s upgrade path and maintainability.

The Results

The system was designed to protect U.S. military personnel from COVID-19 and built with the flexibility to address future threats, whether communicable diseases or proximity-based hazards like radioactive material exposure. The architecture successfully addressed every constraint: HIPAA compliance, national security requirements, offline operation, two-way synchronization, multiple device types, and privacy preservation through audit-logged searches.

Daily standups kept the client informed and allowed rapid reprioritization as requirements evolved. When performance problems surfaced at scale, we diagnosed the root cause, explored multiple solutions, and delivered middleware that transformed query response times without creating technical debt in the core platform.

The engagement demonstrated what becomes possible when a development partner understands both the technical landscape and the mission. We did not simply write code to a specification. We anticipated performance constraints, explored caching alternatives before building middleware, and made architectural decisions that balanced immediate needs against long-term maintainability.