Skip to main content
100%
Infrastructure-as-Code
42
security-hardened Terraform modules
0
public endpoints on clinical data services
7 yr
backup retention on patient data

Client: A physician-owned cardiology practice moving its clinical IT onto Azure. As a HIPAA-covered entity handling ePHI, it needed a secure foundation built correctly from the start — not retrofitted later.

The challenge

This was a new tenant: no landing zone, no network, no governance, no guardrails. The practice was migrating patient-data systems — a leading ambulatory EHR and practice-management platform (including a FHIR interoperability server) on a SQL estate of about 27 databases — plus a Citrix virtual desktop environment for clinicians.

Everything a covered entity needs had to be created from nothing: encryption of ePHI at rest and in transit, network isolation for every data service, long-term backup retention, least-privilege access, and complete audit logging. And it had to be repeatable, auditable Infrastructure-as-Code, not hand-built in a portal.

What we did

We designed and built a seven-subscription Azure landing zone entirely in Terraform, backed by a private registry of 42 purpose-built, security-hardened modules. Connectivity, management, production, and virtual-desktop workloads sit in separate subscriptions, and every change passes plan/apply approval gates for a complete audit trail.

  • Network: hub-and-spoke with a FortiGate next-generation firewall at the core. All spoke egress is forced through the firewall for inspection, DNS is centralized and private, and a single hardened Azure Bastion is the only administrative way in.
  • Data isolation: every clinical PaaS service — Key Vault, Azure SQL, Log Analytics, Azure Backup — is reachable only over private endpoints. Workload subnets have no public IP addresses at all.
  • Encryption: customer-managed, HSM-backed RSA-4096 keys on every managed disk, plus customer-managed-key Transparent Data Encryption for SQL. The practice holds its own keys.
  • Governance: 24 Entra ID security groups bound to least-privilege, subscription-scoped roles, with separate security-operations, incident-response, auditor, and break-glass access.
  • Resilience: a four-tier Azure Backup model with seven-year retention on patient-data workloads, mapped to HIPAA record-retention expectations.

Results

OutcomeResult
Delivery model100% Infrastructure-as-Code; 42-module private registry; every change plan/apply-gated
Data-plane exposureZero — clinical PaaS is private-endpoint only; no public IPs on workload subnets
EncryptionHSM-backed RSA-4096 customer-managed keys on all disks, plus CMK TDE on SQL
Retention7-year backup on patient data; 365-day audit logs; 90-day network flow logs
Access control24 least-privilege role groups with break-glass separation

The environment is compliant by construction. Patient data never crosses a public endpoint, administrative access runs through one audited chokepoint, the practice owns its encryption keys, and every part of the estate is versioned, reviewable, and reproducible.

The client's identity is anonymized. The environment, findings, and results are drawn from a real Hat Boy Software engagement; figures are representative and rounded.

More case studies

Not sure where to start? Start with an assessment.

A senior review of your app, cloud estate, or AI platform, scoped and quoted before work starts, that ends in a prioritized plan, so you decide what to fix and when.

Talk to an engineer