AWS Security · HIPAA · AI Agents

Your healthtech app handles PHI. One misconfigured bucket away from a breach notification.

We make that problem disappear on AWS.

For digital-health startups, telehealth, and healthtech SaaS that handle PHI.

AWS Community Builder · Security AWS Certified Security · Specialty (SCS-C03) AWS Certified Solutions Architect (SAA-C03)
Frameworks we build to
HIPAA HITRUST SOC 2 NIST AWS Well-Architected
Approach

From zero to audit-ready on AWS.

You want one thing: to walk into a HIPAA or security audit on AWS and pass, with no surprises waiting in your configuration. That is the job. We take a healthtech estate from wherever it is today to a defensible, evidence-backed posture you can prove to an assessor.

The arc is always the same: foundation, then hardening, then continuous monitoring.

The full menu (landing zone, posture assessment, HITRUST readiness, Bedrock AI agents, Well-Architected review, continuous monitoring) is scoped into a plan after the first call, not sold as a checklist here.

Proof

Evidence, not adjectives.

Two engagements from real client work, anonymized by agreement. Every claim below is drawn from a documented deliverable: no invented metrics, no names, no borrowed logos.

Anchor engagement
US healthtech · Analytics on PHI

End-to-end HIPAA-grade AWS, hardened through a third-party pen test.

Context

A US healthtech running analytics over protected health information needed an audit-ready AWS foundation, not one account stretched past its limits.

What we did

Built a multi-account landing zone in CDK: service-control guardrails, KMS customer-managed encryption, and centralized logging. Then remediated an independent penetration test, including a fix for PHI that was reaching ALB access logs.

Outcome

A defensible, HIPAA-mapped estate with the PHI-in-logs exposure closed and recovery proven, not assumed.

OrganizationsSCPsKMSCloudTrailCDK
~7 min
Disaster-recovery restore, demoed end to end.
Incident response
911 voice platform · Non-healthcare

Evicting a miner and a backdoor from production.

Inherited a production server compromised under a prior contractor. We identified a crypto-miner and a backdoor, rotated every credential, and rebuilt the environment to a clean, trusted baseline.

EC2IAMKey rotationIncident response

Engagements are anonymized by agreement: client names, logos, and identifying detail are withheld. References can be arranged for qualified prospects.

Shared responsibility, handled

We architect, configure, and operate the controls that live in your half of the AWS shared responsibility model, and document who owns what.

HIPAA-eligible under your AWS BAA

Workloads run on HIPAA-eligible services covered by your AWS Business Associate Addendum, with the BAA handled as part of onboarding.

Mapped to NIST and HITRUST

Controls map to NIST and HITRUST so the same engineering work produces the audit evidence assessors expect. AI agents on Bedrock store no client PHI and keep no retention.

Contact

Let's close the gap before an auditor finds it.

Tell us where you are on AWS or HIPAA and you will get clear next steps. Or book a 30-minute consultation.