Susheel Thapa
Skip to content
>_ST
AWSAuth0DockerPythonFHIRZero-Trust

AWS Zero-Trust Healthcare Microservices & Auth0 IAM

HIPAA-oriented cloud architecture implementing Auth0 fine-grained RBAC, private API gateway endpoints, and automated audit trails for healthcare workloads.

AWS Zero-Trust Healthcare Microservices Architecture

An enterprise cloud deployment engineered to satisfy strict HIPAA and SOC 2 Type II compliance constraints. The system isolates sensitive Electronic Health Record (EHR) data behind private VPC endpoints while federating authentication through Auth0.

Architecture Topology

    flowchart TD
  Client[Web & Mobile Clients]
  Auth0[Auth0 Identity Platform]
  
  subgraph AWS ["AWS Cloud (VPC Isolated)"]
      APIGW[API Gateway (Private VPC Link)]
      subgraph Compute ["ECS Fargate Cluster"]
          AuthService[Auth Verification Service]
          FHIRProxy[FHIR Proxy Service]
      end
      subgraph Storage ["Encrypted Data Plane"]
          Aidbox[(FHIR / Aidbox Store)]
          KMS[AWS KMS Customer Managed Keys]
      end
  end

  Client -->|1. Authenticate with MFA| Auth0
  Auth0 -->|2. Issue Scoped JWT| Client
  Client -->|3. HTTPS Request with Bearer Token| APIGW
  APIGW --> AuthService
  AuthService -->|4. Validate Claims & Permissions| FHIRProxy
  FHIRProxy -->|5. TLS mTLS Encrypted Query| Aidbox
  Aidbox -.-> KMS
  

Technical Highlights

  • Role-Based Access Control (RBAC): Auth0 Custom Actions validating user organizational membership and assigning patient-level scopes (patient/*.read).
  • Encrypted Storage: PostgreSQL RDS database with KMS customer-managed key encryption and automatic rotation.
  • Audit Logging: Structured JSON logging streaming into AWS CloudWatch with automated alerting for unauthorized access attempts (403 Forbidden).