Case study · 2026
The sidecar I didn't build
The RFC proposed a ClamAV sidecar for HIPAA uploads. Managed scanning cut worker memory from 8 GB to 2 GB and monthly scanning cost by about 90%, and the quarantine policy turned out to be the real system.
Context
A customer-facing app needed to accept medical records and identity documents from claimants. HIPAA applies, files go up to 50 MB, and any public upload endpoint has to be prepared for illegal content with its own legal obligations. The RFC proposed a ClamAV sidecar in ECS plus Rekognition for image moderation.
The problem
Five questions were unanswered: what the reporting obligations actually require, how to size and run the scanner, how moderation should treat medical imagery, how much memory a worker needs to process a 50 MB file, and how long flagged files must be retained.
What I did
- Researched each question against the primary sources (federal statute, AWS docs, provider pricing) before touching the design.
- Replaced the sidecar with GuardDuty Malware Protection for S3: event-driven, tag-based results, nothing to patch.
- Built the moderation path with per-category confidence thresholds and a human-review queue, because medical images trip the same labels as explicit content.
- Split quarantine by cause: virus-positive files get a 30–90 day forensic hold; suspected illegal content gets Object Lock and a documented manual reporting process. Metadata survives the file’s deletion.
- Wired it into the existing CDK constructs — buckets, KMS keys, SQS queues, a dedicated EventBridge bus — following the repo’s own patterns, not a standalone stack.
The trade-off
Managed scanning is asynchronous, and you don’t control signature timing. In exchange, the worker no longer needs 8 GB to safely handle a 50 MB file — 2 GB is enough — and monthly scanning cost fell from roughly $70–100 to about $7. At low volume the whole addition costs about $3.43 a month, almost all of it fixed KMS fees.
Outcome
The sidecar was never built. The infrastructure is defined in CDK and the phased implementation plan is written.
What I’d do differently
Put the compliance questions in the RFC before choosing a scanner. And evaluate Google Cloud Vision SafeSearch earlier — it handles medical imagery better, even though a second cloud means a second BAA.