Enabling Secure Trusted Research Environments for Biomedical Research on AWS

Overview

An academic medical center replaced ad-hoc research computing with a Trusted Research Environment on AWS. Hundreds of researchers now provision their own Windows, Red Hat Linux and SAS workspaces from a portal reachable only inside the hospital network, with every data transfer approved by a named steward.

INDUSTRY
Healthcare & Life Sciences - Academic Medical Centers
SERVICES/PLATFORMS
Research Gateway

A leading US academic medical center supports hundreds of researchers working with protected health information, clinical datasets, genomics and medical imaging.

As research programs spread across departments and business units, the institution needed a cloud platform its researchers could actually use, without loosening the security policies that come with patient data.

Relevance Lab deployed a customized Research Gateway implementation as a Trusted Research Environment, giving each project isolated workspaces, approval-driven data governance, and administration that no longer depended on Research IT building things by hand.

Cover of the Trusted Research Environment case study PDF
Case Study · PDF

Inside the Trusted Research Environment

How a private, network-only portal delivers Windows, Red Hat Linux and SAS workspaces to hundreds of researchers, with a named Data Administrator approving every dataset that moves in or out.

View the Full Case Study

Business Challenges

01

Secure Research Workspaces

Workspaces had to run on AWS but stay reachable only from the institution's corporate network. Direct internet access to research desktops was not permitted.

02

Standardized Computing Environments

Every workspace had to run an institution-approved Windows Server or Red Hat Enterprise Linux image, with mandatory endpoint protection and licensed research applications such as SAS pre-installed and centrally managed.

03

Controlled Data Movement

Nothing moved in or out without institutional approval. Every ingress and egress needed a full audit trail and enforcement of the institution's data handling policies.

04

Role-Based Governance

Administrators needed to onboard AWS accounts, create projects and manage institutional settings. Researchers and project owners needed self-service inside those boundaries, with responsibilities cleanly separated.

05

Scalable Administration

As research programs multiplied, manual administration stopped scaling. The institution needed central governance, consistent security controls and project-level cost visibility without adding headcount.

Solution

Secure TRE on AWS

Relevance Lab deployed Research Gateway as a private institutional research platform for the medical center.

The solution combined secure infrastructure provisioning with automated governance workflows to deliver compliant, self-service research environments.

Private Research Portal

Research Gateway was deployed as an internal application accessible only from within the institution's network.

Researchers could securely request and manage cloud resources without exposing administrative services to the public internet.

Trusted Research Environment

Each research project received isolated cloud workspaces with:

  • Windows Server remote desktops
  • Red Hat Enterprise Linux desktops
  • Standardized institutional software images
  • Mandatory endpoint protection
  • Centrally managed software updates
  • SAS and licensed research applications
  • Secure project storage
  • Identity-based access controls
Customized Research Catalog

The catalog was customized to align with institutional research requirements.

  • Windows secure desktops
  • Red Hat Enterprise Linux desktops
  • SAS-enabled environments
  • Standardized software stacks
  • Institution-approved compute configurations

Researchers could provision approved environments without manual intervention from Research IT.

Architecture Highlights

Researchers authenticate on the institution's internal network and provision workspaces from a catalog Research IT controls. Research Gateway orchestrates the AWS infrastructure underneath while enforcing governance policies, approval workflows and role-based access.

Reachable only from the institution's internal network, with no administrative service exposed publicly
Identity-integrated authentication, with separate access for administrators, researchers and project owners
Workspaces provisioned from an institution-approved catalog rather than built by hand
Ingress and egress gated by a named Data Administrator, with complete audit trails
Project-level isolation, with cost monitoring and compliance logging across every workspace

Business Outcomes

Researcher Productivity

Researchers reached institution-approved computing environments without waiting on manual infrastructure provisioning.

  • Self-service provisioning of approved workspaces
  • Licensed research software available immediately
  • Research IT off the critical path for routine requests
Governance & Compliance

Governance moved into the platform itself, rather than sitting in manual processes alongside it.

  • Ingress and egress approvals built into the workflow
  • Complete auditability of data movement
  • Standardized security controls on every project
Operational Efficiency

Administration centralized while researchers kept working independently inside approved boundaries.

  • Simplified onboarding of AWS accounts and business units
  • Software images managed centrally, updated once for everyone
  • Consistent policy enforcement as programs multiply
Financial Visibility

Project-level monitoring gave administrators a real view of cloud consumption across departments.

  • Cloud costs allocated by project
  • Research spending visible to administrators
  • Budget planning grounded in actual consumption

Customer Perspective

Research Gateway provided our institution with a secure and scalable Trusted Research Environment that enables our researchers to focus on scientific discovery rather than infrastructure management. By combining standardized research workspaces with governed data workflows and centralized administration, we significantly improved security, operational efficiency, and researcher productivity while maintaining the compliance standards required for sensitive biomedical research.

— Research IT Leadership, Leading U.S. Academic Medical Center

Research Gateway for Trusted Research Environments

Relevance Lab builds Trusted Research Environments on AWS for academic medical centers and research institutions. Network-isolated portals, approval-driven data governance, standardized Windows and Linux workspaces, and licensed research software delivered through a catalog rather than a ticket queue.

AWS recognized Research Gateway as one of the top two partner solutions globally for Higher Education.

HEALTHCARE RESEARCH CASE STUDY

Give Researchers Self-Service Without Opening the Network

See how one academic medical center gave hundreds of researchers self-service AWS workspaces on a portal that never touches the public internet, with every dataset movement approved and logged.

Tags

No items found.