Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Customer Story
Linus Health closed a $55 Million Series B investment to grow its team and accelerate the development of its platform. As part of these plans, Linus Health engaged RKON to build a hardened cloud environment to support the next-generation platform and launch a HIPAA-based security program for ongoing management and increased security and privacy protection.
Linus Health
$28M revenue
Healthcare
HIPAA-Based Cloud Security
The Challenge
Implement a comprehensive, HIPAA-based cloud security solution, including the launch of a security and compliance management program, cloud platform preparation, and development of a hardened configuration baseline for cloud workloads.
Linus Health closed a $55 Million Series B investment to grow its team and accelerate the development of its platform. As part of these plans, Linus Health engaged RKON to build a hardened cloud environment to support the next-generation platform and launch a HIPAA-based security program for ongoing management and increased security and privacy protection.
Our Solution
The security management program launch included selecting a security control framework, drafting policy templates to support the framework, and documenting responses for security controls.
The team adopted controls from NIST 800-66 and tailored them to suit a commercial organization. NIST 800-66 provides prescriptive guidance and controls for the HIPAA Security Rule. All controls were mapped to SOC 2 criteria to support future competitive compliance endeavors.
The team launched a new AWS Organization using AWS Control Tower to create a landing zone for all AWS accounts. Guardrail policies were configured to ensure adherence to company policy. The new AWS Organization was designed by tailoring recommendations from the AWS Security Reference Architecture, including setting up centrally managed security capabilities like logging collection, monitoring, and identity management.
Linus Health uses AWS Config to manage inventory, AWS Security Hub to manage security findings, and threat detection provided by AWS GuardDuty. Further, the team configured AWS CloudTrail for activity logging, VPC Flow Logs for network activity, and IAM Access Analyzer to manage externally exposed resources.
Protecting workloads and customer data is a critical step to setting up a security program. Accordingly, the companies collaborated on a detailed data flow diagram to understand system boundaries, use cases, user personas, and data types to be protected.
To further accelerate innovation the team used HashiCorp Terraform to create templates for common patterns used by the company’s developers and data scientists. All infrastructure as code (IaC) configurations were hardened to the NIST 800-66 controls for the HIPAA Security Rule.
While the project was underway and meeting milestones, Linus Health hired new employees and added them to the team. Because RKON used best practices and industry standards easily recognizable by each new hire, the onboarding process was straightforward and made onboarding easier.
With a five-week investment, the Linus Health team now has an extensible, scalable security program. They can now proceed with increased focus on their core mission to build and extend their platform to help improve brain and mental health outcomes for people everywhere.
Key design decisions that helped Linus Health maintain momentum include:
Adopt proven frameworks, standards, and controls. Creating custom controls is time-consuming and largely unnecessary compared to selecting and tailoring existing controls.
Use managed cloud services for system components that do not require extensive customization, like message brokers.
Start with a modest scope and depth for compliance and security capabilities. Expand and improve over time.
Accelerate HIPAA compliance by configuring and hardening HIPAA compliant cloud services.
"We are very happy without decision to engage with RKON. They were easy to work with, and allowed our leadership to focus on our strategic quest to enable precision brain health for all patients living with dementia."
- John Langton, CTO at Linus Health
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Cyber Risk Is Continuously Evolving. Your Security Validation Strategy Should Keep Pace. Many organizations view penetra...
Why Validating Your Defenses Is Just as Important as Investing in Them Organizations continue to invest heavily in cyber...
The System Security Plan is dead. FedRAMP’s Consolidated Rules for 2026 (CR26), published June 24, retired the document ...