HIPAA-aligned cloud foundation for a clinical data startup
Cleared HIPAA technical safeguards review with their first enterprise customer's security team — on the first pass.
- 1 (first pass)
- Security review cycles
- 100%
- Encrypted data stores
- All privileged paths
- IAM roles with break-glass
- 7 years, immutable
- Audit log retention
A two-engineer founding team with a working prototype on a single AWS account, hardcoded credentials in env files, and an enterprise customer asking for a HIPAA attestation in six weeks.
- 01
Multi-account org with dedicated accounts for prod, staging, audit, and security tooling. SSO with break-glass procedure documented and rehearsed.
- 02
VPC architecture with PHI-handling workloads isolated, all egress through inspected paths, no public subnets in production.
- 03
Replaced env-file secrets with Vault on a hardened EKS cluster, dynamic database credentials, secrets rotation automated.
- 04
Wired CloudTrail, GuardDuty, and Config into the audit account with immutable storage. Mapped each HIPAA technical safeguard to a specific technical control with evidence collected continuously.
- 05
Wrote the actual policies — access management, incident response, change management — in plain English, with the technical controls each one referenced.
Passed the customer's review on first submission. The CTO walked into the next sales conversation with a one-page security overview that was true. The same foundation later carried them through SOC 2 Type I without re-architecture.
Other engagements.
Rebuilding the platform under a payments company without slowing the roadmap
Cut deploy time from 38 minutes to under 9, reduced cluster spend by 31%, and got the team out of a quarterly upgrade panic.
Standing up a platform team where there wasn't one
Delivered a working internal developer platform, paved-path service template, and hired the two engineers who own it now.
Getting an e-commerce platform through Black Friday without a war room
Handled 7.2x the previous year's peak with a single sub-five-minute degradation, no all-hands incident, and a smaller bill than the prior year.