Hjem » Sykehuspartner – Healthcare

Governance and security for healthcare data at +3 million people scale

Client
Sykehuspartner – Healthcare
Industry
Healthcare IT / Data Infrastructure
Challenge
Building governance, security, and operational structure for a national healthcare data platform
Results

A governed Power BI platform enabled secure, reliable data access for 90,000 healthcare professionals

Scope

We built the governance and security foundation behind a national healthcare data platform

Sykehuspartner AS supports most regional health authorities in Norway. Around 90,000 users rely on its data platform, and the decisions made through that platform affect healthcare delivery for 3 million people.

As the Power BI environment expanded across both cloud and on-premises infrastructure, the real challenge became governance. Sensitive healthcare data, strict regulatory obligations, and a decentralised organisation created a need for clear policies, structured access control, and a secure operating model.

The scope included:

  • Establishing a governance framework for a large decentralised data platform
  • Defining policies for data sharing, ownership, and lifecycle management
  • Designing security architecture for sensitive healthcare data across hybrid environments
  • Structuring roles, permissions, and access controls in line with regulatory requirements
  • Building an operational foundation for high availability, compliance, and long-term maintainability
  • Enabling secure integration between on-premises infrastructure and cloud analytics

Concept

A governed platform built for trust, compliance, and scale

The objective was to turn a growing Power BI environment into a governed and operational platform that could scale safely across a highly regulated healthcare landscape.

BCT worked across both Power BI Cloud and Power BI On-Premises to design the frameworks needed to support secure data access, reliable operations, and clear accountability across the organisation.

Rather than treating governance as documentation around the platform, we built it into the platform itself — through policies, access structures, technical architecture, and operational processes designed for real-world use.

Process

BCT provided two years of on-site strategic and technical support, helping Sykehuspartner create the structure needed to operate the platform with confidence.

Governance framework

We established end-to-end governance models covering data ownership, sharing protocols, lifecycle management, and user responsibilities. The framework was designed for a decentralised organisation operating under strict regulatory obligations with multiple gates to avoid sensitive leaks or decisions affecting critical reporting.

We built hybrid-governance models for decentralized decision making to ensure speed and agility while supporting a strong and efficient management of 5.000+ reports and 250+ workspaces

Security architecture

We defined and implemented role structures, permission models, and security guidelines aligned with GDPR, Norwegian healthcare regulations, and the handling of highly sensitive health and identity data.

The security model utilized nested group security through an advanced Azure Entra ID setup with multiple layers and protocols to ensure efficient handling and management of approval flows. The system was integrated into a larger ITSM structure with a built-in reporting layer for day-to-day follow-up and administration.

Overall the approach ensured that the setup was manageable by a small and dedicated team with efficient tools, cutting months of work into a 2-day automated job.

Hybrid architecture

We designed the secure gateway integration connecting on-premises data sources with the cloud analytics environment, enabling reliable data movement without exposing sensitive information in transit. The model was built on top of a detailed network infrastructure with gated VLANs to ensure DMZ compliance for a secure gateway.

The gateway was centrally managed by the BI management team and had clear security and governance processes for ensuring a strict one-way data protocol.

Platform operations

We supported the operational setup of the platform throughout the engagement, helping ensure high availability, regulatory compliance, and service continuity across a critical national user base. We supported Sykehuspartner more than 2+ years with setup, integration, implementation and day-to-day operations of the setup after Go-live.

Results

The result was a governed, compliant, and operational Power BI platform built for national scale.

By establishing the right governance model, security architecture, and hybrid operating structure, Sykehuspartner gained a stronger foundation for healthcare data access across Norway.

This made it possible to:

  • Support 90,000 healthcare professionals through a governed analytics platform
  • Meet strict regulatory requirements for healthcare data security and access control
  • Enable secure and reliable data flow between on-premises systems and cloud analytics
  • Give teams, users, and data owners clear responsibilities across the platform
  • Strengthen long-term platform operations with a structure built to scale

More broadly, the work ensured that healthcare administrators and professionals could make faster, better-informed decisions because the infrastructure behind them was secure, stable, and operationally sound.

Running a data platform where the stakes are high?

Governance, security and operational structure aren't problems that fix themselves. If your platform is growing faster than your frameworks, we should talk.

Talk to Us About Your Project.

Danmarks Statistik

A hybrid AI architecture enabled secure search, internal chat, and direct API access

We build scalable software and AI solutions that actually work
– pragmatic, data-driven and made by real people.
Born digital. Built different.
Get in touch
info@blackcapitaltechnology.com +45 60 92 92 60
Mølleå 3-5,
9000 Aalborg
Danmark
(+45) 60 92 92 60
CVR:
DK-42380784
Turbinveien 9,
0195 Oslo
Norway
(+47) 907 00 863
Org. nr.:
NO-933435458