Lift, Re-Platform, and Optimize for a Healthcare Data Provider
A mid-market healthcare analytics company under HIPAA and SOC 2
Healthcare / Health data analytics
11 months · 5 Sentrize engineers (1 lead, 2 cloud engineers, 1 security engineer, 1 SRE)
AWS, Terraform, Docker, Kubernetes, PostgreSQL, Redis, Prometheus, Grafana
Zero-downtime migration
Infrastructure cost
SOC 2 Type II
The challenge
The client's analytics platform processed protected health information for hospital systems and payers from a managed data centre whose contract, hardware, and operating assumptions were all reaching end of life. Renewal meant re-investing in an environment the team no longer wanted; migration meant moving a HIPAA-regulated workload that customers query around the clock.
Three constraints framed the engagement. First, downtime was effectively off the table — clinical and payer customers rely on the platform continuously, and contractual SLAs left no room for a "migration weekend." Second, compliance posture had to improve, not merely survive the move: a SOC 2 Type II audit was scheduled, and the existing environment's controls were maintained by hand and evidenced by screenshots. Third, cost needed to come down. The data-centre footprint was sized for a peak that occurred a few days per month, and finance was carrying that peak every day.
Previous internal attempts had stalled at the planning stage because every big-bang cutover design concentrated too much risk in a single event. The client engaged Sentrize to find a path that spread that risk instead.
The solution
We ran a phased strangler-pattern migration to AWS, shifting traffic per service behind a routing layer with per-service rollback. All infrastructure was Terraform-defined with encryption by default and audit logging mapped to SOC 2 controls.
The engagement began with a four-week discovery: a full inventory of services, data flows, and PHI touchpoints, producing a dependency graph that dictated migration order. Stateless services moved first, then read paths, then systems of record — each behind a routing layer that could shift traffic to AWS in percentages and shift it back in seconds if error rates or latency regressed. Every service had its own rollback plan; no cutover depended on another succeeding on the same day.
Rather than lift the old environment's habits along with its workloads, we rebuilt the foundations as code. Every environment — network topology, IAM, compute, data stores — is defined in Terraform, with encryption at rest and in transit as the default and no path to provision an unencrypted resource. Containerized services run on Kubernetes; PostgreSQL and Redis moved to managed equivalents with automated backup and tested restore procedures.
Compliance was engineered in parallel, not appended afterwards. Audit logging, access review, and change management were mapped to SOC 2 criteria from the start, so control evidence is generated by the platform itself rather than assembled manually before an audit. Sentrize's own ISO 27001 and SOC 2 Type II certified practices, and HIPAA-ready engineering controls, set the baseline for how PHI was handled throughout the engagement.
The final phase was optimization: right-sizing instances against observed load, autoscaling the analytics tier to its actual demand curve, and moving predictable baseline capacity onto committed pricing.
The results
The migration completed in 9 months with zero downtime — traffic shifted service by service, and no customer-facing outage or maintenance window was ever required. Several cutovers happened during business hours, deliberately, because the routing layer made them non-events.
Infrastructure cost fell 38% against the data-centre baseline, driven by autoscaling to real demand instead of provisioned peak, right-sizing, and committed-use pricing on the steady-state floor. The scheduled SOC 2 Type II audit completed with 0 findings, with the auditors working largely from evidence the platform generates automatically. As secondary outcomes, disaster-recovery restore was reduced from an untested runbook to a rehearsed procedure measured in hours, and new environments — previously a hardware ticket — are now provisioned from Terraform in under a day.
"They moved our entire platform under us and our customers never felt a thing."
— Marcus Lindqvist, VP of Infrastructure
---
Related: Cloud Migration · AWS Consulting · Security & Compliance · All case studies
Cloud Migration · AWS Consulting · Security & Compliance · All case studies
