A North American healthcare commercial-intelligence SaaS platform
AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)
For a North American healthcare commercial-intelligence platform on multi-billion-row HCP and claims data, VeUP ran a Security-pillar Well-Architected Review and acted as AWS security advisor through a live hardening effort: IAM least-privilege, federated identity to scoped roles, and recovery to a known-good baseline.
The challenge
The customer runs a healthcare commercial-intelligence platform serving queries over very large HCP and medical-claims datasets. As the platform scaled, its AWS identity and access posture needed to be brought into line with the AWS Well-Architected security pillar: console access spanned multiple identity sources, IAM permissions had drifted from least-privilege, and the team needed a clear, auditable hardening path — including the ability to recover cleanly and restore data integrity under pressure. The customer needed an AWS security advisor who could both assess the environment against the security pillar and provide hands-on hardening guidance in real time.
The solution
A Security-pillar Well-Architected Review plus hands-on AWS security advisory through an active hardening effort, delivered within the AWS shared-responsibility model. (1) Posture review — reviewed the environment against the security pillar using AWS Security Hub, surfacing the highest-priority identity and access gaps. (2) Identity and access hardening — drove AWS IAM least-privilege remediation and consolidated console access by federating the customer's identity sources (Amazon Cognito, Microsoft Entra ID, and Google) to scoped IAM roles, so access was governed through a controlled, auditable path rather than fragmented sources. (3) Credential and recovery controls — guided credential and access-key rotation and restored data integrity from available backups, re-establishing a known-good baseline. (4) Escalation — coordinated escalation to a dedicated managed incident-response provider for controls outside VeUP's advisory scope.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | IAM least-privilege remediation applied across the environment, closing the highest-priority access gaps surfaced in the Security Hub review; consolidated, federated identity — Cognito, Entra, and Google federated to scoped IAM roles for governed console access; credential rotation and integrity restoration completed, re-establishing a known-good security baseline; a clear AWS shared-responsibility hardening narrative with appropriate escalation to a dedicated managed incident-response partner. VeUP acted as the customer's trusted AWS security advisor through the hardening window. |
| Engagement window | 2025-07-23 (Resell/Ignite onboarding); Security-pillar WAFR + live hardening Jan 2026 → Identity/access hardening, credential rotation, and integrity restoration delivered; advisory ongoing |
| Cost / TCO posture | Two AWS-funded engagements: a Resell/Ignite onboarding ($96K ARR opp) and a paid Migration (Build) professional-services engagement (PS $60K). The security advisory was delivered within the funded Ignite relationship; the parallel data-platform replatform (BigQuery → S3/Athena) is tracked as a separate Migration & Modernization narrative. |
| Lessons & continuation | Under a live incident, consolidating fragmented console-access identity sources to scoped IAM roles is the fastest way to re-establish a governed, auditable access path. Restoring a known-good baseline (credential rotation + integrity restoration) and escalating controls outside advisory scope to a dedicated IR provider keeps the customer covered end-to-end under the shared-responsibility model. |
AWS Security Hub · AWS IAM (least-privilege) · Amazon Cognito + Microsoft Entra ID + Google (federated to scoped IAM roles) · AWS Backup · AWS Well-Architected Tool
Architecture
AWS Well-Architected view of the security-pillar hardening — from the pre-remediation baseline of fragmented identity sources and attacked compute surfaces through to the target-state AWS environment: federated identity via AWS IAM Identity Center, least-privilege IAM, Security Hub / CloudTrail detection, and AWS Backup recovery.


