// Case Study

Enhancing User Security with Google Sign-In Authentication for StarHealth

All case studies
// client engagement
Written by NextGen Coding Company Engineering Team — senior U.S.-based software engineers and solution architects
Technically reviewed by NextGen Principal Architect (AWS Certified Solutions Architect, 15+ yrs building production systems in fintech, healthcare, and tax technology)
Published Last updated

Client Background

StarHealth is a global healthcare data and analytics platform with a mission to securely connect patients, providers, and researchers. Its platform hosts over 1,000,000 doctors, 2,000 hospitals, and 450,000 clinical trials. With such scale, protecting sensitive healthcare data while ensuring smooth access for users is vital. StarHealth sought a secure, frictionless authentication system to safeguard data and enhance the user experience across its rapidly growing network.

The Problem

With increasing user demand, StarHealth needed a modern authentication solution that improved security without adding friction for end users. Legacy login systems were insufficient for protecting sensitive data and maintaining regulatory compliance. The requirements for the new solution included:

  • Secure authentication that could scale with millions of global users.

  • Integration with Google Sign-In to reduce credential management complexity.

  • Multi-device compatibility for desktop, tablet, and mobile logins.

  • Support for Single Sign-On (SSO) and Multi-Factor Authentication (MFA).

  • Encryption and tokenization of sensitive data.

  • Full compliance with HIPAA and GDPR regulations.

The challenge was balancing robust security with a seamless user experience across multiple services and devices.

Our Solution

NextGen implemented a comprehensive authentication framework powered by Google Sign-In and cloud-native security tools. The design delivered strong data protection, simplified access, and industry-grade compliance.

Google Sign-In API Integration

  • Integrated Google Identity Services API for users to log in with existing Google accounts.

  • Eliminated password fatigue and enhanced security with Google’s built-in authentication protocols.

  • Styled the login interface with Material-UI to align with StarHealth’s branding.

Single Sign-On (SSO) Across Devices

  • Enabled SSO functionality, allowing users to authenticate once and access all StarHealth services across devices.

  • Delivered consistent login sessions on desktop, tablet, and mobile platforms.

Multi-Factor Authentication (MFA)

  • Incorporated Google’s MFA features, including phone prompts and time-based one-time passwords (TOTP).

  • Strengthened defense against unauthorized access to sensitive medical and research data.

OAuth 2.0 Secure Token Exchange

  • Used OAuth 2.0 for secure authentication flows and scoped token exchanges.

  • Prevented interception risks by ensuring tokens were short-lived and role-based.

Firebase Authentication Management

  • Adopted Firebase Authentication to manage sessions, monitor activity, and verify tokens.

  • Provided administrators with dashboards to track login behavior and detect anomalies.

Encrypted Data Transmission and Storage

  • Secured credentials and session tokens with Google Cloud Key Management Service (KMS).

  • Protected data in transit and at rest with full encryption protocols.

HIPAA and GDPR Compliance

  • Built consent prompts, audit trails, and data anonymization into the login process.

  • Enabled administrators to revoke access instantly to meet regulatory demands.

  • Ensured full adherence to HIPAA and GDPR across authentication workflows.

Scalable Cloud Deployment

  • Deployed the authentication architecture on Google Cloud Platform (GCP).

Used Google Kubernetes Engine (GKE) to scale dynamically during traffic spikes, supporting thousands of concurrent logins without downtime.

Results

The Google Sign-In integration delivered measurable improvements for both StarHealth users and administrators:

  • 99.99% reduction in unauthorized access, achieved through MFA and encrypted token exchange.

  • 45% faster onboarding, as users registered and logged in with their existing Google accounts.

  • 30% increase in user retention, driven by convenience and security.

  • 100,000+ daily logins supported reliably through GKE auto-scaling.

  • 25% improvement in perceived security, reflected in user surveys after deployment.

  • Actionable insights for administrators via Firebase dashboards, enabling proactive security policy refinement.

Why It Matters

Healthcare platforms hold some of the most sensitive data in the world. Secure, compliant, and seamless authentication is not just an IT requirement — it is the foundation of user trust. By integrating Google Sign-In with MFA, OAuth 2.0, and Firebase Authentication, StarHealth set a new standard for balancing convenience with security. The project demonstrates how healthcare organizations can adopt scalable cloud solutions to protect sensitive data, satisfy regulatory mandates, and deliver user-friendly experiences at enterprise scale.

Call to Action

Healthcare organizations that modernize authentication frameworks reduce security risks, streamline onboarding, and improve patient and provider trust. NextGen designs authentication systems that are scalable, compliant, and user-centric.

→ Book a consultation with NextGen https://nextgencodingcompany.com/contact

Contact admin@nextgencodingcompany.com or book a call to speak with our solutions team to begin scoping https://calendly.com/next_gen_coding_company/30min

// case study faq

Frequently asked questions

What did NextGen actually build in this engagement?
NextGen designed and shipped a production system end to end: architecture, data model, application code, integrations, security review, and deployment. A senior U.S.-based team owned delivery from discovery through launch, and the client kept full ownership of the codebase and cloud accounts.
How long does an engagement like this take?
Most engagements of this shape run eight to sixteen weeks from kickoff to production. A discovery and architecture sprint takes two to three weeks, the first working release lands around week six, and the remaining time covers hardening, integrations, and rollout support.
What technologies were used?
This engagement was delivered with Google Auth, Next.js. A senior U.S.-based team owned the architecture and the implementation, and the client kept full ownership of the codebase and cloud accounts.
Can NextGen deliver a similar outcome for us?
Yes. We start with a paid discovery sprint that produces an architecture, a scope, and a fixed price or a staffed team plan. From there you can proceed with a fixed-scope build or a dedicated team. Book a call and we will scope your project against this case study.
// let's build something

Start your project request

Tell us what you're building — engineering capacity, AI, QA, cloud, or a fixed-scope software engagement. Our NYC team responds within one business day.

// what to expect
  • Response within 1 business day
  • 30-minute discovery conversation
  • Recommended engagement model & pricing
  • NYC-focused — in-person available
Start Project Request

Inbound sales only. All form information is encrypted in transit.