👋 Welcome back, Dr. Chen Here's your clinic today
CLINIC OPEN 🌸 Spring Schedule
🏥 5 stationsROUND CLINIC
6STAFF ON DUTY
247PATIENTS
1,247/sEVENTS
24CAMERAS
156SENSORS
0SELECTED
▌ CARE TEAM COGNITO
▌ CLINIC FLOOR PLAN ◉ 5 STATIONS • IOT CORE
💙
CARE HUB
247 patients • 6 staff
🛎️
Reception
12 waiting
12
🩺
Exam
4 / 4 busy
🔬
Lab
2 active
💊
Pharmacy
2 pending
2
📹
Telehealth
3 sessions
📋
Admin
5 tasks
▌ TODAY'S ACTIVITY ◉ EVENTBRIDGE
MEDCLOUD · A WELCOMING CLINIC EXPERIENCE • HIPAA-COMPLIANT • 40+ OPERATIONS

☁️ INFRASTRUCTURE MAP

▸ Infrastructure, Not a Product

Every button in this demo maps to a real AWS architectural pattern. The UI is the demo. The infrastructure is what we sell.

How to Read This

  • Click anything — a station, a patient dot, a staff member, a command.
  • Primary popup shows the task state and live feed.
  • Process popup (right side) shows the AWS pipeline, service tags, and implementation code.
  • Every service tag (AWS, EventBridge, IoT, Kinesis) is what actually runs.

What You're Looking At

  • Round 5-station clinic — 247 patients, 8 staff, 24 cameras, 156 IoT sensors
  • 40+ operations — appointments, records, prescriptions, lab results, billing, inventory, telehealth, compliance
  • Live event stream — 1,247 events/sec through EventBridge
  • Immutable audit — every action writes to a ledger that cannot be modified, even by root

▸ AWS Services in This Build

Compute

Lambda 18 functions — appointments, patient records, prescriptions, lab results, billing, inventory, telehealth, compliance, audit writer, alarm fanout, MFA verifier, WAF health, drift detector, cost monitor

Fargate Billing processor (3 tasks in prod), insurance claim generator, report generator

Data

DynamoDB patients, appointments, prescriptions, lab_results, audit_ledger, staff — on-demand billing, PITR on every table

S3 recordings bucket (Object Lock COMPLIANCE 7yr, KMS video key), transcripts bucket (phone key), config bucket (general key)

Eventing

EventBridge Single bus, one rule per domain, DLQ on every target

IoT Core Door controllers, sensors, pharmacy dispensers — per-thing policies with mutual TLS

SNS Security alarm topic, staff broadcast topic

AI / Media

Kinesis Video 24 camera streams ingested continuously

Rekognition Frame sampling at 1 frame / 5s across active cameras — the reason the cost stays sane

Transcribe Real-time telehealth transcription (consent checked first)

Comprehend Sentiment + keyword analysis on transcribed calls

Connect Phone system — every inbound call routes through here

Chime SDK Telehealth video (WebRTC mesh)

Identity / Security

Cognito User pool with MFA enforced, groups: doctor, nurse, admin, auditor

KMS 5 customer-managed keys — general, audit, video, phone, secrets

WAF Operator API — default-block, allow-list facility CIDRs only

IAM Compute role cannot decrypt audit key — can write, cannot read back

API

API Gateway REST for clinical commands, WAF-protected, Cognito authorizer on every method

AppSync GraphQL for operator console, subscriptions for live state

Observability

CloudWatch Per-env log retention, narrow metric filters, alarms that page humans

X-Ray Distributed tracing on the two control-plane functions

Compliance

HealthLake FHIR-compliant medical records, HIPAA covered

Object Lock S3 COMPLIANCE mode — nobody, including root, can delete before 7 years

▸ Sample Pipelines (End to End)

Patient Record Access — Doctor Command

  • 1. Doctor clicks → WebSocket → API Gateway
  • 2. Lambda authorizer validates JWT + MFA
  • 3. Role checked: doctor in cognito:groups?
  • 4. DynamoDB get_item with KMS decryption
  • 5. Audit writer Lambda appends to ledger (compute role has PutItem, no GetItem)
  • 6. CloudWatch metric filter watches for record_denied

Prescription — Controlled Substance Check First

  • 1. Doctor submits → API Gateway
  • 2. Lambda fires on prescription create
  • 3. Controlled substance check runs FIRST
  • 4. If controlled → additional DEA validation required
  • 5. If not → SNS to pharmacy, DynamoDB write
  • 6. Flagged content → EventBridge → SNS → compliance officer
  • 7. Full transcript archived to S3 (7y, phone KMS key)

Lab Results — Auto Processing

  • 1. Lab machine → IoT Core
  • 2. Lambda processes result
  • 3. Critical value detection
  • 4. High-confidence anomalies → EventBridge
  • 5. Provider notified via SNS

Emergency Code Blue — Cascading Fanout

  • 1. Staff triggers (MFA required)
  • 2. EventBridge receives CodeBlueTriggered
  • 3. Lambda fanout publishes wildcard IoT message
  • 4. Every responder receives simultaneously (QoS 2)
  • 5. SNS alerts all staff (SMS + email)
  • 6. Two-person rule enforced for critical actions

Appointment — Atomic Write

  • 1. Staff selects slot
  • 2. Lambda runs DynamoDB TransactWriteItems
  • 3. Both appointment + patient record updated or neither
  • 4. SNS notifies patient and provider
  • 5. Calendar sync via EventBridge

▸ What This Actually Costs

AWS Bill — Monthly

  • NAT gateway: $96 (prod, 3 AZs)
  • NAT data processing: ~$45 (cut sharply by VPC endpoints)
  • Lambda: ~$38
  • Fargate: ~$74
  • Kinesis Video: ~$110
  • Rekognition: ~$180 (sampled — would be ~$18,000 if every frame analyzed)
  • Transcribe: ~$40
  • DynamoDB: ~$52
  • S3 + Object Lock: ~$48
  • KMS (5 keys): ~$8
  • CloudWatch: ~$47
  • Total prod: ~$738 / month
  • Total dev: ~$82 / month (no cameras, 1 NAT)

What It Costs to Build

  • Architecture + compliance scoping: 4–8 weeks
  • Reference implementation: 3–6 months
  • Integration with existing cameras, doors, PBX: 2–4 months
  • Typical range: $250k – $600k one-time

What It Costs to Run

  • AWS bill (per env): ~$1k/yr dev, ~$9k/yr prod
  • 24/7 monitoring + IR: $80k – $200k/yr
  • Compliance audits (HIPAA): $20k – $50k/yr
  • Firmware + integration maintenance: $40k – $120k/yr

The Honest Shortcut

The AWS bill is not the expensive part. It is roughly 5% of annual cost of ownership. The rest is people, compliance, and physical integration with forty-year-old hardware.

▸ Compliance & Controls

HIPAA (Medical Records)

  • HealthLake is FHIR-compliant, covered under AWS BAA
  • Medical records encrypted with a dedicated KMS key
  • Access restricted to medical role via Cognito group
  • Every access logged — no PHI exposed to non-medical roles

Controlled Substances

  • DEA validation is the FIRST check in the prescription pipeline
  • Controlled substances require additional authorization
  • Allowlist maintained by compliance team, not engineering
  • Fail-closed: if validation unavailable, no prescription

Two-Person Rule

  • Unlock requires supervisor OR two operators within 10s window
  • Emergency actions require two distinct confirmations
  • Enforced in Lambda, not in UI — a UI bypass cannot bypass the rule
  • Denials are themselves auditable events

Audit Immutability

  • Audit ledger encrypted with a separate KMS key
  • Compute role has PutItem — can append, cannot read back
  • Reader role is separate, assumed only by auditor group
  • CloudTrail alarm on kms:PutKeyPolicy against audit key

Network

  • No public compute — everything in private subnets
  • VPC endpoints for S3, DynamoDB, KMS, Secrets Manager
  • WAF default-block on operator API (allow-list facility CIDRs)
1 / 5