How Halcyon Health passed its security review with private networking
A healthcare scheduling company moved patient data services onto a private network and cut its audit preparation from weeks to days.
Results
A smaller surface to defend
- Audit preparation
- days
- Down from three weeks of evidence gathering.
- Public databases
- 0
- Every data store is reachable only on the private network.
- Services moved
- Scheduling, reminders, and billing.
The challenge
Halcyon Health runs appointment scheduling for clinics, so its services handle patient names, contact details, and visit history. Each annual security review meant weeks of collecting firewall rules and screenshots to prove which services could reach which databases.
Several internal services still had public endpoints, protected only by IP allow lists that nobody wanted to touch.
The solution
The team moved its 22 services onto a private network and removed the public endpoints from everything except the patient-facing web service. Access rules live in the same config file as the services, so every change goes through code review.
Preview environments run on their own isolated networks with synthetic data, so testing never touches real patient records.
The results
The next security review took three days. Auditors read the network rules straight from the repository history, and no database is reachable from the public internet.
“Our auditors asked which services could reach patient data. For the first time, the answer was one config file instead of a week of screenshots.”