Patient data treated like it's our own.
HIPAA-compliant infrastructure across the platform. AES-256 encryption at rest. TLS 1.3 in transit. Audit-logged access with 7-year retention. Every covered entity signs an executed BAA before any patient data moves. Our standard isn't "compliant enough" — it's compliant by architecture.
What HIPAA compliance actually looks like.
Six structural commitments. Each one a property of how the platform is built — not a checkbox or a policy document.
Encryption everywhere
PHI encrypted at rest with AES-256 (Supabase-managed keys, AWS KMS). All transit secured with TLS 1.3. Database connections require certificate validation. Backups encrypted at the same standard, with 30-day retention.
Access control
Role-based access control across the platform. MFA required for all privileged accounts (engineering, support, ops). Customer practice accounts get per-practice data isolation through Row-Level Security policies. Cross-practice access is architecturally impossible.
Audit logging
Every PHI access logged with timestamp, user ID, practice ID, action type, before/after state, and IP address. 7-year retention (HIPAA standard). Logs are immutable. Practice owners can request a complete access export at any time.
BAA before data moves
No exceptions. Every covered entity signs an executed BAA with TechStack LLC before any patient data leaves their system. We don't use click-through BAAs. State-level attachments added when applicable (CMIA, HB 300, SHIELD). Counter-signed copies return within two business days.
Breach notification, 72 hours
Incident response runbook reviewed quarterly, tested annually. Breach discovery triggers notification to affected covered entities within 72 hours with full disclosure: nature, scope, PHI types, remediation taken, recommended response. Subprocessor breaches treated identically.
Subprocessor discipline
Every subprocessor that touches PHI carries a signed BAA: Supabase (database + auth), Twilio (SMS, HIPAA program enrollment in progress), and Mailgun (email, HIPAA tier with BAA execution in progress). All run on HIPAA-compliant infrastructure tiers. 30-day notice before any new subprocessor that touches PHI is added.
Where your data actually lives.
Full subprocessor list with their compliance posture and BAA status.
| Subprocessor | Function | Location | BAA | SOC 2 |
|---|---|---|---|---|
| Supabase | Postgres database + auth + storage (PHI) | AWS us-east-2 (Virginia) | in progress | Type II |
| Twilio | SMS messaging — patient outreach (PHI) | AWS us-east-1 + multi-region | in progress | Type II |
| Mailgun | Transactional email — patient outreach (PHI) | AWS us-east-1 | in progress | Type II |
| AWS us-east-2 | Underlying cloud infrastructure (PHI) | Virginia, USA | ✓ | Type II |
| GoHighLevel | Sales demo booking + prospect intake (PII only) | AWS us-east-1 | PII only · BAA not required | Type II |
| Hostinger VPS | Static marketing site (no PHI / no PII) | AWS-backed, US-East | no PHI | n/a |
| Cloudflare | DNS + CDN for static assets (no PHI / no PII) | Global edge | no PHI | Type II |
What's live · what's next.
HIPAA Privacy + Security Rules
Full compliance with the HIPAA Privacy and Security rules across all platform operations. BAA execution standard, AES-256 + TLS 1.3 encryption, audit logging, breach notification runbook.
Subprocessor BAAs
Subprocessor BAAs in progress with Supabase, Twilio, and Mailgun (HIPAA tiers); AWS BAA executed. All run on SOC 2 Type II-certified infrastructure. 30-day change notice policy.
SOC 2 Type II audit
Active engagement with audit firm. Type II observation period in progress (covers 6 months of controls in operation). Target attestation: Q4 2026.
Penetration testing program
Annual third-party penetration testing on production infrastructure. Results available under NDA. First engagement scheduled for early 2027.
HITRUST CSF certification
Healthcare-specific certification on top of HIPAA. Targeted for late-2027. Required by some large dental groups and specialty medical health systems.
Internal security reviews
Quarterly access reviews, runbook drills, and threat model updates. Continuous monitoring of subprocessor compliance certificates.
The questions every privacy officer asks.
01 Is TechStack HIPAA compliant? +
02 When do you sign the BAA? +
03 What is your subprocessor compliance posture? +
04 What happens if there's a breach? +
05 Is your infrastructure SOC 2 compliant? +
06 Can patients exercise their HIPAA rights through TechStack? +
07 Where is patient data stored? +
Want our complete security questionnaire?
We respond to standard vendor security questionnaires (CAIQ, SIG, HECVAT) and can provide subprocessor compliance certificates under NDA. Most practice IT directors or privacy officers complete their review in under a week with our materials in hand.
Want to walk the security posture with our team?
15-minute call with a real engineer. We'll answer subprocessor questions, BAA timing, breach response, and anything your privacy officer flagged. No sales handoff.