HIPAAmart

Technology Guides

Technology choices need a compliance context.

Evaluate the services, data flows, contracts, settings, and evidence around systems that handle ePHI.

Reviewed August 2026

Available guidance

  • AWS and HIPAA

    A service-specific starting point for reviewing AWS workloads, shared responsibility, BAA scope, identity, logging, and recovery.

  • Microsoft Azure and HIPAA

    A practical review frame for Azure services, identity, monitoring, encryption, and shared responsibility.

  • Google Cloud and HIPAA

    How to evaluate Google Cloud services, configurations, access, logging, and recovery for workloads involving ePHI.

  • SaaS and HIPAA

    Evaluate hosted applications through data flows, support, retention, identity, subprocessors, and the actual service contract.

  • Generative AI and HIPAA

    A focused review of prompts, outputs, model providers, retention, RAG, human review, and PHI leakage.

  • APIs and HIPAA

    Protect PHI at the boundaries where applications authenticate, transmit, log, transform, and authorize data.

  • Email and HIPAA

    A workflow-based guide to email, PHI, patient requests, misdirection, encryption decisions, and vendor responsibilities.

  • Backup and HIPAA

    Evaluate backup confidentiality, integrity, availability, retention, access, and restoration evidence.

  • Identity Management and HIPAA

    Use lifecycle, privilege, authentication, service-account, and access-review practices to protect ePHI.