Back to all work Case Study · Production Verified

Healthcare Zero-Trust Cloud Baseline

Comprehensive security re-architecture across 6 Microsoft Azure enterprise subscriptions: Private Endpoints, Azure Policy-as-code, Privileged Identity Management (PIM), and automated HIPAA / SOC 2 compliance guardrails.

Client Industry HealthTech / HIPAA
Duration 7 Weeks
Role Principal Cloud Security Architect
Primary Stack Azure · Bicep · Sentinel · PIM
100%
SOC 2 Type II audit pass
0
Public IP exposures on databases
100%
Azure Policy automated compliance
< 4 min
PIM just-in-time access approval
Doctor reviewing patient records on a digital tablet in a hospital corridor
Zero-Trust Architecture Flow
Microsoft Entra ID Conditional Access & MFA
→
PIM Approval Time-Bound Just-in-Time Access
→
Azure Private Link Zero Public Endpoints
→
Microsoft Sentinel SIEM Continuous Monitoring

The Challenge

The organisation stores protected health information (PHI) for 1.8M patients. Prior to the project, teams lacked centralised identity governance, storage accounts were partially exposed to the internet, and an upcoming SOC 2 Type II audit risked failure.

The Architectural Solution

Milestone 1

Zero Public Ingress Network Topology

Isolated all data storage, databases, and container registries behind Azure Private Endpoints inside dedicated VNets. Eliminated all direct public internet gateways.

Milestone 2

Bicep Management Groups & Azure Policy

Defined 48 automated Azure Policies enforced at the Root Management Group level to prevent any engineer from provisioning unencrypted disks or public IPs.

Milestone 3

Audit & Incident Automation

Connected Microsoft Sentinel with automated playbooks to quarantine anomalous logins and send real-time Slack alerts to the SecOps team.

“Ryan transformed our security posture from a chaotic anxiety point into our proudest enterprise sales asset. We sailed through our audit with zero non-conformities.”

Marcus Vance — Chief Information Security Officer, HealthVitals