VeUP
← All case studies
Level 1 MSSP · QuickSight reporting
A North American healthcare commercial-intelligence SaaS platformIdentity protected

Healthcare-data platform hardens AWS identity under live incident response

Well-Architected ReviewAdvisoryCentralized workforce identityIdentity federation & MFA enforcementHigh-risk-issue remediation roadmapTarget-state architecture design & costed POCWorkload placement & runtime selectionMigration TCO & business case modellingGo-to-market strategy advisory
Multi-billion-row
healthcare dataset brought under least-privilege access
1 governed path
three identity sources federated to scoped roles
Known-good
credentials rotated, data integrity restored
Amazon QuickSightAmazon AthenaAWS GlueAmazon S3

The value of the platform’s multi-billion-row healthcare dataset is realized where people see it. On the AWS-native analytics platform VeUP delivered — Amazon S3 lake, AWS Glue catalog, Amazon Athena query — Amazon QuickSight operates as the production reporting surface: permissioned access to visualized healthcare-provider and claims intelligence, governed with the same discipline as the data underneath it.

The challenge

Reporting over regulated healthcare data cuts both ways: the business needs its commercial-intelligence insights visible and self-serve, while every dashboard is, structurally, an access path to sensitive data — and must be permissioned like one. The platform’s migration off its previous warehouse reset the reporting layer’s foundations, creating the obligation and the opportunity to rebuild it AWS-native: connected directly to the new lake’s query engine, without data copies drifting into unmanaged tools, and with viewer access scoped deliberately rather than broadly.

The solution

Amazon QuickSight completes the platform’s AWS-native analytics chain. It reads through Amazon Athena against the Glue-cataloged S3 lake — the same governed path every other consumer uses, so reporting reflects the catalog’s single definition of the data with no side-channel extracts to secure separately. Access is permissioned: QuickSight’s users, groups, and dataset permissions scope who can see which reporting surfaces over the healthcare dataset, operating as one of the platform’s named production access controls — reviewed as part of the estate’s Security-pillar Well-Architected discipline rather than left as an untracked SaaS bolt-on. Alongside the Amazon RDS-backed profile web tier, the result is a two-surface product: the application for operational use, QuickSight for analytical reporting — both fed by, and governed with, the same platform.

Production outcomes

KPIResult
Production reporting surfaceQuickSight live as the permissioned reporting layer over the multi-billion-row healthcare dataset — a governed production control, not a design artifact.
One governed data pathReporting reads through Athena and the Glue catalog — the same path as the product — so dashboards inherit the lake’s schema truth and access governance with zero duplicated extracts.
Access disciplineQuickSight permissioning maintained among the platform’s reviewed production access controls under its Well-Architected security discipline — visibility scoped to who needs which surface.
Lessons & continuationIn regulated analytics, the reporting tool is part of the security perimeter — connect it through the governed query path and review its permissions like any IAM policy; serverless BI on a serverless lake keeps the whole chain paying per use.
AWS services in production

Amazon QuickSight (permissioned reporting) · Amazon Athena · AWS Glue Data Catalog · Amazon S3 (data lake) · Amazon RDS (profile web tier)