Multi-Lab Health Sciences Research Environment on AWS

Overview

A leading research university's health sciences division built a Secure Research Environment on AWS with Research Gateway. Internal and external researchers now work on the same protected datasets in isolated project workspaces, with every data transfer approved and logged. Three research labs run on the foundation, from medical imaging AI through to GPU-backed analytics, and the same framework is ready for the programs that follow.

INDUSTRY
Healthcare and Life Sciences
SERVICES/PLATFORMS
Research Gateway

A leading university health sciences division works across clinical research, biomedical informatics, disease prevention, medical imaging, precision medicine and AI-driven healthcare.

As research programs grew and collaboration with outside institutions increased, the division needed a platform where researchers could work with sensitive biomedical data without loosening security, privacy or regulatory controls.

Relevance Lab built a Secure Research Environment on AWS using Research Gateway, working with the division's health sciences, IT and security teams.

Biomedical Research Case Study cover
Case Study · PDF

Inside the Secure Research Environment

The full case study covers the multi-account AWS architecture, the HIPAA-aligned controls, and the approval workflows that decide how research data moves in and out of the enclave.

View the Full Case Study

Business Challenge

On-premises infrastructure could not keep pace with collaborative research programs that involved sensitive biomedical and healthcare datasets, multiple institutions, and HIPAA obligations. The division needed to:

1 Open research projects to external collaborators without exposing patient data
2 Control every movement of data into and out of the research environment
3 Support workloads from statistical analysis through to AI and machine learning
4 Provision compliant research environments in a fraction of the usual time
5 Leave behind a framework that future research programs can reuse

Solution

Relevance Lab partnered with the University’s Health Sciences, IT, and security teams to deploy a cloud-native Secure Research Environment powered by Research Gateway.

The solution created a secure research enclave with governed data ingress/egress, isolated project workspaces, and centralized administrative oversight.

Research Gateway Platform

The control plane for every secure research project:

  • Self-service project onboarding
  • Secure workspace provisioning
  • Role-based access management
  • Budget and cost visibility per project
  • Governance and compliance controls
  • Automated environment deployment
  • Operational monitoring and reporting
Secure Research Enclave

How data and access stay governed:

  • Controlled data ingress and egress workflows
  • Segregated project environments
  • Secure Linux and Windows workspaces
  • Federated authentication with role-based access
  • Audit logging and activity tracking
  • Security monitoring and compliance reporting
Flexible Research Infrastructure

What researchers can actually run:

  • Clinical and biomedical data analysis
  • AI and machine learning research
  • Statistical computing with RStudio
  • Data science with JupyterLab
  • GPU-enabled research environments
  • Containerized and HPC workloads
  • Secure data repositories and data lakes
Research Workloads Enabled

Three research groups with different computational needs run on the same platform.

Medical Imaging AI Lab

  • HIPAA-controlled environment
  • RStudio and JupyterLab
  • Windows and Linux desktops
  • AI/ML workflows with SageMaker
  • Biomedical data repositories

Research Lab

  • Research computing workspaces
  • Containerized applications
  • RStudio and Jupyter-based analytics

Data Science and Analytics Lab

  • GPU-enabled research environments
  • High-performance analytics workloads
  • Advanced computational research applications

Architecture Highlights

The Secure Research Environment was built on a multi-account AWS Landing Zone — separate Root, Infra, Security, and Workloads OUs — and designed around eight foundational principles.

Scalable Cloud Foundation

  • Research Gateway inside the AWS Landing Zone
  • Centralized governance across accounts
  • Automated environment provisioning
  • Isolated project workspaces
  • Self-service access for researchers

Governance Foundation

  • AWS Control Tower
  • AWS Organizations
  • IAM Identity Center
  • Multi-account architecture
  • Centralized security and logging

Secure Research Workspaces

  • Linux and Windows desktops
  • Remote desktop access
  • Containerized workloads
  • JupyterLab and RStudio
  • GPU-enabled AI/ML environments

Data Management Framework

  • Shared research repositories
  • Project-specific storage
  • Secure data ingress and egress
  • Controlled results sharing
  • Research collaboration workspaces

Secure Data Ingress and Egress

  • Predefined approval workflow for every transfer
  • Controlled results sharing
  • Full traceability of data movement
  • Audit trail across the enclave

Researcher-Centric Access

  • Access through secure virtual workspaces
  • No direct access to underlying infrastructure
  • Federated authentication
  • Role-based permissions per project

HIPAA-Aligned Security Controls

  • Controls for sensitive biomedical research
  • Protection for patient-related datasets
  • Segregated project environments
  • Security monitoring and compliance reporting

Operational Governance

  • Automated monitoring
  • Operational reporting
  • Centralized logging
  • Alerting across research operations

Business Outcomes

Faster Research Enablement

  • Standardized, pre-approved environments
  • Faster project onboarding
  • Reduced provisioning delays

Secure Multi-Institution Collaboration

  • Researchers from several organizations on one platform
  • Sensitive datasets under a single set of controls
  • Authorized access only, tracked and logged

Stronger Compliance & Governance

  • Centralized governance and monitoring
  • Controlled data access and approval workflows
  • Improved auditability and oversight

Research Agility & Future Readiness

  • Compute, storage, analytics and AI on demand
  • A repeatable Secure Research Environment blueprint
  • Extends across departments and future programs

Customer Perspective

The Secure Research Environment developed with RelevanceLab provides a repeatable framework for enabling collaborative biomedical research while maintaining the rigorous security and compliance standards required for sensitive healthcare data. The platform gives our researchers the flexibility they need while providing the governance our institution requires.

— Health Sciences Leadership Team

Research Gateway for Health Sciences Research

Relevance Lab builds Secure Research Environments on AWS for academic medical centers and health sciences institutions. That means multi-account governance, HIPAA-aligned controls, approval-driven data movement, and workspaces ready for everything from RStudio to GPU-backed AI. The platform also provides budget and cost visibility per project.

AWS recognized Research Gateway as one of the top two partner solutions globally for Higher Education. Institutions come to us to replace isolated on-premises infrastructure with governed self-service, without loosening the standards patient data demands.

BIOMEDICAL RESEARCH CASE STUDY

Ready to open your research data to outside collaborators?

See how Relevance Lab helped a health sciences institution give internal and external researchers access to the same protected datasets, with every transfer approved and logged.

Tags

No items found.