Home › Services › Healthcare and life sciences
Industry · Healthcare and life sciences
Clinics accumulated one tenant per practice. Patient data under retention rules. Environments that a client’s security review will inspect before a contract is signed. We have done the seventeen-into-one consolidation and built the locked-down Azure environment.
Healthcare groups have a specific history: each clinic or practice set up its own Microsoft 365 tenant, usually by whoever happened to be handling IT at that site. A group of a dozen practices has a dozen tenants, none of them talking to the others, and a licensing bill that pays for the same person several times over.
The data is regulated. Mailboxes and sites holding patient information sit under retention policies or legal hold, and holds are tenant configuration, not data — they have to be recreated in the target before anything moves, with compliance sign-off for each. Data residency rules may require that a country’s patient data stays in that country’s tenant.
And in life sciences the buyer’s own clients run security reviews. An environment that handles protected health information has to pass someone else’s audit before a contract is signed — which changes how it is built, not just how it is described.
What we see in this sector
Not a list of features. The things that actually change scope, sequence and price when the client is in healthcare and life sciences.
Our largest consolidation was seventeen healthcare tenants into one, for a group of clinics in Australia. It was also our first at that scale, and it taught us to script everything: the write-up says what went slowly and why.
Anything under litigation hold or a retention policy is inventoried during discovery and does not move without compliance sign-off. A mailbox on hold keeps its contents after the licence is removed, which changes how leavers are handled.
For a healthcare consulting firm launching a software product, we built an Azure environment designed to accept protected health information and pass the clients’ security reviews. Their founder’s account of it is on this site.
Reception, appointments, referrals, on-call: healthcare runs on shared mailboxes with delegate access. They are recreated, not copied, and the permission map is the first document we produce.
Yes, if the retention policies and holds are recreated in the target tenant before the data moves, and compliance signs off on each item under hold. Migrating data into a tenant where the hold does not yet exist is the mistake to avoid, and discovery is where it is caught.
No, and we say so on the verification page rather than hoping nobody asks. Where a procurement process requires one from the supplier, we do not qualify. Where it requires the environment to pass a security review, we have built environments that did.
Often yes, by regulation. Data residency is confirmed per entity during discovery, and the target architecture can keep each country’s data in its own tenant while consolidating identity and licensing. That is a design decision, made before anything moves.
Put the mailbox on hold before removing the licence. It becomes an inactive mailbox: invisible in the address book, costing nothing, searchable through eDiscovery for as long as the hold lasts. Remove the licence first and it is deleted after the grace period, hold or no hold.
Three months for roughly 500 users. It was our first at that scale and we did too much by hand; the process was rebuilt around PowerShell afterwards, which is why the thousand-user consolidation that followed moved faster at twice the size.
Scoping costs nothing
Tenant count, rough headcount, which countries, and what is driving the date. You get back a sequence, an honest view of what will be slow, and a fixed price — usually within one business day.