PROJECT-04 / Healthcare security engineering

HIPAA/HITRUST-Aligned Healthcare Security Engineering Platform

In-progress HIPAA/HITRUST-aligned security engineering for a synthetic healthcare workload.

State
In Progress
Platform
AWS / Google Cloud

01 /Security Objective

Implement security controls for a synthetic healthcare workload aligned to selected HIPAA and HITRUST control objectives.

Category: Healthcare security engineering

02 /Architecture Overview

AWS is the primary implementation platform; Google Cloud is scoped for control-equivalent objectives.

Platform scope

  • AWS
  • Google Cloud

CONTROL /Controls in Scope

  • Network segmentation
  • Least privilege
  • VPC Flow Logs
  • CloudWatch

03 /Implementation Record

Terraform-managed network segmentation, security groups, VPC Flow Logs, CloudWatch logging, and least-privilege IAM work.

Delivery
Terraform with AWS CLI and console validation

04 /Validation Record

Validation method
AWS CLI and console validation with controlled failures, investigation, remediation, revalidation, teardown, and evidence records.
Evidence record
Validation, remediation, and teardown records

WORKFLOW /Engineering Lifecycle

  1. 01Design
  2. 02Implement
  3. 03Deploy
  4. 04Validate
  5. 05Inject controlled failure
  6. 06Investigate
  7. 07Remediate
  8. 08Revalidate
  9. 09Destroy
  10. 10Document evidence

05 /Current State & Limitations

In Progress

This is a technical engineering exercise using synthetic healthcare data. It is not a compliance claim, certification, attestation, or production healthcare system.

View Source Repository