Invoice

Value Delivered

Ernesto Cullari Media LLC

Revrcel

Attn: Cheryl Marchese (Partner)

February 27, 2026

February 17, 2026

Description Market Value Status
1. Custom Landing Page Infrastructure & Page Development $2,000.00 DELIVERED
2. Complete Website Replication (43 Pages) $8,000.00 MARKET PRICE
3. HIPAA Compliance Audit & Risk Assessment $5,000.00 MARKET PRICE
Total Value Delivered $15,000
1. Infrastructure & Landing Pages — $2,000 Value

We built Revrcel a modern page replacement system. The existing WordPress pages are slow, bloated with plugin overhead, and difficult to update. We recreated key pages from scratch using clean, modern HTML and CSS — no WordPress, no page builder plugins, no theme bloat. The result is pages that load significantly faster, look identical (or better) to the originals, and are hosted on their own dedicated server (Google Cloud) separate from WordPress.

We also set up Cloudflare DNS for the domain with all existing email records (Google Workspace MX, SPF, DKIM, DMARC) already in place, and wrote a Cloudflare Worker that routes specific page URLs to the new modern pages while sending everything else to the WordPress site.

Skincare Page — Bio-Regenerative Exosome Serum

Complete page built from scratch in modern HTML and CSS. Includes hero section, clinical results, product science breakdown, ethics section, call-to-action buttons, and the Revrcel AI chat widget.

Product Page Template — GHK-Cu Copper Peptide

Pixel-accurate rebuild of the WooCommerce product page. Image gallery, price display, quantity selector, "Add to Cart" button connected to the real WooCommerce cart. Serves as a reusable template for future product pages.

Bloodwork Membership Page

Full rebuild of the WordPress bloodwork page. Original scanned element-by-element using automated browser tools. Rebuilt from scratch in semantic HTML/CSS — matches the original design exactly. Loads dramatically faster.


2. Complete Website Replication — $8,000 Value

Full static HTML/CSS/JavaScript replication of the entire revrcel.com website. Every page on the live site was cloned into a standalone, high-performance static site deployed to Google Cloud Run as a separate service. The result is a complete, independent copy of the site that loads significantly faster than WordPress and can be customized, extended, or used as a migration target.

43 Pages
15 CSS Files
39 Assets
68 MB Total Size
23

Product Pages

  • Apex, BPC-157, Clarity, Define, Equilibria, Exosome Serum, Fortis, GHK-Cu, Gladiator, Gut Health, IGF-1 LR3, Ignite, Intimacy, LifeSpark, NAD+, Restore, Revival, Semaglutide, Semorelin, SleepWell, Testosterone, Tirzepatide, Vitalis
7

Main Pages

  • Home
  • Shop (+ 2 pagination pages)
  • Get Started
  • Bloodwork
  • Hormones
  • Contact
  • FAQs
6

Blog Pages

  • Blog Index
  • Aging With Confidence
  • The New Era of Wellness
  • Peptides for Women
  • The Future of Wellness
  • Elevate Your Performance
7

Account & Legal

  • Account Dashboard
  • Login
  • Cart
  • Privacy Policy
  • Terms & Conditions
  • HIPAA Policy
  • Skincare Index

Technical Deliverables

ComponentDetail
HTML Pages43 pages across 6 subdirectories (products, blog, account, skincare, legal, main)
CSS Architecture15 files — reset, variables, global, 2 component files (header/footer), 10 page-specific stylesheets
JavaScript2 files — core functionality + embedded chat widget
Image Assets37 files — logos, backgrounds, blog images, product images, team photos, icons
Video Assets2 files — hero video + redefine background video
Responsive DesignMobile (<768px), Tablet (768–1024px), Desktop (>1024px) breakpoints
DeploymentDockerfile + nginx.conf, deployed to Cloud Run (revrcel-website, us-east4)
DocumentationREPLICATION_PLAN.md (phased plan), SITEMAP.md (complete URL mapping)

3. HIPAA Compliance Audit — $5,000 Value

We conducted a comprehensive HIPAA compliance analysis of the Revrcel platform (operated by Bluprint Health), examining all technology systems, data flows, communication touchpoints, published policies, and vendor relationships for Protected Health Information (PHI) handling.

The audit assessed 12 website pages, 15 communication touchpoints across the full customer lifecycle, all published legal/policy pages, 8 vendors for BAA status, and conducted a deep dive into the GoHighLevel HIPAA module.

15/15 Touchpoints Non-Compliant
6 Critical Findings
3 Unfixable Gaps
0 BAAs Evidenced

Critical Findings

WordPress/WooCommerce has no HIPAA compliance pathway

Critical

Neither Automattic nor WooCommerce offer a Business Associate Agreement. Order records linking patients to peptide purchases constitute PHI when tied to a clinical relationship. No encryption, no access controls, no audit logging.

Lab scripts, results, and treatment plans sent via unencrypted email

Critical

The most sensitive clinical communications — lab orders, 100+ biomarker results, prescriptions, and treatment protocols — flow via standard email. No evidence of Paubox, Virtru, Hushmail, or any encrypted email service.

No Business Associate Agreements evidenced with any vendor

Critical

HIPAA requires BAAs with every vendor that touches PHI. No BAAs were evidenced with GoHighLevel, WordPress hosting, email provider, SMS provider, or lab partners.

No prescription verification gate in checkout

Critical

The FAQ states "all peptides require a doctor's prescription" but anyone can add products to cart and purchase without consultation, prescription, or physician approval. Product pages carry contradictory "research purposes only" disclaimers.

GoHighLevel HIPAA add-on likely not activated

Critical

Six observable indicators suggest the $297/mo HIPAA add-on is not active: misspelled HIPAA URL, no mention of GHL's HIPAA module in policies, privacy policy disclaims PHI collection, and overall compliance posture.

info@revrcel.com used for PHI access requests

Critical

The HIPAA policy directs patients to submit PHI access requests to info@revrcel.com — likely standard, unencrypted email. Every PHI response sent through it is a potential violation.

HIPAA policy is vague with no technical specifics

High

No mention of encryption standards, TLS versions, named platforms, or specific safeguards. URL is misspelled (/hippa-policy/ instead of /hipaa-policy/).

Privacy policy contradicts actual data collection practices

High

States "We do not knowingly collect PHI through standard website forms" while the business model inherently collects PHI through WooCommerce checkout tied to clinical relationships.

No secure patient portal for clinical document exchange

High

All clinical documents (lab scripts, results, treatment plans, prescriptions) exchanged via email rather than a secure, access-controlled patient portal.

Three Unfixable Gaps

These gaps cannot be resolved within the current technology stack:

Gap 1: WooCommerce Gap

Order records linking patients to specific peptide purchases constitute PHI. WooCommerce stores this in an unencrypted MySQL database with no access controls, no audit logging, and no BAA. There is no HIPAA pathway for WooCommerce — it cannot be fixed, only replaced.

Gap 2: Email Gap

The most sensitive clinical communications — lab scripts, lab results, treatment plans, prescriptions — flow via standard email between Dr. Hodor and patients, outside of any encrypted or HIPAA-compliant system.

Gap 3: Prescription Enforcement Gap

Anyone can purchase peptide products without consultation, prescription verification, or physician approval — despite the FAQ stating "all peptides require a doctor's prescription." Product pages carry "research and educational purposes only" disclaimers that contradict the physician-supervised clinical framing.

Audit Deliverables

HIPAA Compliance & Purchase Flow Analysis

Markdown — 581 lines

HIPAA Compliance Analysis (Styled)

Print-ready HTML — 50 KB

HIPAA Compliance Analysis (Executive)

PDF — 8 pages, 486 KB

HIPAA-Compliant Platform Build Plan

Markdown — 355 lines (full remediation spec)

The build plan includes complete specifications for a HIPAA-compliant replacement platform: database schema (9 migrations), field-level AES-256 encryption, hash-chained tamper-proof audit logging, role-based access control, prescription verification gate, and an 8-phase implementation roadmap. Remediation work is not included in this invoice and would be scoped separately.


Summary
DeliverableMarket ValueStatus
Infrastructure (Cloud Run + Docker + nginx + GitHub + Cloudflare) $2,000 Delivered
3 landing pages (Skincare, Product Template, Bloodwork) Included Delivered
Complete website replication (43 pages, 68 MB) $8,000 Delivered — Market Price
HIPAA Compliance Audit & Risk Assessment $5,000 Delivered — Market Price
Routing to revrcel.com Blocked (GoDaddy nameserver change)
HIPAA remediation platform build Scoped separately (build plan delivered)