Client: A physician-owned cardiology practice moving its clinical IT onto Azure. As a HIPAA-covered entity handling ePHI, it needed a secure foundation built correctly from the start — not retrofitted later.
The challenge
This was a new tenant: no landing zone, no network, no governance, no guardrails. The practice was migrating patient-data systems — a leading ambulatory EHR and practice-management platform (including a FHIR interoperability server) on a SQL estate of about 27 databases — plus a Citrix virtual desktop environment for clinicians.
Everything a covered entity needs had to be created from nothing: encryption of ePHI at rest and in transit, network isolation for every data service, long-term backup retention, least-privilege access, and complete audit logging. And it had to be repeatable, auditable Infrastructure-as-Code, not hand-built in a portal.
What we did
We designed and built a seven-subscription Azure landing zone entirely in Terraform, backed by a private registry of 42 purpose-built, security-hardened modules. Connectivity, management, production, and virtual-desktop workloads sit in separate subscriptions, and every change passes plan/apply approval gates for a complete audit trail.
- Network: hub-and-spoke with a FortiGate next-generation firewall at the core. All spoke egress is forced through the firewall for inspection, DNS is centralized and private, and a single hardened Azure Bastion is the only administrative way in.
- Data isolation: every clinical PaaS service — Key Vault, Azure SQL, Log Analytics, Azure Backup — is reachable only over private endpoints. Workload subnets have no public IP addresses at all.
- Encryption: customer-managed, HSM-backed RSA-4096 keys on every managed disk, plus customer-managed-key Transparent Data Encryption for SQL. The practice holds its own keys.
- Governance: 24 Entra ID security groups bound to least-privilege, subscription-scoped roles, with separate security-operations, incident-response, auditor, and break-glass access.
- Resilience: a four-tier Azure Backup model with seven-year retention on patient-data workloads, mapped to HIPAA record-retention expectations.
Results
| Outcome | Result |
|---|---|
| Delivery model | 100% Infrastructure-as-Code; 42-module private registry; every change plan/apply-gated |
| Data-plane exposure | Zero — clinical PaaS is private-endpoint only; no public IPs on workload subnets |
| Encryption | HSM-backed RSA-4096 customer-managed keys on all disks, plus CMK TDE on SQL |
| Retention | 7-year backup on patient data; 365-day audit logs; 90-day network flow logs |
| Access control | 24 least-privilege role groups with break-glass separation |
The environment is compliant by construction. Patient data never crosses a public endpoint, administrative access runs through one audited chokepoint, the practice owns its encryption keys, and every part of the estate is versioned, reviewable, and reproducible.
The client's identity is anonymized. The environment, findings, and results are drawn from a real Hat Boy Software engagement; figures are representative and rounded.