<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Writing by Assad Nadeem Qureshi</title>
    <link>https://anqureshi.com/blog</link>
    <description>Practical notes on healthcare software, cloud architecture, AI, analytics, observability, and developer tools.</description>
    <language>en</language>
    <atom:link href="https://anqureshi.com/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Thu, 13 Aug 2026 00:00:00 +0500</lastBuildDate>
    <item>
      <title>Responding to Suspected PHI Exposure</title>
      <link>https://anqureshi.com/blog/responding-to-suspected-phi-exposure</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/responding-to-suspected-phi-exposure</guid>
      <description>A practical engineering playbook for containment, evidence, access revocation, scope assessment, vendor escalation, recovery, and safer follow-up.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Secrets and Encryption-Key Management for Healthcare Applications</title>
      <link>https://anqureshi.com/blog/secrets-encryption-key-management-healthcare</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/secrets-encryption-key-management-healthcare</guid>
      <description>A practical operating model for storing secrets, separating keys, rotating credentials, controlling access, and recovering encrypted healthcare workloads.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>How I Moved Mackex from WordPress to a Fast Next.js Site</title>
      <link>https://anqureshi.com/blog/mackex-wordpress-to-nextjs-performance</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/mackex-wordpress-to-nextjs-performance</guid>
      <description>A practical case study of rebuilding Mackex Services from a WordPress theme into a fast Next.js App Router site backed by WordPress, WPGraphQL, ISR, Vercel, and SEO cleanup.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Backup and Disaster Recovery for HIPAA Workloads</title>
      <link>https://anqureshi.com/blog/hipaa-backup-disaster-recovery</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/hipaa-backup-disaster-recovery</guid>
      <description>A practical guide to backup and disaster recovery for HIPAA workloads, including recovery objectives, immutable storage, provider controls, BAAs, PHI, and restoration testing.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Healthcare SaaS Tenant Isolation and Authorization</title>
      <link>https://anqureshi.com/blog/healthcare-saas-tenant-isolation</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/healthcare-saas-tenant-isolation</guid>
      <description>A practical guide to tenant isolation and authorization for healthcare SaaS, including identity, data, storage, queues, caches, background jobs, audit logs, emergency access, and isolation testing.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Planning My First SMART on FHIR Integration</title>
      <link>https://anqureshi.com/blog/smart-on-fhir-integration</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/smart-on-fhir-integration</guid>
      <description>Notes from planning a first SMART on FHIR R4 integration and the architecture and product questions involved.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Sentry vs Crashlytics for Healthcare Apps: HIPAA, BAA, and PHI</title>
      <link>https://anqureshi.com/blog/sentry-vs-crashlytics-healthcare</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/sentry-vs-crashlytics-healthcare</guid>
      <description>A data-flow-first comparison of Sentry and Firebase Crashlytics for healthcare applications, including BAA availability, PHI risks, configuration, and vendor review.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Secure CI/CD for Healthcare Apps Across AWS, GCP, and Azure</title>
      <link>https://anqureshi.com/blog/secure-cicd-healthcare-apps-aws-gcp-azure</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/secure-cicd-healthcare-apps-aws-gcp-azure</guid>
      <description>A practical healthcare CI/CD model using workload identity, protected releases, verified provenance, isolated runners, safe migrations, and audit evidence.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Using Healthcare Production Data in Development and Staging</title>
      <link>https://anqureshi.com/blog/production-data-development-staging-hipaa</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/production-data-development-staging-hipaa</guid>
      <description>A practical workflow for healthcare test data covering synthetic fixtures, de-identification limits, governed subsets, controlled debugging, access expiry, refreshes, backups, and verified deletion.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>How to Structure AWS, GCP, and Azure for Development, Staging, and Production</title>
      <link>https://anqureshi.com/blog/multi-environment-cloud-architecture-aws-gcp-azure</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/multi-environment-cloud-architecture-aws-gcp-azure</guid>
      <description>A practical guide to separating development, staging, and production across AWS accounts, GCP projects, and Azure subscriptions, including identity, networks, data, delivery, backups, and governance.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Mixpanel vs Google Analytics for Healthcare Apps: HIPAA, BAA, and PHI</title>
      <link>https://anqureshi.com/blog/mixpanel-vs-google-analytics-healthcare</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/mixpanel-vs-google-analytics-healthcare</guid>
      <description>A practical comparison of Mixpanel and Google Analytics for healthcare apps across BAA scope, PHI restrictions, identifiers, consent, retention, deletion, exports, and regions.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>HIPAA Vendor Checklist for Analytics and Monitoring Tools</title>
      <link>https://anqureshi.com/blog/hipaa-vendor-checklist-analytics-monitoring</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/hipaa-vendor-checklist-analytics-monitoring</guid>
      <description>A practical checklist for evaluating BAA scope, PHI data flow, subprocessors, retention, security, access, and incident obligations for analytics and monitoring vendors.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Designing Healthcare Analytics Events Without PHI</title>
      <link>https://anqureshi.com/blog/healthcare-analytics-without-phi</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/healthcare-analytics-without-phi</guid>
      <description>A practical event taxonomy and validation pattern for healthcare applications that minimizes the risk of exposing protected health information.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Evaluating Healthcare AI Vendors Under HIPAA and BAA Constraints</title>
      <link>https://anqureshi.com/blog/healthcare-ai-vendor-selection</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/healthcare-ai-vendor-selection</guid>
      <description>A practical engineering framework for evaluating AI services that may create, receive, maintain, or transmit protected health information.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Configure Sentry Without Leaking PHI in Healthcare Apps</title>
      <link>https://anqureshi.com/blog/configure-sentry-without-phi</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/configure-sentry-without-phi</guid>
      <description>A practical Sentry configuration guide for reducing PHI exposure across errors, requests, breadcrumbs, replay, logs, traces, alerts, and integrations.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Centralized Cloud Audit Logging Across AWS, GCP, and Azure</title>
      <link>https://anqureshi.com/blog/centralized-cloud-audit-logging-aws-gcp-azure</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/centralized-cloud-audit-logging-aws-gcp-azure</guid>
      <description>A practical multi-cloud design for complete audit coverage, protected retention, investigation, alerting, cost control, and verification.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Best MCP Servers for Developers: Cursor, Claude Code, and Codex</title>
      <link>https://anqureshi.com/blog/best-mcp-servers-for-developers</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/best-mcp-servers-for-developers</guid>
      <description>A practical guide to useful MCP servers for Cursor, Claude Code, and Codex, including GitHub, Playwright, Context7, Serena, security, and setup choices.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>Using Amazon Macie for HIPAA Workloads: Finding PHI in Amazon S3</title>
      <link>https://anqureshi.com/blog/amazon-macie-hipaa-phi-s3</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/amazon-macie-hipaa-phi-s3</guid>
      <description>A practical architecture guide to using Amazon Macie to discover possible PHI in Amazon S3 while accounting for AWS BAA requirements, findings, remediation, and coverage limits.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Wed, 22 Jul 2026 00:00:00 +0500</pubDate>
    </item>
    <item>
      <title>AI Agents vs RAG: What's the Difference (and When You Need Both)</title>
      <link>https://anqureshi.com/blog/ai-agents-vs-rag</link>
      <guid isPermaLink="true">https://anqureshi.com/blog/ai-agents-vs-rag</guid>
      <description>A practical breakdown of what each actually does, when to use which, and how they combine in production.</description>
      <dc:creator>Assad Nadeem Qureshi</dc:creator>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0500</pubDate>
    </item>
  </channel>
</rss>
