• Client
    Agilis Dental
  • Sector
    Multi-tenant dental SaaS
  • Platform
    Microsoft Azure
  • Delivered as
    Terraform, dev and prod, plus a handover pack
  • 14Terraform modules, from network to Sentinel
  • 7 + 6security alert rules, plus Sentinel analytics rules
  • 12handover documents for the client’s team

The challenge

What had to be true

A dental platform holds protected health information: records, appointments and the people behind them, across a portal and companion apps. The environment had to keep that data off the public internet, make every access attributable, and give the team a way to see and respond to threats.

It also had to be reproducible and something the client’s own team could run after we stepped back, so it was built entirely as code, and the operational knowledge was part of the deliverable rather than an afterthought.

The work

What we built

  • One protected way inAzure Front Door with a WAF policy (Microsoft’s default rule set 2.1 and bot-manager rules) in front of everything. The backend App Services accept traffic only from Front Door, deployment endpoint included.
  • Data services off the public internetCosmos DB, Storage and Key Vault reached over private endpoints with private DNS; App Service joined to the virtual network; network security groups on every subnet.
  • Identity instead of keysManaged identities for service-to-service access. Storage account keys are switched off entirely, Key Vault uses RBAC with soft delete and purge protection, and app settings read secrets through Key Vault references.
  • Guardrails as policyThe HIPAA/HITRUST initiative assigned through Azure Policy, plus custom policies that enforce private endpoints, storage encryption and diagnostic settings.
  • Detection and responseDiagnostics from every resource into Log Analytics and Application Insights, seven alert rules, and Microsoft Sentinel with Entra ID and Defender for Cloud connectors and six HIPAA analytics rules.
  • A way to operate itAzure Bastion with a jump VM that shuts itself down, so there is no public RDP; and a handover pack covering deployment, hardening and verification, backups, incident response and the Sentinel workflow.

Security

How the data is protected

  • Front Door WAF with OWASP and bot protection; backends reachable only through it
  • Private endpoints for Cosmos DB, Storage and Key Vault
  • Storage account keys disabled; access by managed identity and RBAC only
  • TLS 1.2 minimum, with infrastructure encryption on storage enforced by policy
  • Alerts on Key Vault auth failures, policy violations, WAF blocks, unusual data access and denied traffic
  • Cosmos DB automatic failover in production, with point-in-time backup available

HIPAA has no certification body. We implement the technical safeguards and the evidence behind them; the compliance programme itself remains the covered entity’s.

I recommend Deecoding for the HIPAA-aligned Azure implementation they delivered for our dental platform: they designed and deployed a production-ready security architecture with private networking, encryption, access controls, monitoring, and Microsoft Sentinel, together with the operational documentation we need to run the environment securely.

Fadi RiachiFounder & CEO, Agilis Dental

Stack

What it runs on

  • Terraform
  • Azure Front Door + WAF
  • Azure App Service
  • Azure Static Web Apps
  • Cosmos DB for MongoDB
  • Blob Storage
  • Azure Key Vault
  • Private Endpoints
  • Virtual Network & NSGs
  • Log Analytics
  • Application Insights
  • Microsoft Sentinel
  • Azure Policy
  • Azure Bastion

Running patient data on Azure?

Tell us what you are building. We will come back with what we would need to know, a rough shape for the work, and whether we are the right people for it.

Let’s talk