A leading research university's health sciences division built a Secure Research Environment on AWS with Research Gateway. Internal and external researchers now work on the same protected datasets in isolated project workspaces, with every data transfer approved and logged. Three research labs run on the foundation, from medical imaging AI through to GPU-backed analytics, and the same framework is ready for the programs that follow.
A leading university health sciences division works across clinical research, biomedical informatics, disease prevention, medical imaging, precision medicine and AI-driven healthcare.
As research programs grew and collaboration with outside institutions increased, the division needed a platform where researchers could work with sensitive biomedical data without loosening security, privacy or regulatory controls.
Relevance Lab built a Secure Research Environment on AWS using Research Gateway, working with the division's health sciences, IT and security teams.
Case Study · PDF
Inside the Secure Research Environment
The full case study covers the multi-account AWS architecture, the HIPAA-aligned controls, and the approval workflows that decide how research data moves in and out of the enclave.
On-premises infrastructure could not keep pace with collaborative research programs that involved sensitive biomedical and healthcare datasets, multiple institutions, and HIPAA obligations. The division needed to:
1Open research projects to external collaborators without exposing patient data
2Control every movement of data into and out of the research environment
3Support workloads from statistical analysis through to AI and machine learning
4Provision compliant research environments in a fraction of the usual time
5Leave behind a framework that future research programs can reuse
Solution
Relevance Lab partnered with the University’s Health Sciences, IT, and security teams to deploy a cloud-native Secure Research Environment powered by Research Gateway.
The solution created a secure research enclave with governed data ingress/egress, isolated project workspaces, and centralized administrative oversight.
Research Gateway Platform
The control plane for every secure research project:
Self-service project onboarding
Secure workspace provisioning
Role-based access management
Budget and cost visibility per project
Governance and compliance controls
Automated environment deployment
Operational monitoring and reporting
Secure Research Enclave
How data and access stay governed:
Controlled data ingress and egress workflows
Segregated project environments
Secure Linux and Windows workspaces
Federated authentication with role-based access
Audit logging and activity tracking
Security monitoring and compliance reporting
Flexible Research Infrastructure
What researchers can actually run:
Clinical and biomedical data analysis
AI and machine learning research
Statistical computing with RStudio
Data science with JupyterLab
GPU-enabled research environments
Containerized and HPC workloads
Secure data repositories and data lakes
Research Workloads Enabled
Three research groups with different computational needs run on the same platform.
Medical Imaging AI Lab
HIPAA-controlled environment
RStudio and JupyterLab
Windows and Linux desktops
AI/ML workflows with SageMaker
Biomedical data repositories
Research Lab
Research computing workspaces
Containerized applications
RStudio and Jupyter-based analytics
Data Science and Analytics Lab
GPU-enabled research environments
High-performance analytics workloads
Advanced computational research applications
Architecture Highlights
The Secure Research Environment was built on a multi-account AWS Landing Zone — separate Root, Infra, Security, and Workloads OUs — and designed around eight foundational principles.
Scalable Cloud Foundation
Research Gateway inside the AWS Landing Zone
Centralized governance across accounts
Automated environment provisioning
Isolated project workspaces
Self-service access for researchers
Governance Foundation
AWS Control Tower
AWS Organizations
IAM Identity Center
Multi-account architecture
Centralized security and logging
Secure Research Workspaces
Linux and Windows desktops
Remote desktop access
Containerized workloads
JupyterLab and RStudio
GPU-enabled AI/ML environments
Data Management Framework
Shared research repositories
Project-specific storage
Secure data ingress and egress
Controlled results sharing
Research collaboration workspaces
Secure Data Ingress and Egress
Predefined approval workflow for every transfer
Controlled results sharing
Full traceability of data movement
Audit trail across the enclave
Researcher-Centric Access
Access through secure virtual workspaces
No direct access to underlying infrastructure
Federated authentication
Role-based permissions per project
HIPAA-Aligned Security Controls
Controls for sensitive biomedical research
Protection for patient-related datasets
Segregated project environments
Security monitoring and compliance reporting
Operational Governance
Automated monitoring
Operational reporting
Centralized logging
Alerting across research operations
Business Outcomes
Faster Research Enablement
Standardized, pre-approved environments
Faster project onboarding
Reduced provisioning delays
Secure Multi-Institution Collaboration
Researchers from several organizations on one platform
Sensitive datasets under a single set of controls
Authorized access only, tracked and logged
Stronger Compliance & Governance
Centralized governance and monitoring
Controlled data access and approval workflows
Improved auditability and oversight
Research Agility & Future Readiness
Compute, storage, analytics and AI on demand
A repeatable Secure Research Environment blueprint
Extends across departments and future programs
Customer Perspective
“
The Secure Research Environment developed with RelevanceLab provides a repeatable framework for enabling collaborative biomedical research while maintaining the rigorous security and compliance standards required for sensitive healthcare data. The platform gives our researchers the flexibility they need while providing the governance our institution requires.
— Health Sciences Leadership Team
Research Gateway for Health Sciences Research
Relevance Lab builds Secure Research Environments on AWS for academic medical centers and health sciences institutions. That means multi-account governance, HIPAA-aligned controls, approval-driven data movement, and workspaces ready for everything from RStudio to GPU-backed AI. The platform also provides budget and cost visibility per project.
AWS recognized Research Gateway as one of the top two partner solutions globally for Higher Education. Institutions come to us to replace isolated on-premises infrastructure with governed self-service, without loosening the standards patient data demands.
BIOMEDICAL RESEARCH CASE STUDY
Ready to open your research data to outside collaborators?
See how Relevance Lab helped a health sciences institution give internal and external researchers access to the same protected datasets, with every transfer approved and logged.