Enabling Secure Trusted Research Environments for Biomedical Research on AWS

A leading US academic medical center supports hundreds of researchers working with PHI, clinical datasets, genomics, medical imaging, and other sensitive data.

As research programs expanded, the institution needed an AWS-based Trusted Research Environment (TRE) — one offering secure, isolated workspaces and protecting data across its full lifecycle, from ingestion through collaboration to controlled export, all within strict institutional security and governance requirements.

RelevanceLab partnered with the institution to deploy a customized Research Gateway implementation, delivering secure research environments, automated governance workflows, and simplified administration institution-wide.

Healthcare Research Case Study cover
Case Study · PDF

Trusted Research Environments for Sensitive Biomedical Data

A deep dive into how Research Gateway delivers HIPAA-aligned research workspaces, controlled data movement, and centralized governance for PHI, genomics, and clinical research data on AWS.

View the Full Case Study

Business Challenges

01

Secure Research Workspaces

Research workspaces needed to run on AWS while remaining accessible only through the institution's corporate network. Direct Internet access was prohibited to protect sensitive research data.

02

Standardized Computing Environments

All workspaces had to use institution-approved Windows Server and Red Hat Enterprise Linux images with mandatory security software, including CrowdStrike, and centrally managed research applications such as SAS.

03

Controlled Data Movement

All research data ingress and egress required institutional approval, complete audit trails, and policy enforcement to prevent unauthorized movement of sensitive data.

04

Role-Based Governance

The platform required clearly defined administrative and researcher roles, enabling centralized governance while providing researchers with self-service access within approved policies.

05

Scalable Administration

The institution needed centralized governance, standardized security controls, automated administration, and project-level cost visibility to support expanding research programs while maintaining compliance.

Solution

Secure TRE on AWS

RelevanceLab deployed Research Gateway as a private institutional research platform accessible exclusively from the customer's network.

The solution combined secure infrastructure provisioning with automated governance workflows to deliver compliant, self-service research environments.

Private Research Portal

Research Gateway was deployed as an internal application accessible only from within the institution's network.

Researchers could securely request and manage cloud resources without exposing administrative services to the public Internet.

Trusted Research Environment

Each research project received isolated cloud workspaces with:

  • Windows Server remote desktops
  • Red Hat Enterprise Linux desktops
  • Standardized institutional software images
  • CrowdStrike endpoint protection
  • Centrally managed software updates
  • SAS and licensed research applications
  • Secure project storage
  • Identity-based access controls
Customized Research Catalog

The catalog was customized to align with institutional research requirements.

  • Windows secure desktops
  • Red Hat Enterprise Linux desktops
  • SAS-enabled environments
  • Standardized software stacks
  • Institution-approved compute configurations

Researchers could provision approved environments without manual intervention from Research IT.

Architecture Highlights

Secure Research Platform with Centralized Governance

Researchers access Research Gateway through the institution’s internal network, where authenticated users provision secure research workspaces using institution-approved catalog offerings.

Private application deployment
Identity-integrated authentication
Role-based access control
Automated workspace provisioning
Secure Windows and Linux desktops
Governed data ingress workflows
Governed data egress workflows
Centralized software image management
Project-level isolation
Cost monitoring and reporting
Comprehensive auditing and logging

Business Outcomes

Researcher Productivity

Researchers gained rapid access to secure, institution-approved computing environments without waiting for manual infrastructure provisioning.

  • Faster onboarding of new research projects
  • Self-service provisioning of approved workspaces
  • Consistent research environments across departments
  • Immediate access to licensed research software
  • Reduced dependency on Research IT for routine requests
Governance & Compliance

Institutional governance became embedded within the research platform through automated controls and standardized security.

  • Controlled data ingress and egress approvals
  • Complete auditability of data movement
  • Centralized management of sensitive datasets
  • Standardized security controls
  • Reduced risk of unauthorized data access
Operational Efficiency

Research Gateway centralized administration while enabling researchers to operate independently within approved governance boundaries.

  • Simplified AWS account onboarding
  • Standardized project creation
  • Centralized software management
  • Reduced manual provisioning effort
  • Consistent policy enforcement
Financial Visibility

Project-level cost monitoring and reporting improved visibility into cloud consumption across research departments.

  • Monitor research spending
  • Allocate cloud costs by project
  • Improve budget planning
  • Optimize cloud utilization

Customer Perspective

Research Gateway provided our institution with a secure and scalable Trusted Research Environment that enables our researchers to focus on scientific discovery rather than infrastructure management. By combining standardized research workspaces with governed data workflows and centralized administration, we significantly improved security, operational efficiency, and researcher productivity while maintaining the compliance standards required for sensitive biomedical research.

— Research IT Leadership, Leading U.S. Academic Medical Center

Research Gateway: Built for Modern Research Computing

Relevance Lab helps academic medical centers and research institutions replace manual, compliance-heavy research provisioning with a governed Trusted Research Environment on AWS. Our expertise covers Research Gateway deployment, HIPAA-aligned security controls, approval-driven data ingress and egress workflows, and role-based governance for research administrators, researchers, and project owners.

We combine deep AWS platform knowledge with hands-on experience in biomedical and clinical research computing, helping institutions standardize research workspaces, reduce dependency on Research IT for routine requests, and give scientists secure, self-service access to the compute they need.

HEALTHCARE RESEARCH CASE STUDY

Ready to Build a Trusted Research Environment?

Give your researchers self-service access to compliant AWS research environments with Relevance Lab. Deploy Research Gateway, standardize secure workspaces, and centralize governance — all with expert guidance.

Tags

No items found.