Forty-one roles that could reach patient data. Three should have.
Nobody had built a privileged path deliberately. Six years of small, reasonable IAM decisions had built eleven of them.
- client
- A clinical records provider
- sector
- Healthcare
- service
- Cloud security review
- duration
- 18 working days
The provider held records for eleven million patients across two AWS organisations that had been merged after an acquisition and never reconciled.
Healthcare
Built a complete identity graph across both organisations, including cross-account trust.
Traced every reachable path from a compromised developer laptop to the patient data store.
Raised infrastructure fixes as pull requests against their Terraform, not as findings in a PDF.
Wrote the guardrail policy set that now blocks the pattern at deploy time.
| ref | finding | severity |
|---|---|---|
| DW-2507-01 | Cross-account role assumable by any principal in acquired organisation | critical |
| DW-2507-03 | CI runner role able to modify its own trust policy | critical |
| DW-2507-08 | Patient data bucket readable by eleven unrelated service roles | high |
| DW-2507-14 | No expiry on federated session duration | medium |
Standing access to patient data fell from forty-one roles to three, all of which now require just-in-time elevation with a named approver.
They sent pull requests instead of a spreadsheet. Our team merged most of them the same week.
tell us what you would least like us to reach
Scoping is a conversation with the people who own the systems, not a form. Twenty minutes is usually enough to tell whether we are the right practice for the problem.
