A leading US academic medical center supports hundreds of researchers working with protected health information, clinical datasets, genomics and medical imaging.
As research programs spread across departments and business units, the institution needed a cloud platform its researchers could actually use, without loosening the security policies that come with patient data.
Relevance Lab deployed a customized Research Gateway implementation as a Trusted Research Environment, giving each project isolated workspaces, approval-driven data governance, and administration that no longer depended on Research IT building things by hand.
Case Study · PDF
Inside the Trusted Research Environment
How a private, network-only portal delivers Windows, Red Hat Linux and SAS workspaces to hundreds of researchers, with a named Data Administrator approving every dataset that moves in or out.
View the Full Case Study
→
Business Challenges
01
Secure Research Workspaces
Workspaces had to run on AWS but stay reachable only from the institution's corporate network. Direct internet access to research desktops was not permitted.
02
Standardized Computing Environments
Every workspace had to run an institution-approved Windows Server or Red Hat Enterprise Linux image, with mandatory endpoint protection and licensed research applications such as SAS pre-installed and centrally managed.
03
Controlled Data Movement
Nothing moved in or out without institutional approval. Every ingress and egress needed a full audit trail and enforcement of the institution's data handling policies.
04
Role-Based Governance
Administrators needed to onboard AWS accounts, create projects and manage institutional settings. Researchers and project owners needed self-service inside those boundaries, with responsibilities cleanly separated.
05
Scalable Administration
As research programs multiplied, manual administration stopped scaling. The institution needed central governance, consistent security controls and project-level cost visibility without adding headcount.
Solution
Secure TRE on AWS
Relevance Lab deployed Research Gateway as a private institutional research platform for the medical center.
The solution combined secure infrastructure provisioning with automated governance workflows to deliver compliant, self-service research environments.
Private Research Portal
Research Gateway was deployed as an internal application accessible only from within the institution's network.
Researchers could securely request and manage cloud resources without exposing administrative services to the public internet.
Trusted Research Environment
Each research project received isolated cloud workspaces with:
- Windows Server remote desktops
- Red Hat Enterprise Linux desktops
- Standardized institutional software images
- Mandatory endpoint protection
- Centrally managed software updates
- SAS and licensed research applications
- Secure project storage
- Identity-based access controls
Governed Data Ingress & Egress
Research Gateway implemented approval-driven workflows for all research data movement.
- Institutional Data Libraries
- Research study administration
- Ingress approval workflows
- Egress approval workflows
- Complete audit trails
- Policy enforcement
Customized Research Catalog
The catalog was customized to align with institutional research requirements.
- Windows secure desktops
- Red Hat Enterprise Linux desktops
- SAS-enabled environments
- Standardized software stacks
- Institution-approved compute configurations
Researchers could provision approved environments without manual intervention from Research IT.
Architecture Highlights
Researchers authenticate on the institution's internal network and provision workspaces from a catalog Research IT controls. Research Gateway orchestrates the AWS infrastructure underneath while enforcing governance policies, approval workflows and role-based access.
Reachable only from the institution's internal network, with no administrative service exposed publicly
Identity-integrated authentication, with separate access for administrators, researchers and project owners
Workspaces provisioned from an institution-approved catalog rather than built by hand
Ingress and egress gated by a named Data Administrator, with complete audit trails
Project-level isolation, with cost monitoring and compliance logging across every workspace
Business Outcomes
Researcher Productivity
Researchers reached institution-approved computing environments without waiting on manual infrastructure provisioning.
- Self-service provisioning of approved workspaces
- Licensed research software available immediately
- Research IT off the critical path for routine requests
Governance & Compliance
Governance moved into the platform itself, rather than sitting in manual processes alongside it.
- Ingress and egress approvals built into the workflow
- Complete auditability of data movement
- Standardized security controls on every project
Operational Efficiency
Administration centralized while researchers kept working independently inside approved boundaries.
- Simplified onboarding of AWS accounts and business units
- Software images managed centrally, updated once for everyone
- Consistent policy enforcement as programs multiply
Financial Visibility
Project-level monitoring gave administrators a real view of cloud consumption across departments.
- Cloud costs allocated by project
- Research spending visible to administrators
- Budget planning grounded in actual consumption
Customer Perspective
“
Research Gateway provided our institution with a secure and scalable Trusted Research Environment that enables our researchers to focus on scientific discovery rather than infrastructure management. By combining standardized research workspaces with governed data workflows and centralized administration, we significantly improved security, operational efficiency, and researcher productivity while maintaining the compliance standards required for sensitive biomedical research.
— Research IT Leadership, Leading U.S. Academic Medical Center
Research Gateway for Trusted Research Environments
Relevance Lab builds Trusted Research Environments on AWS for academic medical centers and research institutions. Network-isolated portals, approval-driven data governance, standardized Windows and Linux workspaces, and licensed research software delivered through a catalog rather than a ticket queue.
AWS recognized Research Gateway as one of the top two partner solutions globally for Higher Education.
HEALTHCARE RESEARCH CASE STUDY
Give Researchers Self-Service Without Opening the Network
See how one academic medical center gave hundreds of researchers self-service AWS workspaces on a portal that never touches the public internet, with every dataset movement approved and logged.