ASU · Mayo Clinic·Product Design Lead·2025
Designing for trust in cancer care
ChemoBuddy is a companion app for people going through chemotherapy. It replaces a 40-page binder with one calm, prioritized action, built with Mayo Clinic physicians who validated every symptom-to-urgency call.
100%
usability task completion
+85%
session time, 4.2 to 7.8 minutes
Zero
critical alert failures during pilot
Selected
for the Mayo Clinic Observership

Problem
Cancer patients receive a 40-page information binder at diagnosis, at the exact moment they are least able to read it. The real questions arrive later: at 2 AM, in parking lots, halfway through an infusion. The system is built to be just-in-case when patients need it to be just-in-time. Existing patient portals solve the wrong half of this. They show medical records, and patients were not asking for their records. They were asking what to do today.
Constraints
No direct patient access
Ethical review ruled out interviewing people in active treatment. Every research signal had to come through structured role-play designed with clinicians instead.
Clinical safety is not negotiable
A symptom classified wrong could delay emergency care. Every symptom-to-urgency threshold needed physician sign-off before it could ship.
Institutional trust does not transfer
Mayo Clinic credibility does not automatically carry into a mobile app. The product had to earn trust screen by screen, on its own.
Design for the worst day
The user is nauseated, exhausted, and working through chemo brain. Anything that only holds up in ideal conditions does not hold up at all.
Key Insight
We assumed patients wanted comprehensive access to their information, but the sessions revealed they wanted permission to stop worrying. Nobody asked for more content. Every one of them asked some version of the same question: am I doing this right? The job was to manufacture certainty, not to deliver information.
Solution
Designed ChemoBuddy, a companion built so the conversation is the shell and structure is the answer. A patient describes a symptom in plain language and the assistant does not reply with an essay. It opens a guided body map, a region picker, and a severity scale, then returns a triage result. Education arrives the same way, as a short video followed by a three-question check inside the same thread rather than an article to go read. Red-flag symptoms escalate to explicit emergency instructions and a ranked list of nearby ERs. Caregivers are invited by the patient into Primary or Secondary roles with per-signal sharing toggles, under a standing notice showing exactly how many people can see their data.
My Role
- Product Design Lead, ChemoBuddy
- Partnered with Dr. Umar Janjua at Mayo Clinic to run 12 structured patient and caregiver role-play sessions
- Owned the conversational assistant, body-map symptom tracking, guided education, and caregiver permission flows
- Ran clinical safety review with Dr. Irbaz Riaz across three rounds of symptom-to-urgency thresholds
- 10-week engagement, end to end
Duration
10 weeks at ASU, in partnership with Mayo Clinic
Team Collaboration
Oncologists, Oncology Nurses, Clinical Researchers, Caregivers
Impact
100%
usability task completion
+85%
session time, 4.2 to 7.8 minutes
Zero
critical alert failures during pilot
Selected
for the Mayo Clinic Observership
The choices that shaped the product
Key Decisions
Decision 01
Today, not a dashboard
The obvious answer was a comprehensive health hub: appointments, medications, logs, education, all in one place. We built it, and in role-play testing participants scrolled it for roughly 90 seconds without clicking anything. Everything had the same visual weight, so nothing read as the next thing to do. Dr. Riaz put it plainly: they do not want their record, they want to know what to do today. We replaced the hub with a strict hierarchy of Now, Today, This Week, Library, and made only the top level visible by default. The other three still exist. They just stop competing for attention on a day when attention is the scarcest thing the patient has. Task completion went to 100%.

Decision 02
Conversation as the door, structure as the answer
Patients have questions at odd hours, so leading with a conversational assistant looked right on paper. Testing complicated it. Participants loved that something would answer at 2 AM, then sat with a blank prompt and did not know what to ask. Open-ended input made them enumerate worst cases, and none of them trusted an AI to tell them whether a symptom was an emergency. The fix was not to demote the chat. It was to stop letting the chat answer freely. A patient now says they have a severe headache and the assistant does not diagnose. It asks one clarifying question, opens a guided body map, then a region picker, then a severity scale, and returns a triage result against clinically validated thresholds. Education runs on the same rail: a two-minute video, then a three-question check, inside the same thread. A standing banner on every screen states the chat is for education only and to contact a provider for urgent concerns, which is the line that made clinicians comfortable shipping any of it.

Decision 03
Patient-invited caregivers, not auto-sharing
Early designs assumed caregivers wanted full visibility and patients wanted them to have it. Dr. Umar corrected that in one sentence: some patients do not want their family to know how scared they are. So the default became private and the patient does the inviting. Access comes as two named roles rather than one on-off switch. A Primary caregiver can view and edit health data, manage the other caregivers, and receive every notification. A Secondary caregiver can read symptom and medication logs and nothing more, with no edit rights and no say over who else is in. Underneath sit per-signal sharing toggles, and above it a standing privacy notice that names exactly how many people can currently see the patient data, with Manage access one tap away. Family does most of the real tracking in cancer care and most tools treat them as an afterthought, but handing them a firehose by default takes something from the patient. This was where we stopped designing for HIPAA and started designing for emotional privacy.

Context
At diagnosis, a cancer patient is handed a 40-page information binder. It is thorough, it is accurate, and it arrives at the exact moment the person receiving it is least able to read anything. The binder answers questions the patient has not thought to ask yet, and by the time those questions do arrive, at 2 AM, in a hospital parking lot, halfway through an infusion, the binder is at home on a shelf.
The existing digital answer does not close that gap. Patient portals like MyChart are records systems. They show lab values, visit summaries, and appointment history, which is the right tool for a clinician and the wrong tool for someone trying to decide whether the way they feel right now is normal or an emergency. Patients were not asking for their records. They were asking what to do today.
ChemoBuddy was built to answer that question and only that question. A companion that shows one prioritized action, lets patients log what they feel by tapping a body map instead of translating it into medical vocabulary, and puts a real clinical escalation path behind every triage result. It was designed with Mayo Clinic physicians over 10 weeks and was selected for the Mayo Clinic Observership.
Problem Statement
“Design a chemotherapy companion that answers the question patients actually ask. Not what does my record say, but am I doing this right, today.”
Pain Points
Information Overload at the Worst Moment
A 40-page binder handed over on diagnosis day, with no clear starting point and no sense of what matters first. Comprehensive is not the same as usable.
The "Is This Normal?" Loop
Every new symptom forces the same unanswerable question: emergency or side effect. Without a fast way to resolve it, patients either panic or wait too long, and both outcomes are bad.
Caregivers Are Invisible to the Tools
Family members do most of the real tracking, appointment logistics, and symptom recall. Nearly every product treats them as an afterthought with no account of their own.
Trust Does Not Come Preinstalled
Institutional credibility does not automatically transfer to a mobile app. One confusing screen at 2 AM and the patient stops believing the rest of it.
Research
Sixteen weeks from market analysis to human truth, validated at every step.
Phase 01·Weeks 1 to 3
Clinical Context and Landscape
- The information patients receive is front-loaded to the single day they are least equipped to absorb it. Everything after that is self-serve.
- The literature was consistent that mHealth improves symptom management and quality of life, and equally consistent that the evidence base has gaps around older adults, feasibility, and long-term adoption. It also flagged the specific risk we were walking into: AI chatbots in oncology education carry real exposure to misinformation and misplaced trust, and reviewers called for transparency and periodic clinical review as the mitigation.
- Not one of the 7 competitors covered the whole job. MyChart holds the records but has no symptom tracking or personalized education. Belong has community but no clinical integration. MyLifeLine handles caregivers well and sits completely outside clinical care. Wellframe personalizes but is not built for chemotherapy side effects. The gap was not a missing feature, it was that nobody had joined education, symptom triage, caregivers, and the care team in one place.
- Clinicians already knew the binder was not working. What they lacked was a channel that could reach patients between visits without adding to their own inbox.
- Direct access to patients in active treatment was ruled out on ethical grounds, which meant the research design had to route around it rather than push against it.


Phase 02·Weeks 4 to 7
Human Truth Discovery
- Patients were not asking for more content. They were asking for confirmation that they were handling this correctly. The unmet need was certainty, not access.
- The highest-anxiety moments were not appointments. They were the hours in between, when something felt wrong and there was nobody to ask.
- Caregivers consistently described wanting to help without making the patient feel watched. Several patients, independently, described wanting help without revealing how frightened they were.
- The two personas failed the same design in opposite ways. Sarah, about to start, needed orientation and short actionable insights she could glance at between work breaks. Rachel, on day 4 of her third cycle, often could not focus on a screen at all and used the app lying down. Anything that assumed a reading patient broke for one of them.


By the time I find the answer, I have already panicked.
Role-play participant, on the search crisis
I want my daughter to help, but I do not want her to see how scared I am.
Role-play participant, on the privacy paradox
Some days I can barely read the screen. I just want a voice to tell me what matters right now.
Rachel, mid-cycle persona, on why audio shipped
Phase 03·Weeks 8 to 10
Solution Validation
- Designs that tested well in ideal conditions failed under simulated chemo brain. The body map exists because text-entry symptom forms did not survive that test.
- Task completion reached 100% once the home screen was reduced to a single prioritized action, and session time grew 85%, from 4.2 to 7.8 minutes, which read as deeper use rather than confusion.
- Every red-flag symptom in the pilot was correctly classified and routed. Zero critical alert failures.
It does not feel like an app, it feels like a companion.
Pilot participant, on the trust moment
Design Pillars
The principles that guided every decision from sketches to ship.
Progressive Disclosure
Show only what is needed now. Everything else still exists and stays one tap away, but it does not compete for attention on a day when attention is the scarcest resource the patient has.
Calm Authority
Every interaction has to read as this understands what you are going through. Not clinical enough to alarm, not casual enough to minimize. The tone an oncology nurse uses on the phone.
Patient Sovereignty
Privacy here is emotional, not just legal. HIPAA is the floor. The real design work is giving the patient control over who gets to see their fear.
User Flows
Two roles, one shared system. Built so coordination feels invisible.
Patient: symptom logging, led by the conversation
“I just need to know if I am doing this right.”


Patient: guided education, same thread
“Do not hand me a hundred pages of general advice.”


Caregiver: supportive but bounded
“I want to help without making them feel watched.”

Clinical: the safety net
“We need signal without noise.”

Usability Testing
Findings from real users that turned assumptions into evidence.
Participants
12 role-play dyads across patient and caregiver pairs, tested in sleep-deprived and distracted states to approximate real treatment conditions
Methodology
Clinician-authored role-play scenarios, followed by task-based usability testing and three rounds of clinical safety review
A comprehensive home screen produced no action at all
Issue
Participants scrolled the health hub for roughly 90 seconds without clicking anything. Appointments, medications, logs, and education all carried the same visual weight, so nothing read as the next thing to do.
Resolution
Replaced the hub with a strict Now, Today, This Week, Library hierarchy, with only the top level visible by default. Task completion moved to 100%.
An open chatbot raised anxiety instead of lowering it
Issue
Participants loved that something would answer at 2 AM, then sat with a blank prompt and did not know what to ask. Open-ended input made them enumerate worst cases, and none of them trusted an AI to triage a symptom.
Resolution
Kept the conversation as the entry point but stopped it answering freely. It now asks one clarifying question and hands the patient a guided body map, a region picker, and a severity scale, with a standing banner stating the chat is for education only.
Alert tone landed wrong in both directions
Issue
The first pass at alert copy read as casual and minimized real concerns. The rewrite over-corrected into clinical language that alarmed participants who were already frightened.
Resolution
Calibrated the copy with oncology nurses across three passes until it read as empathetic, direct, supportive authority. The words a nurse would actually use on the phone.
Dense text was unreadable on treatment days
Issue
Education shipped as long-form articles. Participants simulating chemo brain could not hold a paragraph, and several abandoned mid-article without finding the answer.
Resolution
Made the session ask before it delivers. Video sessions, audio explanation, flashcards, or text guide, chosen by the patient at the start. Audio matters most, because it is the only format that still works with your eyes closed.
Before & After
Iterations from user testing that meaningfully shifted behavior.
Knowing the number is current
Before

The journey header showed overall treatment progress with no indication of when it last pulled from the care team. Nothing on screen told the patient whether they were looking at today or at last week.
After

An animated confirmation lands under the title as the data arrives: last synced 2h ago. One line, and the progress figure above it reads as fact rather than an estimate.
Emergency guidance you can actually read
Before

The urgent response arrived as one solid block of pink, opening with a hedge about being glad you reached out before getting to the point. Three critical instructions ran together inside a single tinted field, including the do-not instruction that mattered most.
After

An Attention Needed badge, a white card with real whitespace, and each instruction on its own icon-led row. Alternating message colours separate every turn of the conversation. The preamble is gone and the do-not instruction is impossible to skim past.
Ask how they want to learn, do not assume
Before

The assistant answered a treatment question with a dense paragraph covering both drugs, then pointed at an education section somewhere else. One format, delivered whether or not the patient could read right then.
After

The session opens by asking which format works: video session, audio explanation, flashcards, or text guide. Audio matters most here, because it is the only one that still works with your eyes closed.
Gallery





What partners say
Operators using the product in the field, in their own words.
“This respects the patient autonomy while still giving us clinical signal. That is the balance we have been looking for.”

Dr. Irbaz Riaz
Oncology, Mayo Clinic
Reflections
Design for the worst day, not the best
We ran usability testing with participants who were sleep-deprived and deliberately distracted, because that is closer to the real condition of someone mid-treatment than a rested person in a quiet room. Designs that tested cleanly in ideal conditions fell apart under those constraints. The body map is not a nice interaction pattern I wanted to use. It exists because text-entry symptom forms did not survive a simulation of chemo brain, and nothing else we tried did either.
Clinical collaboration is design material
Dr. Riaz and Dr. Umar were not stakeholders to keep happy. They were expert users whose knowledge the product needed to encode. Every symptom-to-urgency mapping in the app came out of a review with them, and the thresholds went through three rounds before they held up. The single sharpest correction in the whole project was one sentence from Dr. Umar about patients not wanting family to see how scared they are, which rewrote the entire caregiver model.
Trust is cumulative and fragile
One confusing screen erodes confidence in the whole system, and a cancer patient at 2 AM has no margin for a product that seems unsure of itself. That pushed a disproportionate amount of the work into micro-interactions: the sync confirmation, the loading state while records connect, the exact wording of an alert. None of it shows up in a feature list. All of it determines whether the app gets opened a second time.
Privacy is emotional before it is legal
HIPAA compliance is table stakes and it is also not the thing patients were worried about. What they wanted was control over who sees their vulnerability, which is a product decision, not a policy one. Defaulting caregiver access to private and making it revocable without explanation cost us almost nothing to build and was the change participants reacted to most strongly.
