End-to-end HIPAA-grade AWS, hardened through a third-party pen test.
A US healthtech running analytics over protected health information needed an audit-ready AWS foundation, not one account stretched past its limits.
Built a multi-account landing zone in CDK: service-control guardrails, KMS customer-managed encryption, and centralized logging. Then remediated an independent penetration test, including a fix for PHI that was reaching ALB access logs.
A defensible, HIPAA-mapped estate with the PHI-in-logs exposure closed and recovery proven, not assumed.