Case Study Healthcare

Modernizing Application Credentials Off Windows Server 2012 for a Tier 1 Healthcare System

Retiring server-stored passwords and unsupported infrastructure for a Tier 1 healthcare system's applications

Server-stored passwords eliminated; PHI/PII logging exposure closed

Summary

When Windows Server 2012 reached end of extended support in October 2023, aiDataWorks led a credentials modernization effort for a Tier 1 healthcare system to migrate applications onto in-support infrastructure while eliminating insecure, server-stored password files. The team replaced local password-file dependencies with NuGet package-based, SDK-driven application accounts secured via a Privileged Access Management (PAM) SDK, updated Oracle connectivity, and migrated execution to Windows Server 2022. The effort also closed a critical security gap by removing PHI/PII data from web service logs in legacy code. Changes were validated in Dev/Test before production rollout, and the same modernization pattern was extended to additional applications, leaving the healthcare system running securely and compliantly on modern infrastructure.

The challenge

  • End-of-support infrastructure. Windows Server 2012 reached end of extended support in October 2023, forcing applications off unsupported infrastructure before security and vendor patching stopped altogether.
  • Insecure local credential storage. Applications stored server-side password files locally, a pattern that violated least-privilege principles and fell short of modern security standards.
  • PHI/PII exposure in application logs. Legacy web service code recorded sensitive PHI/PII data in logs — a real compliance and security exposure that needed to be closed alongside the infrastructure migration.
  • Modernization without disruption. Applications needed to meet modern security and design standards without degrading performance for the teams and systems that depended on them.

The solution

Credential & infrastructure modernization: legacy Windows Server 2012 applications with local password files → NuGet/SDK-based account & Oracle Client 19c updates → Windows Server 2022 production, secured by the PAM SDK

How we built it

Credential modernization (NuGet/PAM)

  • Transitioned application accounts to NuGet packages (SDK-based application accounts), eliminating server-stored password files.
  • Integrated the Privileged Access Management (PAM) SDK so credentials resolve securely at runtime instead of being read from a local file.
  • Aligned the new account model with Secrets Agents standards for consistent, auditable credential handling.

Oracle connectivity update

  • Updated application code for Oracle account handling to work with the new SDK-based credential model.
  • Integrated Oracle Client 19c across the affected applications, replacing the outdated client tied to the legacy server.

Server 2022 migration & job scheduling

  • Migrated application execution from Windows Server 2012 to Windows Server 2022.
  • Aligned MJS job scheduling with the updated host groups tied to the new server environment.

PHI/PII logging remediation & rollout

  • Removed PHI/PII data recording from web service logs by fixing the legacy code responsible for it.
  • Tested all changes in Dev/Test environments before merging to production.
  • Extended the same modernization pattern to additional applications after the initial rollout.

Outcomes

100% Applications migrated to in-support Windows Server 2022 was Windows Server 2012
Eliminated Server-stored password files replaced by SDK-based, PAM-secured accounts
Closed PHI/PII logging exposure removed from legacy web service code
  • All listed applications now run on in-support Windows Server 2022, removing the operational and security risk of unsupported infrastructure.
  • Compliance was achieved with Oracle account naming standards, least-privilege principles, and encryption-at-rest standards across the modernized applications.
  • The same modernization pattern was extended beyond the initial application set, giving the healthcare system a repeatable path for future credential and infrastructure updates.

Solving something similar?

We will walk your current data landscape and show you what a governed, secure infrastructure would take.

Schedule a consultation