Every change that touches authentication, authorization, or PHI handling goes through a security review before merge. The review is conducted by the security team and tracked in a public-internal queue.
Reviews are sized to the change. A small change might be a thirty-minute conversation; a new service might be a multi-session review with a written report.
We also run pre-launch reviews for every new product surface, with a checklist that's updated when we learn something the hard way.
