Case Study Healthcare
Modernizing Application Credentials Off Windows Server 2012 for a Tier 1 Healthcare System
Retiring server-stored passwords and unsupported infrastructure for a Tier 1 healthcare system's applications
Server-stored passwords eliminated; PHI/PII logging exposure closed
Summary
When Windows Server 2012 reached end of extended support in October 2023, aiDataWorks led a credentials modernization effort for a Tier 1 healthcare system to migrate applications onto in-support infrastructure while eliminating insecure, server-stored password files. The team replaced local password-file dependencies with NuGet package-based, SDK-driven application accounts secured via a Privileged Access Management (PAM) SDK, updated Oracle connectivity, and migrated execution to Windows Server 2022. The effort also closed a critical security gap by removing PHI/PII data from web service logs in legacy code. Changes were validated in Dev/Test before production rollout, and the same modernization pattern was extended to additional applications, leaving the healthcare system running securely and compliantly on modern infrastructure.
The challenge
- End-of-support infrastructure. Windows Server 2012 reached end of extended support in October 2023, forcing applications off unsupported infrastructure before security and vendor patching stopped altogether.
- Insecure local credential storage. Applications stored server-side password files locally, a pattern that violated least-privilege principles and fell short of modern security standards.
- PHI/PII exposure in application logs. Legacy web service code recorded sensitive PHI/PII data in logs — a real compliance and security exposure that needed to be closed alongside the infrastructure migration.
- Modernization without disruption. Applications needed to meet modern security and design standards without degrading performance for the teams and systems that depended on them.
The solution
How we built it
Credential modernization (NuGet/PAM)
- Transitioned application accounts to NuGet packages (SDK-based application accounts), eliminating server-stored password files.
- Integrated the Privileged Access Management (PAM) SDK so credentials resolve securely at runtime instead of being read from a local file.
- Aligned the new account model with Secrets Agents standards for consistent, auditable credential handling.
Oracle connectivity update
- Updated application code for Oracle account handling to work with the new SDK-based credential model.
- Integrated Oracle Client 19c across the affected applications, replacing the outdated client tied to the legacy server.
Server 2022 migration & job scheduling
- Migrated application execution from Windows Server 2012 to Windows Server 2022.
- Aligned MJS job scheduling with the updated host groups tied to the new server environment.
PHI/PII logging remediation & rollout
- Removed PHI/PII data recording from web service logs by fixing the legacy code responsible for it.
- Tested all changes in Dev/Test environments before merging to production.
- Extended the same modernization pattern to additional applications after the initial rollout.
Outcomes
- All listed applications now run on in-support Windows Server 2022, removing the operational and security risk of unsupported infrastructure.
- Compliance was achieved with Oracle account naming standards, least-privilege principles, and encryption-at-rest standards across the modernized applications.
- The same modernization pattern was extended beyond the initial application set, giving the healthcare system a repeatable path for future credential and infrastructure updates.
Solving something similar?
We will walk your current data landscape and show you what a governed, secure infrastructure would take.
