Start before architecture hardens
This checklist is for early technical discovery, product due diligence, and pre-build review. It helps a team find the software decisions that will affect PHI handling, vendor scope, cloud architecture, AI, analytics, monitoring, delivery, and operational evidence.
Source basis: HHS guidance on the HIPAA Security Rule, its Security Rule summary, and covered entities and business associates.
Readiness review
1. Covered workflow
Identify whether the product supports care, payment, operations, clinical documentation, patient communication, insurance, provider workflows, or another healthcare function.
2. PHI data map
List where PHI is created, received, maintained, transmitted, transformed, exported, deleted, logged, backed up, or viewed by support users.
3. Vendor and BAA scope
Review cloud, email, SMS, AI, analytics, monitoring, storage, search, support, video, and data-processing vendors for BAA availability and covered features.
4. Identity and roles
Define patient, clinician, staff, admin, support, service-account, and emergency-access roles with least-privilege permissions and reviewable access history.
5. Tenant and account boundaries
Decide how organizations, clinics, practices, departments, patients, and internal users are separated across application data, storage, queues, caches, and jobs.
6. Environments
Separate development, staging, and production. Prefer synthetic data outside production, and govern any production-derived subset with access limits and expiry.
7. Encryption and secrets
Check transport security, encryption at rest, key ownership, secret storage, rotation, workload identity, break-glass access, and recovery paths.
8. Audit evidence
Capture meaningful access, administrative, deployment, data-change, vendor, and support events without placing unnecessary PHI into logs.
9. Analytics and monitoring
Design allowlisted event names and technical identifiers. Review URLs, breadcrumbs, stack traces, replay tools, exports, alerts, and integrations for PHI leakage.
10. AI and automation
Map prompts, files, transcripts, embeddings, logs, model retention, subprocessors, human review, failure modes, and whether the AI service is covered by the right agreement.
11. Backup and recovery
Set recovery objectives, protect backup access, test restore paths, document retention, and verify deletion expectations across derived and backup copies.
12. Delivery readiness
Review CI/CD permissions, protected releases, artifact provenance, dependency scanning, database migrations, rollback plans, and emergency deployment ownership.
What to document before building
- What data is in scope? Write down the specific PHI categories, files, identifiers, events, and derived data the product may handle.
- Who is responsible? Assign product, engineering, security, privacy, legal, support, and vendor-review owners before launch pressure arrives.
- Which vendors can receive what? Record approved services, covered features, retention settings, subprocessors, and data that must never be sent.
- What evidence proves the controls? Define the audit trails, access reviews, restore tests, incident runbooks, release records, and deletion checks you expect to see later.
- What remains unresolved? Keep a risk register for legal review, architecture decisions, vendor gaps, manual workflows, and post-launch controls.
Go deeper
HIPAA-compliant app development
How I think about the engineering side of HIPAA-aware healthcare software delivery.
Production data in staging
How to avoid casual PHI movement into development and QA workflows.
Configure Sentry without PHI
Practical controls for error monitoring, traces, replays, alerts, and integrations.
Vendor checklist
Questions to ask analytics and monitoring vendors before healthcare data can reach them.
Want a technical review?
Send the workflow, current stack, vendors, integrations, and the biggest risk you already see. I can help turn this checklist into a practical architecture and delivery plan.
Please do not send PHI, patient records, credentials, keys, screenshots containing patient data, or incident evidence by email.