NY Medicaid VDI Compliance Setup
Budget: $1,500 – $3,000 USD
I need to stand up a fresh, fully compliant virtual desktop interface that will satisfy New York Medicaid and Medicaid waiver program requirements from day one. Because no infrastructure exists yet, you will architect, configure, deploy, and lock down the entire VDI environment from scratch, showing clear alignment with SOC 2 Type II controls so I can demonstrate compliance to Medicaid payers and within future data-use agreements.
What matters most to me is expert handling of configuration, deployment, and especially security and access controls. Every component—from network segmentation and MFA to encryption and logging—must map cleanly to PHI tokenization policies and the broader NY Medicaid regulatory framework. A solid grasp of SOC 2 Type II evidence gathering is essential; I expect artifacts that auditors can accept without extra clarification.
Deliverables
• High-level and detailed architecture diagrams
• Configuration scripts / images for the VDI stack
• Security hardening report covering access controls, tokenization approach for PHI, and audit logging
• SOC 2 Type II control matrix showing how each control is met within the environment
• Operational runbook for ongoing maintenance and user onboarding
Acceptance criteria
• Environment spins up in a clean tenant and passes an internal penetration test
• All PHI is tokenized or otherwise protected in transit and at rest
• Documentation is complete enough for a third-party auditor to trace each SOC 2 Type II control without follow-up questions
• User login from an approved device delivers a desktop in under 15 seconds with no data leakage outside the defined perimeter
You’ll have direct access to me for swift decision-making, and I’m happy to schedule regular checkpoints to keep the build moving smoothly. If you thrive on green-field compliance projects and can translate regulations into airtight technical controls, let’s get this launched.
What matters most to me is expert handling of configuration, deployment, and especially security and access controls. Every component—from network segmentation and MFA to encryption and logging—must map cleanly to PHI tokenization policies and the broader NY Medicaid regulatory framework. A solid grasp of SOC 2 Type II evidence gathering is essential; I expect artifacts that auditors can accept without extra clarification.
Deliverables
• High-level and detailed architecture diagrams
• Configuration scripts / images for the VDI stack
• Security hardening report covering access controls, tokenization approach for PHI, and audit logging
• SOC 2 Type II control matrix showing how each control is met within the environment
• Operational runbook for ongoing maintenance and user onboarding
Acceptance criteria
• Environment spins up in a clean tenant and passes an internal penetration test
• All PHI is tokenized or otherwise protected in transit and at rest
• Documentation is complete enough for a third-party auditor to trace each SOC 2 Type II control without follow-up questions
• User login from an approved device delivers a desktop in under 15 seconds with no data leakage outside the defined perimeter
You’ll have direct access to me for swift decision-making, and I’m happy to schedule regular checkpoints to keep the build moving smoothly. If you thrive on green-field compliance projects and can translate regulations into airtight technical controls, let’s get this launched.
Related categories:
Compliance
Penetration Testing
Virtualization
Encryption
Security
Network Security
Data Protection
Architecture