For healthcare teams on AWS

Build the AWS foundation your healthcare customer expects.

Deploy a HIPAA-aligned AWS foundation into your own account: versioned, validated, documented. Your engineers stay on the product.

No AWS credentials or patient data needed to get started.

Built with OpenTofuDeployed in your accountOwned by you
WHAT SITS UNDER YOUR HEALTHCARE WORKLOAD
Seven security layers: PHI, Data Security, Scanning and Logs, Access Controls, System Controls, HIPAA Boundary - Network, and Physical.
Your AWS account. Your infrastructure.

A defined scope. A documented handoff.

Xperlock configures the agreed AWS foundation. AWS secures its facilities; your team owns application and data safeguards.

HIPAA-aligned AWS
environments delivered for

By Xpertech, the team behind Xperlock.

UC San Diego HealthUCI HealthZentalis
Choose your scope

Two scopes.
One standard.

Start with one AWS account or establish governance across your organization. Choose the scope that fits your team.

Xperlock LiteSingle account

Your first regulated workload. One AWS account.

For small teams standing up a new, dedicated AWS account.

  • Segmented networking and controlled access
  • Encryption, audit logging and security services
  • A versioned OpenTofu foundation in your account
  • Implementation evidence and a clear handoff

Not included in Lite: application compute, databases, and workload migration. Those are scoped separately.

Xperlock EnterpriseMultiple accounts

Multiple accounts.
Consistent governance.

For teams coordinating security across separate environments.

  • Governance with AWS Organizations and Control Tower
  • Isolation for production, development and shared services
  • Centralized logging and scoped network inspection
  • Organization policies and implementation evidence

Both plans support hosted state and drift detection through Xperlock Workspace.

The blocker

Infrastructure delays become revenue delays.

Your launch is ready. Someone is asking how you protect data, control access and prove what is configured: a customer, an auditor, or your board.

That work competes with the features your customers are waiting for.

Build in-house
  1. Assign engineers
  2. Design controls
  3. Implement & test
  4. Assemble evidence
With Xperlock
  1. Agree the scope
  2. Approve the plan
  3. Deploy baseline
  4. Receive evidence

The decision is how much of your team's time that work should take.

Buy vs build

Put engineering time
into your product.

See what a comparable in-house build could take—and where an engineered baseline can help.

A comparable in-house build
SINGLE-ACCOUNT SCOPE

US$25k–$50k

Illustrative labor budget

2–3 monthsCalendar time
2–3 person-monthsDevOps-led work + review

One lead engineer builds the baseline, with architecture and security review.

MULTI-ACCOUNT SCOPE

US$120k–$160k

Illustrative labor budget

4–6 monthsCalendar time
8–10 person-monthsCombined engineering effort

Infrastructure, architecture and security specialists work across parallel workstreams.

What goes into these estimates?

Illustrative US salaries and benefits over the stated engineering effort. Not measured client project costs. AWS usage, software, recruitment and ongoing operations are excluded.

Actual effort depends on account readiness, integrations, control scope and review requirements.

With Xperlock

Start with the baseline
already engineered.

Configure, review, deploy and validate a reusable OpenTofu baseline, within a defined scope.

Illustrative savings scenario60–80% lower implementation cost

Assumes Xperlock plus retained internal work totals 20–40% of the equivalent in-house budget. Your quote establishes the actual comparison; this is not a measured result or guarantee.

Automated deployment after approval

Account preparation, AWS provisioning, integration and validation still take time. Your quote defines the delivery schedule.

Lite is a fixed-price scope of four to six weeks. Enterprise is quoted against your account structure.

See what is included
How it works

A clear plan.
A controlled deployment.

From your requirements to evidence you can use, with a decision point before anything is deployed.

  1. 01

    Assess the fit

    Review your workload and requirements. Choose Lite or Enterprise and agree what is included.

    Your agreed scope
  2. 02

    Review & approve

    Review the OpenTofu plan, permissions and estimated AWS running costs after readiness checks.

    Your approved plan
  3. 03

    Deploy in your account

    Apply the approved foundation using scoped, temporary access. You own the AWS resources.

    Your AWS baseline
  4. 04

    Validate & hand over

    Receive your inventory, implementation report and responsibility checklist. Choose handoff or ongoing support.

    Your implementation evidence

Know what will change before it changes.

What's deployed

What gets deployed
into your account.

Coordinated controls in your AWS environment, with a record of what was implemented.

01Identity & access

Scoped roles and least-privilege policies help your team control who can do what.

02Network boundaries

Segmented networks and defined traffic paths. Enterprise adds account governance and scoped centralized inspection.

03Encryption

Key management and encryption settings for the resources in your agreed scope.

04Logging & detection

Audit trails, configuration records and enabled AWS security services help you investigate changes.

05Backup and recovery

Backup and retention configuration for agreed resources, with recovery responsibilities documented.

06Implementation evidence

A resource inventory, configuration checks and an action list give your team a clear handoff.

YOUR AWS ACCOUNTBuilt with OpenTofu
Your application & dataYour team's responsibility
Identity & access
Network boundaries
Encryption
Logging & detection
Backup and recovery
Implementation evidence & handoff

The deliverable is infrastructure in your account, with versioned configuration and documented responsibilities.

Where your responsibility starts.

Your applications, data handling, policies, agreements and operations also need safeguards.

Delivered work

Built on healthcare
delivery experience.

Real AWS engagements by Xpertech, the team behind Xperlock.

Xperlock is the productized version of this work. Same team, same standards, delivered as a defined scope.

Bring experienced infrastructure thinking to your next launch.

Xperlock Workspace

Keep your environment
current as you grow.

Deployment is a starting point. Continue with hosted state, drift detection and a supported update workflow.

  • Hosted state

    Retained infrastructure state and version history.

  • Continuous drift detection

    Recurring automated checks highlight changes from the managed baseline.

  • Reviewed updates

    See proposed changes before they are applied.

YOUR BASELINE LIFECYCLE
  1. 01
    Versioned baseline

    Configuration + hosted state

  2. 02
    Recurring drift checks

    Compare the managed configuration

  3. 03
    Review proposed changes

    Your approval before updates

  4. 04
    Update & record

    Baseline versions and deployment history

Prefer to manage it yourself? Choose a defined handoff of state, configuration and documentation.

FAQ

The questions
people ask first.

Start with the right scope and a clear understanding of who owns what.

Which plan fits us?

Lite fits a new, dedicated AWS account for a regulated workload. Enterprise fits multiple environments with shared governance. The free assessment helps you choose.

Who owns the environment?

You own the AWS resources. Xperlock uses scoped access to implement the agreed foundation. Your handoff defines how access and state custody end.

Does this make us HIPAA compliant?

The foundation is one part of your program. Your organization remains responsible for its applications, data handling, administrative safeguards and ongoing operations.

What happens when our environment changes?

Workspace checks the managed baseline for drift. Corrections follow a reviewed change process; they are not silently applied. You can also choose a documented handoff to your team.

Your next step

Move your next healthcare
deal forward.

Start with a free assessment of your workload, data and environment needs. Leave with a clearer view of the next steps.

Let's scope your environment

Book Free Assessment

Share your contact details first. The assessment opens in a new tab after intake is accepted.

Online requests are coming soon. You can prepare your details below and contact us by email. Nothing is sent from this page.

Please keep patient data, credentials and other sensitive information out of this form.

Open your email app →