VeUP
← All case studies
AWS Level 1 MSSP · Security-Pillar WAFR + Incident-Response Advisory
A North American healthcare commercial-intelligence SaaS platformIdentity protected

Healthcare-data platform hardens AWS identity under live incident response

Well-Architected ReviewAdvisoryCentralized workforce identityIdentity federation & MFA enforcementHigh-risk-issue remediation roadmapTarget-state architecture design & costed POCWorkload placement & runtime selectionMigration TCO & business case modellingGo-to-market strategy advisory
Multi-billion-row
healthcare dataset brought under least-privilege access
1 governed path
three identity sources federated to scoped roles
Known-good
credentials rotated, data integrity restored
AWS Security HubAWS IAMAmazon CognitoAWS Backup

Shared anonymously — the customer’s name is held by VeUP and available on request.

For a North American healthcare commercial-intelligence platform on multi-billion-row HCP and claims data, VeUP ran a Security-pillar Well-Architected Review and acted as AWS security advisor through a live hardening effort: IAM least-privilege, federated identity to scoped roles, and recovery to a known-good baseline.

The challenge

The customer runs a healthcare commercial-intelligence platform serving queries over very large HCP and medical-claims datasets. As the platform scaled, its AWS identity and access posture needed to be brought into line with the AWS Well-Architected security pillar: console access spanned multiple identity sources, IAM permissions had drifted from least-privilege, and the team needed a clear, auditable hardening path — including the ability to recover cleanly and restore data integrity under pressure. The customer needed an AWS security advisor who could both assess the environment against the security pillar and provide hands-on hardening guidance in real time.

The solution

VeUP paired a Security-pillar Well-Architected Review with hands-on security advisory through the live hardening effort, working within the AWS shared-responsibility model. The review, run through AWS Security Hub, surfaced the highest-priority identity and access gaps first. VeUP then drove AWS IAM least-privilege remediation and consolidated console access by federating the customer's identity sources — Amazon Cognito, Microsoft Entra ID, and Google — to scoped IAM roles, replacing fragmented sign-in paths with one governed, auditable route. Credentials and access keys were rotated and data integrity restored from available backups, putting the platform back on a known-good baseline. Controls outside VeUP's advisory scope went to a dedicated managed incident-response provider, keeping the customer covered end to end.

Production outcomes

KPIResult
Production outcomesLeast-privilege IAM now applies across the environment, closing the highest-priority access gaps the Security Hub review surfaced. Console access flows through one governed path — Cognito, Entra ID, and Google federated to scoped IAM roles. Credentials were rotated and data integrity restored, putting the platform back on a known-good security baseline, with controls beyond advisory scope handled by a dedicated managed incident-response partner. Through the whole hardening window, VeUP was the customer's trusted AWS security advisor.
Engagement windowThe partnership began in mid-2025. The Security-pillar review and live hardening ran in January 2026 — identity and access hardened, credentials rotated, integrity restored — and the advisory relationship continues.
Cost / TCO postureThe security advisory ran inside VeUP’s ongoing partnership with the customer. A parallel replatform of the data layer (BigQuery → S3/Athena) is its own migration and modernization story, told separately.
Lessons & continuationUnder a live incident, consolidating fragmented console-access identity sources to scoped IAM roles is the fastest way to re-establish a governed, auditable access path. Restoring a known-good baseline (credential rotation + integrity restoration) and escalating controls outside advisory scope to a dedicated IR provider keeps the customer covered end-to-end under the shared-responsibility model.
AWS services in production
AWS Security HubAWS IAMAmazon CognitoAWS BackupAWS Well-Architected Tool
Federated identity sources
Microsoft Entra IDGoogle

Architecture

From fragmented sign-in paths and attacked surfaces to one governed environment: federated identity through AWS IAM Identity Center, least-privilege IAM, Security Hub and CloudTrail detection, and AWS Backup recovery.

The hardened AWS environment — identity consolidated through AWS IAM Identity Center to least-privilege AWS IAM roles, AWS Secrets Manager / KMS credential rotation, SSM Session Manager MFA-gated access, a VPC compute tier (ECS, EKS, QuickSight, RDS), AWS Backup recovery, a Security Hub / CloudTrail / CloudWatch detection rail, a planned hardening backlog (WAF, Shield, Security Groups/VPC segmentation), and escalation to a dedicated managed incident-response provider.
The hardened environment — one federated sign-in path, least-privilege roles, detection wired in, recovery ready.
The environment before hardening — fragmented identity sources (Amazon Cognito, Microsoft Entra ID, Google) each with an independent console-access path, and attacked compute/analytics surfaces (Amazon ECS, Amazon EKS, Amazon QuickSight, Amazon RDS) with only partial backup coverage at incident time.
The starting point — three separate sign-in paths, attacked surfaces, and only partial backup coverage.