As-Planned vs As-Built Analysis: Building a Platform That Survives Cross-Examination

Most as-planned vs as-built analysis compares the baseline to the last P6 update and calls the result an as-built. It isn't one. This is how to build the data layer underneath a delay analysis: versioned XER ingestion, activity identity across renumbering, a first-appearance table that proves when every actual date entered the record, calendar-safe float, and record linking that proposes candidates instead of asserting cause.

Continue ReadingAs-Planned vs As-Built Analysis: Building a Platform That Survives Cross-Examination

Build a Secure AI Medical Assistant on AWS: The Boundaries That Actually Leak

A practical architecture for a secure AI medical assistant on AWS, organised by the boundary the data crosses: the input box, your own invocation logs, cross-Region inference routing, the retrieval index, and clinical accuracy. Includes real commands, the failure modes that stay invisible until an audit, and the trade-offs worth knowing before you build.

Continue ReadingBuild a Secure AI Medical Assistant on AWS: The Boundaries That Actually Leak

HIPAA Compliance on AWS: The Gaps That Pass Every Security Check

A working engineer's guide to HIPAA compliance on AWS, organised by the gap between the control you configured and the obligation you actually carry. Covers BAA account scope, the eligible services list as a contract boundary, KMS key policy versus the encryption checkbox, what "six years" really applies to, backup and restore scope, and the subprocessor chain nobody inventories.

Continue ReadingHIPAA Compliance on AWS: The Gaps That Pass Every Security Check