I will audit your AWS or server setup for hipaa compliance and security gaps

United States

I speak English

34 orders completed

Clinical AI, HIPAA Compliant EMR EHR, Health Integrations, 9 Engineer Team

11 years in healthcare software. Three years ago I built the team I wished I'd had. Trilops - nine engineers. We build HIPAA-compliant EMR/EHR platforms, telehealth, patient portals, medical billing,...

Level 2

Has met high performance criteria and has a proven track record for meeting client expectations.

About this Gig

Find out where you're exposed before a regulator or an enterprise client does.


"We think we're HIPAA compliant" is a bad place to be when a customer sends a 300-question security review.


WE REVIEW

Access control and RBAC · tenant isolation · encryption in transit and at rest · key management · authentication, MFA, password and session policy · audit logging and retention · PHI data flows · backup, restore and disaster recovery · BAA coverage · incident response readiness.


CLOUD DEPTH

We run production healthcare workloads on AWS and Windows Server. Expect specifics: VPC and subnet exposure, security groups, IAM least-privilege, GuardDuty and CloudTrail coverage, KMS rotation, S3 and RDS encryption.


WHAT YOU GET

A written report in plain language. Findings, risk-ranked, each with a specific fix. Not a checklist - a read on your actual system.


Also available: HECVAT and CAIQ-Lite questionnaires, customer-facing security overview, policy pack, Security Risk Assessment.


This is a technical assessment by healthcare engineers, not a legal opinion. For signed attestation you want a certified auditor.


Send me your stack. I'll tell you before you order if it's worth it.


Tools:

Docker

GitLab

Harness

Jenkins

GitHub

Kubernetes

Amazon EKS

Frameworks:

Npm

Cloud Provider:

Amazon Web Services

Microsoft Azure

Programming language:

Bash

Java

JavaScript

Kotlin

Python

PowerShell

Expertise:

Debugging

Development

Configuration

Clients I’ve worked with
1stRx

1stRx

1stRx needed GLP-1 patient intake off manual forms and into their clinical system without adding headcount. We built a custom workflow form portal that captures and validates structured intake, then pushes it straight into their EMR — no re-keying. Build, EMR integration and team onboarding. RBAC, audit logging, encrypted PHI. 1stRx was later acquired into a larger group.

Jan 2025

SuperVize

SuperVize

SuperVize tracked supervised hours, practicums and evaluations manually. We built a role-based platform for graduate schools, mental health agencies and umbrella organizations: real-time hours tracking, practicum applications, evaluations, secure messaging, document management. E-signature, 2FA, HIPAA and FERPA compliant.

Mar 2025

My Portfolio

Other DevOps Engineering Services I Offer