Healthcare-data platform hardens AWS identity under live incident response
Shared anonymously — the customer’s name is held by VeUP and available on request.
For a North American healthcare commercial-intelligence platform on multi-billion-row HCP and claims data, VeUP ran a Security-pillar Well-Architected Review and acted as AWS security advisor through a live hardening effort: IAM least-privilege, federated identity to scoped roles, and recovery to a known-good baseline.
The challenge
The customer runs a healthcare commercial-intelligence platform serving queries over very large HCP and medical-claims datasets. As the platform scaled, its AWS identity and access posture needed to be brought into line with the AWS Well-Architected security pillar: console access spanned multiple identity sources, IAM permissions had drifted from least-privilege, and the team needed a clear, auditable hardening path — including the ability to recover cleanly and restore data integrity under pressure. The customer needed an AWS security advisor who could both assess the environment against the security pillar and provide hands-on hardening guidance in real time.
The solution
VeUP paired a Security-pillar Well-Architected Review with hands-on security advisory through the live hardening effort, working within the AWS shared-responsibility model. The review, run through AWS Security Hub, surfaced the highest-priority identity and access gaps first. VeUP then drove AWS IAM least-privilege remediation and consolidated console access by federating the customer's identity sources — Amazon Cognito, Microsoft Entra ID, and Google — to scoped IAM roles, replacing fragmented sign-in paths with one governed, auditable route. Credentials and access keys were rotated and data integrity restored from available backups, putting the platform back on a known-good baseline. Controls outside VeUP's advisory scope went to a dedicated managed incident-response provider, keeping the customer covered end to end.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | Least-privilege IAM now applies across the environment, closing the highest-priority access gaps the Security Hub review surfaced. Console access flows through one governed path — Cognito, Entra ID, and Google federated to scoped IAM roles. Credentials were rotated and data integrity restored, putting the platform back on a known-good security baseline, with controls beyond advisory scope handled by a dedicated managed incident-response partner. Through the whole hardening window, VeUP was the customer's trusted AWS security advisor. |
| Engagement window | The partnership began in mid-2025. The Security-pillar review and live hardening ran in January 2026 — identity and access hardened, credentials rotated, integrity restored — and the advisory relationship continues. |
| Cost / TCO posture | The security advisory ran inside VeUP’s ongoing partnership with the customer. A parallel replatform of the data layer (BigQuery → S3/Athena) is its own migration and modernization story, told separately. |
| Lessons & continuation | Under a live incident, consolidating fragmented console-access identity sources to scoped IAM roles is the fastest way to re-establish a governed, auditable access path. Restoring a known-good baseline (credential rotation + integrity restoration) and escalating controls outside advisory scope to a dedicated IR provider keeps the customer covered end-to-end under the shared-responsibility model. |
Architecture
From fragmented sign-in paths and attacked surfaces to one governed environment: federated identity through AWS IAM Identity Center, least-privilege IAM, Security Hub and CloudTrail detection, and AWS Backup recovery.

