A HIPAA-compliant, multi-region platform on Microsoft Azure
A critical patient-facing application needed a cloud home that was HIPAA compliant, highly available and recoverable in another region. We designed and built it on Azure with security in every layer.
What stood in the way
HIPAA compliance
A compliant environment for a highly critical application.
High availability and DR
99.9% availability with recovery across regions.
Layered security
Firewall, IDS/IPS, anti-malware and anti-virus.
Monitoring and logs
Log retention and continuous monitoring.
Redundant storage
Storage that survives zone and region failure.
Patch and capacity management
Kept current without downtime.
From diagnosis to design
What we found
- Active Directory: domain and additional domain controllers
- Web and SQL Always On database servers with HA
- Anti-malware, IDS/IPS, log inspection, file-integrity monitoring
- Premium storage, Application Gateway, Application Insights, Azure Backup, ASR
What we did
- Trend Micro security layer configured
- AD, application and database servers configured for HA
- Encryption on storage and disks
- Secure IPSec VPN; certificates on endpoints
- Anti-virus, IDS/IPS, firewall, NSGs and audit logs
How it is built
What the client gained
HIPAA-compliant solution
Encryption, audit logs, IDS/IPS and secure channels by design.
Highly available across regions
VPN-compliant, fault-tolerant and scalable at any time.
Disaster recovery
Machines recreated in region 2 from replicated storage.
Online monitoring
OMS and Application Insights across the estate.
Secure by topology
Layered design with WAF, NSGs and host-based protection.
Scalable anytime
Per-customer application pools on common infrastructure.
Technology

Tell us what you need to build, move or run.
An engineer reads every enquiry, not a sales script. We come back with an approach, a team and a plan you can hold us to.

