Skip to content

Healthcare

Getting a telehealth platform ready for SOC 2 Type II and HIPAA

Hospital customers were asking for a SOC 2 report before signing. We closed the gaps, automated the evidence and put continuous monitoring in place ahead of the audit.

Client Project3 months
Client
Telehealth platform, 120 employees, United States
Industry
Healthcare
Region
United States
Duration
3 months
Team
6 engineers
  • Security and compliance
  • DevOps and CI/CD
  • Cloud infrastructure

Results

Security breaches in 18 months
0
Vulnerabilities remediated
98%
Fewer open vulnerabilities
95%
Monitoring and alerting
24/7

The challenge

Two hospital groups had paused contracts until the platform could show a SOC 2 Type II report and a HIPAA risk assessment. A penetration test had found over 300 open issues, engineers had standing admin access to production, and patient data was reachable from the office network.

The engineering team of 18 had to keep shipping features while this happened, so the work could not turn into a months-long freeze.

Before and after

How things ran when we started, and once the work shipped.

  • Before: Standing admin access to production
  • After: Short-lived access through SSO, fully logged
  • Before: 300+ open penetration test findings
  • After: Critical findings block the merge
  • Before: Evidence gathered in spreadsheets before audits
  • After: SOC 2 Type II report issued with no exceptions

Approach

How the work was done

4 phases over 3 months, with a working demo at the end of every week.

  1. 01

    Weeks 1–2

    Gap assessment

    Mapped existing controls against SOC 2 and the HIPAA Security Rule, triaged the penetration test findings and agreed a fix order with the CTO.

  2. 02

    Weeks 2–6

    Zero-trust access

    Removed standing admin access, moved production access behind SSO with short-lived credentials, and segmented networks so PHI is only reachable from approved workloads.

  3. 03

    Weeks 5–9

    Security in the pipeline

    Added dependency, container and infrastructure scanning to CI, with merges blocked on critical findings, and cleared the backlog of existing vulnerabilities.

  4. 04

    Weeks 9–12

    Monitoring and evidence

    Connected controls to Vanta for automatic evidence collection, set up 24/7 alerting on GuardDuty and audit logs, and ran an incident response tabletop with the leadership team.

Architecture

Access is granted per request and per workload, every change is scanned before it merges, and audit evidence is collected continuously instead of assembled before each audit.

  • Okta SSO with AWS IAM Identity Center and time-bound production access
  • Private subnets and VPC endpoints for every service handling PHI
  • Snyk, Trivy and Checkov checks in every pull request
  • GuardDuty, Security Hub and CloudTrail routed to a 24/7 on-call rotation
  • Vanta collecting control evidence from AWS, GitHub and Okta

Stack

  • AWS
  • Okta
  • Terraform
  • Snyk
  • Trivy
  • Checkov
  • GuardDuty
  • Vanta
“Both paused hospital contracts were signed within a month of the report. Our engineers barely slowed down while the controls went in.”
CTOTelehealth platform, United States

Have a project like this?

Tell us where things stand today. On a 30-minute call an engineer will sketch how we would approach it, the timeline and a price range.