Healthcare Technology
HIPAA-ready access without bastion hosts
Arclight Health replaced shared jump boxes with identity-based, time-limited access to clinical databases and Kubernetes clusters — passing HIPAA review on the first attempt.
6
bastion hosts eliminated
15 min
production access grant time
100%
connections tied to verified identity
Challenge
Arclight Health operates a telehealth platform with PHI stored across Postgres clusters, Redis caches, and EKS workloads in two regions. Engineers reached production through shared bastion hosts with long-lived SSH keys that rotated quarterly at best. Access reviews were manual spreadsheets, and the compliance team had no way to prove who touched patient data during an incident investigation.
Solution
Kimox integrated with Arclight's Okta tenant to provision just-in-time SSH and database access. Engineers request production access through an approval workflow; credentials expire automatically when the session ends. Session audit logs capture every connection event, and optional session recording satisfies the strictest interpretation of HIPAA access controls.
Results
Arclight retired all six bastion hosts within a month. Mean time to grant production access dropped from 48 hours to under 15 minutes for pre-approved on-call engineers. The platform passed its HIPAA technical safeguard review with audit trails that mapped every database connection to a verified identity.
“Our compliance team used to dread access reviews. Now they pull a Kimox report and they're done in an afternoon.”
More customer stories
Six cloud accounts connected in three days
Nexaform unified AWS, GCP, and Azure workloads into a single encrypted mesh — replacing a patchwork of site-to-site VPNs and months-long networking projects.
Global post-production on one flat network
Voxel Stream linked remote editors, render farms, and review suites across four continents — without shipping hardware VPN boxes to every studio.
Factory floors and cloud control planes, unified
Helix Dynamics connected edge robotics controllers, on-prem PLCs, and cloud orchestration into one zero-trust mesh — no inbound firewall ports required.
Ready to simplify your network?
Start free with up to 3 users. Scale when your team does.
Get started free