10 Million Members. Six PKI Gaps. One Healthcare PKI Rebuild.
Customer Profile
Texas’s largest health benefits provider, serving ~10 million members through 150,000+ physicians and 500+ hospitals. Offers individual, employer, Medicaid, Medicare Advantage, dental, and vision plans, with over a century of service in clinical care and community health.
Industry
Healthcare & Health Insurance
Engagement Type
PKI Implementation & Infrastructure Deployment
At a Glance Outcome
2-Tier
Microsoft PKI architecture deployed with offline Root CAHSM
Root and Issuing CA keys secured in tamper-resistant hardwareCompliant
HIPAA and FIPS-aligned key ceremony deliveredNDES
Secure mobile enrollment with real-time OCSP certificate revocationThe Enterprise
Challenges
As the client's digital services expanded, six weaknesses in their hybrid PKI environment came into focus: an exposed Root CA, unprotected private keys, missing governance controls, and gaps in resilience planning.
Root CA online, domain-joined, and exposed
Private keys stored in file system, not HSMs
No key custodian matrix or separation of duties
Six gaps, one trust chain. Every weakness traced back to the same Root CA, so the fix had to start there, then rebuild outward.
Encryption Consulting Assessment Team
PRE-IMPLEMENTATION ASSESSMENT | ENCRYPTION CONSULTING · PKI SERVICES
Our Offered
Solutions
The engagement ran four workstreams across four phases: assessment and design, build and implementation, functional testing, and knowledge transfer.
Capability 01
PKI Architecture Design & Planning
Capability 02
HSM Integration & Key Ceremony
Capability 03
Two-Tier Microsoft PKI Deployment
Capability 04
DR Planning & Knowledge Transfer
The result was a compliant, resilient, and scalable PKI infrastructure, purpose-built to protect the sensitive health data of millions of members and support the organization’s growth for decades ahead.
Encryption Consulting Assessment Team
ENGAGEMENT SUMMARY | ENCRYPTION CONSULTING · PKI SERVICES
The Overall
Business Outcome
With the two-tier Microsoft PKI in place, the client closed the structural vulnerabilities, met HIPAA and FIPS requirements, and now has a security foundation that protects 10 million members and scales as the organization grows.
PKI trust chain fully secured
HIPAA and FIPS compliance achieved
Lifecycle control and resilience established
Discover Our
Latest Resources
- Blogs
- White Papers
- Videos
Uncategorized
Multi-Cloud PKIaaS Architecture Guide for AWS, Azure, and GCP
A technical architecture guide for deploying PKIaaS across AWS, Azure, GCP, Kubernetes, service mesh, and on-premises environments. Covers certificate issuance patterns, enrollment protocol mapping per cloud, cert-manager integration, Istio and Linkerd mTLS, HashiCorp Vault PKI engine, and unified CLM across a multi-cloud estate.
Read more
White Paper
The 47-Day Certificate & Post-Quantum Readiness Playbook
Navigate the 47-day certificate validity era and post-quantum cryptography with a practical readiness playbook covering deadlines, automation, ownership, exceptions, and ROI.
Read more
Video
Introducing MCP Server for Certificate Lifecycle Management (CLM) | AI-Powered CertSecure Manager
Explore expert insights on cybersecurity, PKI, and post-quantum readiness, with practical guidance to strengthen security and future-proof cryptography.
Watch Now
