Operating a US healthcare platform
Stack: Laravel · MySQL · AWS (RDS, EC2, CloudWatch) Client: a US healthcare rounds platform — name withheld under NDA
For healthcare software, the product is only as good as the infrastructure under it — so our engagement centers on operations, not just features.
What we own
- Zero-downtime database upgrades — planned and executed production MySQL major-version upgrades using Blue/Green deployments with full runbooks and tested rollback paths, completed ahead of vendor support deadlines.
- Security hardening for compliance — IAM least-privilege enforcement, network ACL remediation, and automated SSL certificate management in support of the client's compliance program.
- Monitoring and incident response — CloudWatch alarms, log pipelines, and hands-on resolution of production incidents from memory exhaustion to disk-pressure events.
From "it works" to audit-ready
When we took this platform on it already worked. What it did not yet have was the evidence an auditor and an enterprise buyer ask for: scoped IAM, closed network exposure, rehearsed database rollbacks, and alarms that reach a human. We closed every Drata finding on a live system serving clinical staff. The checklist we built doing it is the same one behind our Production-Readiness Audit and SOC 2 Remediation Sprint.
Why it matters
US healthcare buyers evaluating offshore partners worry most about reliability and auditability. This engagement is our answer: multi-year operation of a production healthcare system with a documented change-management discipline. We're happy to discuss the engagement in more depth under NDA, and can provide references on request with the client's consent.
(TODO: add a sanitized architecture diagram and, with written client permission, any metrics or an attributed quote.)

