Skip to content
All work

Case study 07 / 11

Healthcare cybersecurity and compliance

DeployedClient work · NDA

From Spreadsheets to a Healthcare Compliance Platform with AI

Working directly with a UK-based advisory firm, I replaced a spreadsheet-driven compliance practice with a secure platform for hospitals, clinics and health tech companies. Every client gets its own protected workspace, assessments become costed action plans in one click, and an AI assistant answers questions without ever mixing clients' data. I deployed it to the client's own server.

  1. System

    Assessment is scored

  2. Output

    Findings and risks

  3. System

    A costed action plan

  4. Output

    Ordered roadmap, timeline and budget

Every client has its own protected workspace, and the AI assistant only searches the asking client's data.

The problem

My client, a cybersecurity advisory firm, helps hospitals, clinics and health tech companies get ready for two things: using AI safely and qualifying for cyber insurance. They ran the whole practice from a large Excel workbook full of macros. It worked for one consultant and one client at a time, but it couldn't grow.

  • One copy per client. Every client had their own copy of the workbook, and keeping dozens of copies up to date was manual and error-prone.
  • No access control. Someone filling in answers could also change the questions, the scoring or another department's answers.
  • No follow-through. A low score just sat in a cell. Nothing turned it into a task with an owner, a deadline and proof it was fixed.
  • No ongoing view. Once the report was delivered, nobody tracked what changed, which evidence expired or when the next insurance renewal was due.

What I delivered

A secure platform where every client has its own workspace, every user sees exactly what they should, and an assessment flows automatically into an ongoing compliance program. It's built around three connected modules and guided by one nine-step workflow, from setting up a client to producing the final reports:

  • AI readiness assessment: a maturity questionnaire completed department by department.
  • Cyber insurance readiness assessment: a control checklist weighted by what insurers care about most.
  • Continuous compliance: turns the gaps from both into findings, risks, action plans, evidence tracking, monitoring and renewal reminders.

How it works

When an assessment is scored, the platform automatically turns weak answers into findings, groups them into risks, merges duplicates where both assessments point to the same gap, and creates a costed task for every gap. For one demo client, that's 162 findings, 65 risks and 162 costed tasks in a single click.

A list of tasks isn't a plan, so I added a scheduling engine that puts security work in the right order (for example, identity before detection, and detection before incident response) and finds the critical path. That feeds a task board, a timeline view, milestones and a live budget.

One control library covers over three hundred security controls mapped to fourteen frameworks, including HIPAA, NIST, ISO 27001 and SOC 2. One piece of work can show progress toward all of them at once.

An AI assistant that respects boundaries

The final phase added an AI governance assistant that summarises assessments, explains gaps, finds missing evidence and drafts executive briefings.

  • The right model for each question. Simple questions go to a free, locally run model, and complex compliance reasoning goes to a more powerful one, depending on the client's plan. If one provider is down, another takes over, and the cost of every request is logged.
  • Consistent, useful answers. Every answer follows the same structure: summary, findings, risk level, recommended action, business impact, sources and confidence.
  • No mixing of clients' data. Shared reference material is searchable by everyone, but each client's own data is kept in a separate area and only searched for that client. If the system can't confirm which client is asking, it doesn't search client data at all.

Built for trust

  • Two independent layers of protection: the database enforces who can see what, and the application checks again on every request. A dedicated suite of 56 tests logs in as different users and clients and confirms each sees only its own data.
  • Five clear roles: owner, client admin, advisor (only for their assigned clients), client user (only their assigned areas) and read-only viewer.
  • Questions are locked so only answers can be edited, assessments are locked after approval, advisors need the client's sign-off to finalise, and every edit, approval and export is logged.
  • Secure sign-in with multi-factor authentication for admins and advisors.

The results

  • A copy-per-client spreadsheet became one secure platform with protected client workspaces and a shared, locked template library.
  • Scoring, gap analysis, risk registers, action plans and board-ready PDF reports that were built by hand now generate automatically.
  • The question library grew to over a hundred thousand questions across many industries without changing the core.
  • Monitoring, evidence expiry and renewal tracking turn a one-off assessment into an ongoing client relationship.
  • I took it from local development to the client's own server, where their team is testing it.
Under the hoodShow technical details
  • Data layer: self-hosted Grist with row-level access rules. I learned its hidden pitfalls (rules saved the wrong way are never enforced, rule order matters, and formula permissions can leak data) and built helpers so every rule is created correctly.
  • Application: FastAPI handling scoring, workflows, AI routing and billing, with Keycloak and OIDC for sign-in.
  • AI: retrieval with Qdrant and local embeddings, local Llama through Ollama, and OpenAI and Anthropic models with tier-based routing and automatic fallback.
  • Performance: the main dashboard went from eleven sequential data calls to two parallel batches, with caching and compression, so it stays fast with over a hundred thousand records.
  • Pricing: plans, tiers and trials live in the database, so staff can change pricing without a new release. Billing runs on Stripe.