← anqureshi.com
DWG № AQ-B00Writing · Index

Writing

Experience-based notes on healthcare software, AI, analytics, observability, developer tools, cloud architecture, and technical leadership.

Responding to Suspected PHI Exposure

Contain access, preserve evidence, revoke credentials, assess technical scope, escalate vendors, recover safely, and hand breach decisions to authorized privacy and legal owners.

How I Moved Mackex from WordPress to a Fast Next.js Site

A practical migration note on headless WordPress, WPGraphQL, Next.js App Router, Vercel, ISR, SEO cleanup, and production cutover planning.

Secrets and Encryption-Key Management for Healthcare Applications

Store secrets, separate key roles, rotate dependencies, protect audit evidence, and recover encrypted PHI across AWS, Google Cloud, and Azure.

Healthcare SaaS Tenant Isolation and Authorization

Carry verified tenant context through databases, storage, queues, caches, jobs, administrative tools, and audit evidence.

Backup and Disaster Recovery for HIPAA Workloads

Define RPO and RTO, separate backups from replication and high availability, protect recovery points, and prove the complete restore path.

Centralized Cloud Audit Logging Across AWS, GCP, and Azure

Design complete multi-cloud audit coverage with protected retention, identity context, investigation workflows, alerts, cost controls, and verification.

Secure CI/CD for Healthcare Apps

Use workload identity, protected releases, verified provenance, isolated runners, safe migrations, and auditable recovery across AWS, GCP, and Azure.

Using Healthcare Production Data in Development and Staging

Use synthetic fixtures first, then govern any production-derived subset through transformation, expiring access, isolated refreshes, backup-aware deletion, and verification.

How to Structure AWS, GCP, and Azure for Multiple Environments

Separate AWS accounts, GCP projects, and Azure subscriptions with practical identity, network, data, delivery, observability, recovery, sandbox, and policy controls.

Using Amazon Macie for HIPAA Workloads: Finding PHI in S3

How Macie supports PHI discovery in S3, where AWS BAA requirements apply, how to protect findings, and what scanning cannot prove.

HIPAA Vendor Checklist for Analytics and Monitoring

A structured review of BAA scope, PHI data flows, product features, subprocessors, retention, security controls, integrations, and incident obligations.

Configure Sentry Without Leaking PHI

Set a no-PHI observability boundary across errors, requests, breadcrumbs, replay, logs, traces, alerts, integrations, access, and retention.

Designing Healthcare Analytics Events Without PHI

A practical event taxonomy and validation pipeline using controlled workflow state instead of patient identity or clinical content.

Mixpanel vs Google Analytics for Healthcare Apps

Compare BAA and feature scope, PHI restrictions, identifiers, consent, retention, deletion, exports, regions, and safer healthcare event design.

Sentry vs Crashlytics for Healthcare Apps: HIPAA, BAA, and PHI

A data-flow-first comparison of vendor agreements, crash data, PHI exposure, SDK controls, and the questions to answer before production use.

Best MCP Servers for Developers: Cursor, Claude Code, and Codex

A practical field guide to GitHub, Playwright, Chrome DevTools, Context7, client setup differences, security, and deciding when MCP is worth using.

Planning My First SMART on FHIR Integration

Notes from current project work on launch context, scopes, resource mapping, EHR variation, and the questions that belong in discovery.

Evaluating Healthcare AI Vendors Under HIPAA and BAA Constraints

A data-flow-first framework for evaluating BAA coverage, retention, subprocessors, security controls, model failure, and operational ownership.

AI Agents vs RAG: What's the Difference (and When You Need Both)

RAG makes a model know things. Agents make a model do things. A practical breakdown of what each solves, when to use which, and how they combine in production.

Healthcare work, anonymized. Articles draw from delivery experience without exposing clients, PHI, private systems, or confidential implementation details.