I will audit your AWS or server setup for hipaa compliance and security gaps
Clinical AI, HIPAA Compliant EMR EHR, Health Integrations, 9 Engineer Team
Level 2
Has met high performance criteria and has a proven track record for meeting client expectations.
About this Gig
Find out where you're exposed before a regulator or an enterprise client does.
"We think we're HIPAA compliant" is a bad place to be when a customer sends a 300-question security review.
WE REVIEW
Access control and RBAC · tenant isolation · encryption in transit and at rest · key management · authentication, MFA, password and session policy · audit logging and retention · PHI data flows · backup, restore and disaster recovery · BAA coverage · incident response readiness.
CLOUD DEPTH
We run production healthcare workloads on AWS and Windows Server. Expect specifics: VPC and subnet exposure, security groups, IAM least-privilege, GuardDuty and CloudTrail coverage, KMS rotation, S3 and RDS encryption.
WHAT YOU GET
A written report in plain language. Findings, risk-ranked, each with a specific fix. Not a checklist - a read on your actual system.
Also available: HECVAT and CAIQ-Lite questionnaires, customer-facing security overview, policy pack, Security Risk Assessment.
This is a technical assessment by healthcare engineers, not a legal opinion. For signed attestation you want a certified auditor.
Send me your stack. I'll tell you before you order if it's worth it.
Tools:
Docker
•
GitLab
•
Harness
•
Jenkins
•
GitHub
•
Kubernetes
•
Amazon EKS
Frameworks:
Npm
Programming language:
Bash
•
Java
•
JavaScript
•
Kotlin
•
Python
•
PowerShell
Expertise:
Debugging
•
Development
•
Configuration
Clients I’ve worked with
1stRx
1stRx needed GLP-1 patient intake off manual forms and into their clinical system without adding headcount. We built a custom workflow form portal that captures and validates structured intake, then pushes it straight into their EMR — no re-keying. Build, EMR integration and team onboarding. RBAC, audit logging, encrypted PHI. 1stRx was later acquired into a larger group.
Jan 2025
SuperVize
SuperVize tracked supervised hours, practicums and evaluations manually. We built a role-based platform for graduate schools, mental health agencies and umbrella organizations: real-time hours tracking, practicum applications, evaluations, secure messaging, document management. E-signature, 2FA, HIPAA and FERPA compliant.
Mar 2025
My Portfolio
Other DevOps Engineering Services I Offer
FAQ
Is this a penetration test?
No. A penetration test attempts to exploit your system from the outside. This is a configuration and controls review, we examine how the system is built and administered. The two find different problems, and most customer security reviews ask about both. If you need a pen test, engage a specialist
Will this make us HIPAA certified?
There is no such thing as HIPAA certification. No organisation can issue it. What exists is a documented Security Risk Assessment, implemented safeguards, and evidence you can show a customer or regulator. This review produces the technical half of that evidence.
Do you need access to our code and servers?
Read-only access gives a far more accurate result, but it isn't mandatory. We can review architecture documentation, configuration exports and completed questionnaires instead,and the report says plainly which findings are confirmed and which are inferred.
We run Windows Server, not AWS. Can you still help?
Yes. We operate healthcare workloads on both. Windows Server, IIS, SQL Server, patch currency, service exposure and certificate management are all in scope.
A customer sent us a security questionnaire. Can you complete it?
Yes, HECVAT, CAIQ-Lite and most bespoke vendor questionnaires. Usually the right order is: audit first so the answers are true, then complete the questionnaire. Answering optimistically and being caught is worse than answering honestly with a remediation date.
Can you fix what you find?
Yes, quoted separately once we both know the scope. Several findings are usually ongoing operational controls rather than one-time fixes, and those are better covered by a managed operations arrangement than a project.
What if you find something serious?
I'll tell you immediately rather than saving it for the report, and tell you what to do first.
Is our data safe with you?
We work under mutual NDA on request, and under a BAA where the engagement involves PHI access. We ask for read-only access wherever possible, and we don't need production PHI to do this review, synthetic or masked data is sufficient in almost every case.
Who does the work?
Engineers who build and operate HIPAA healthcare platforms daily, not generalist security consultants. That's why findings name specific settings rather than citing standards.

