Securing a Web Platform with AWS WAF
Discover how we strengthened the cybersecurity of a healthcare web platform, automating threat mitigation and securing patient data.

Our Customer
Healthera is a digital healthcare platform that enables patients in the UK to manage their prescriptions, medications, and health services in one place on the web.
For pharmacies and healthcare providers, Healthera helps future-proof their services in a world where patients expect digital-first solutions, reduces administrative burden, and drives business growth.
The Challenges
Addressing Cybersecurity Risks in a Data-Sensitive Web Platform
As a client’s platform handling a vast amount of sensitive medical data and patient transactions, it faced growing cybersecurity risks that threatened data security, application performance, and availability.
Key challenges which customer faced included:
- Frequent Bot Attacks
The platform experienced a surge in automated login attempts, raising concerns about credential stuffing and unauthorized account takeovers. - Web App Vulnerabilities
The evolving cyber threat landscape increased the platform’s exposure to SQL injection (SQLi) and cross-site scripting (XSS) attacks. These emerging threats heightened the likelihood of data breaches and unauthorized access. - Access Control Issues
The app also required strict whitelisting and blocking policies to prevent unauthorized users from accessing sensitive executive and transactional data.
THE SOLUTION
Comprehensive Security with Automated Threat Prevention and Access Control
To fortify the website and ensure its compliance, we implemented AWS Web Application Firewall with a combination of managed and custom security rules, specifically:
Multi-Layered Web Protection with AWS WAF
- Bot Control
Prevented malicious bot traffic while ensuring uninterrupted access for legitimate users. - AWS Core Rule Set (CRS)
Protection against SQL injection, XSS, and PHP-specific vulnerabilities commonly exploited in healthcare platforms. - Managed Rules for WordPress
Blocked request patterns targeting WP vulnerabilities, ensuring security for the site’s content management system. - IP Reputation Lists
Automatically blocked traffic from known malicious IPs, reducing exposure to botnets and attack networks. - Rate-Based Rules
Limited excessive requests per IP, protecting against credential stuffing, brute-force attacks, and DoS attempts. - IP Whitelisting
Ensured that only trusted IP addresses could access sensitive administrative areas, strengthening access control.
AWS Integrations for Security and Performance
To enhance both security and system performance, AWS WAF was integrated with the following AWS services for edge-level filtering and real-time monitoring:
- Amazon CloudFront
Applied security rules at the CDN edge, blocking threats before they could reach the origin server, reducing latency and server load. - Amazon CloudWatch
Provided real-time threat monitoring and traffic analysis, enabling data-driven security adjustments.
Automation and Continuous Refining
A combination of AWS Managed Rule Groups and rate-based rules delivers ongoing protection by automatically updating defenses against the OWASP Top 10 threats, malicious IPs, SQL injection attacks, PHP-specific vulnerabilities, and bot activity. These rules adapt to emerging security risks, significantly reducing the need for manual intervention.
By leveraging AWS WAF Managed Rule Groups, we ensure security policies remain consistently aligned with the latest threat intelligence, strengthening the overall resilience of your applications against web attacks.
Amazon Web Services Utilized
The Results
Reduced Cyber Threats and Enhanced Platform Reliability
By implementing AWS Web Application Firewall, we helped the client’s web platform significantly enhance its security posture, streamline operations, improve application performance, and reduce operational overhead.
Key achievements in details:
- Reduction in Malicious Traffic
Strengthened protection against SQL injection, XSS, and automated attacks, ensuring data comprehensive security. - Lower Infrastructure Costs
Rate-limiting and request filtering optimized server load, reducing unnecessary compute cloud resource consumption. - Increase in Application Uptime
Eliminating bot traffic and malicious requests improved platform availability and response times for legitimate real users. - Faster Security Incident Response
Automated threat mitigation minimized manual intervention, allowing IT engineering to focus on critical tasks, thus lowering administrative workload. - Compliance and Access Control
IP whitelisting and request blocking policies ensured strict security compliance and controlled system access.
Why Romexsoft
Enhance Your Cybersecurity with Our Web Application Security Solutions
Romexsoft is an AWS-certified Consulting Partner, trusted Software Development Company and Managed Service Provider, founded in 2004. We help customer-centric companies build, run, and optimize their cloud systems on AWS with creative, stable, and cost-efficient solutions.
Our key values:
- Delivery of quality solutions
- Customer satisfaction
- Long-term partnership
We have successfully delivered 100+ projects and have a proven track record in FinTech, HealthCare, AdTech, and Media industries.
Romexsoft possesses a 5-star rating on Clutch due to its strong expertise, responsiveness, and commitment. 60% of our clients have been working with us for over 4 years.