VeUP
← All case studies
Production Engagement · Anonymized
Healthcare-data platform hardens AWS identity and access posture under live incident response
Life Sciences & Healthcare (SaaS — healthcare commercial intelligence over HCP + medical-claims data)
AWS Security HubAWS IAMAmazon CognitoAWS Backup
Security Competency · Security-Pillar WAFR + Incident-Response Advisory

A North American healthcare commercial-intelligence SaaS platform

AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)

For a North American healthcare commercial-intelligence platform on multi-billion-row HCP and claims data, VeUP ran a Security-pillar Well-Architected Review and acted as AWS security advisor through a live hardening effort: IAM least-privilege, federated identity to scoped roles, and recovery to a known-good baseline.

The challenge

The customer runs a healthcare commercial-intelligence platform serving queries over very large HCP and medical-claims datasets. As the platform scaled, its AWS identity and access posture needed to be brought into line with the AWS Well-Architected security pillar: console access spanned multiple identity sources, IAM permissions had drifted from least-privilege, and the team needed a clear, auditable hardening path — including the ability to recover cleanly and restore data integrity under pressure. The customer needed an AWS security advisor who could both assess the environment against the security pillar and provide hands-on hardening guidance in real time.

The solution

A Security-pillar Well-Architected Review plus hands-on AWS security advisory through an active hardening effort, delivered within the AWS shared-responsibility model. (1) Posture review — reviewed the environment against the security pillar using AWS Security Hub, surfacing the highest-priority identity and access gaps. (2) Identity and access hardening — drove AWS IAM least-privilege remediation and consolidated console access by federating the customer's identity sources (Amazon Cognito, Microsoft Entra ID, and Google) to scoped IAM roles, so access was governed through a controlled, auditable path rather than fragmented sources. (3) Credential and recovery controls — guided credential and access-key rotation and restored data integrity from available backups, re-establishing a known-good baseline. (4) Escalation — coordinated escalation to a dedicated managed incident-response provider for controls outside VeUP's advisory scope.

Production outcomes

KPIResult
Production outcomesIAM least-privilege remediation applied across the environment, closing the highest-priority access gaps surfaced in the Security Hub review; consolidated, federated identity — Cognito, Entra, and Google federated to scoped IAM roles for governed console access; credential rotation and integrity restoration completed, re-establishing a known-good security baseline; a clear AWS shared-responsibility hardening narrative with appropriate escalation to a dedicated managed incident-response partner. VeUP acted as the customer's trusted AWS security advisor through the hardening window.
Engagement window2025-07-23 (Resell/Ignite onboarding); Security-pillar WAFR + live hardening Jan 2026 → Identity/access hardening, credential rotation, and integrity restoration delivered; advisory ongoing
Cost / TCO postureTwo AWS-funded engagements: a Resell/Ignite onboarding ($96K ARR opp) and a paid Migration (Build) professional-services engagement (PS $60K). The security advisory was delivered within the funded Ignite relationship; the parallel data-platform replatform (BigQuery → S3/Athena) is tracked as a separate Migration & Modernization narrative.
Lessons & continuationUnder a live incident, consolidating fragmented console-access identity sources to scoped IAM roles is the fastest way to re-establish a governed, auditable access path. Restoring a known-good baseline (credential rotation + integrity restoration) and escalating controls outside advisory scope to a dedicated IR provider keeps the customer covered end-to-end under the shared-responsibility model.
AWS services in production

AWS Security Hub · AWS IAM (least-privilege) · Amazon Cognito + Microsoft Entra ID + Google (federated to scoped IAM roles) · AWS Backup · AWS Well-Architected Tool

Architecture

AWS Well-Architected view of the security-pillar hardening — from the pre-remediation baseline of fragmented identity sources and attacked compute surfaces through to the target-state AWS environment: federated identity via AWS IAM Identity Center, least-privilege IAM, Security Hub / CloudTrail detection, and AWS Backup recovery.

Previous state — fragmented identity sources (Amazon Cognito, Microsoft Entra ID, Google) each with an independent console-access path, and attacked compute/analytics surfaces (Amazon ECS, Amazon EKS, Amazon QuickSight, Amazon RDS) with only partial backup coverage at incident time.
Previous state
Target state on AWS — identity consolidated through AWS IAM Identity Center to least-privilege AWS IAM roles, AWS Secrets Manager / KMS credential rotation, SSM Session Manager MFA-gated access, a VPC compute tier (ECS, EKS, QuickSight, RDS), AWS Backup recovery, a Security Hub / CloudTrail / CloudWatch detection rail, a planned hardening backlog (WAF, Shield, Security Groups/VPC segmentation), and escalation to a dedicated managed incident-response provider.
Target state on AWS
Layer-by-layer build-up of the target-state AWS architecture: network foundation, compute and application, data, security and observability, and the numbered data/network paths connecting them.
Layer-by-layer build-up
A North American healthcare commercial-intelligence SaaS platform — AWS Well-Architected security architecture diagram. Previous state: fragmented identity sources (Amazon Cognito, Microsoft Entra ID, Google) each with independent console access, and attacked compute/analytics surfaces (Amazon ECS, Amazon EKS, Amazon QuickSight, Amazon RDS) with only partial backup coverage. Target state: AWS Cloud with identity consolidated through AWS IAM Identity Center to least-privilege AWS IAM roles, AWS Secrets Manager / KMS credential rotation, SSM Session Manager MFA-gated access, a VPC compute tier (ECS, EKS, QuickSight, RDS), AWS Backup recovery, a Security Hub / CloudTrail / CloudWatch detection rail, a planned hardening backlog (WAF, Shield, Security Groups/VPC segmentation), and escalation to a dedicated managed incident-response provider. Includes a Well-Architected pillar-by-pillar alignment strip.
Full Well-Architected overview — VeUP-rendered diagram from the VeUP engagement record and AWS Security Competency case-study evidence (Security-pillar WAFR, IAM/identity-federation hardening).