TechStack
Security & HIPAA compliance

Patient data treated like it's our own.

HIPAA-compliant infrastructure across the platform. AES-256 encryption at rest. TLS 1.3 in transit. Audit-logged access with 7-year retention. Every covered entity signs an executed BAA before any patient data moves. Our standard isn't "compliant enough" — it's compliant by architecture.

AES-256 at rest
Encrypted database
TLS 1.3 in transit
End-to-end
MFA required
All privileged access
7-year audit log
HIPAA-standard retention
US-only storage
AWS us-east-2
The six pillars

What HIPAA compliance actually looks like.

Six structural commitments. Each one a property of how the platform is built — not a checkbox or a policy document.

01

Encryption everywhere

PHI encrypted at rest with AES-256 (Supabase-managed keys, AWS KMS). All transit secured with TLS 1.3. Database connections require certificate validation. Backups encrypted at the same standard, with 30-day retention.

02

Access control

Role-based access control across the platform. MFA required for all privileged accounts (engineering, support, ops). Customer practice accounts get per-practice data isolation through Row-Level Security policies. Cross-practice access is architecturally impossible.

03

Audit logging

Every PHI access logged with timestamp, user ID, practice ID, action type, before/after state, and IP address. 7-year retention (HIPAA standard). Logs are immutable. Practice owners can request a complete access export at any time.

04

BAA before data moves

No exceptions. Every covered entity signs an executed BAA with TechStack LLC before any patient data leaves their system. We don't use click-through BAAs. State-level attachments added when applicable (CMIA, HB 300, SHIELD). Counter-signed copies return within two business days.

05

Breach notification, 72 hours

Incident response runbook reviewed quarterly, tested annually. Breach discovery triggers notification to affected covered entities within 72 hours with full disclosure: nature, scope, PHI types, remediation taken, recommended response. Subprocessor breaches treated identically.

06

Subprocessor discipline

Every subprocessor that touches PHI carries a signed BAA: Supabase (database + auth), Twilio (SMS, HIPAA program enrollment in progress), and Mailgun (email, HIPAA tier with BAA execution in progress). All run on HIPAA-compliant infrastructure tiers. 30-day notice before any new subprocessor that touches PHI is added.

Infrastructure stack

Where your data actually lives.

Full subprocessor list with their compliance posture and BAA status.

Subprocessor Function Location BAA SOC 2
Supabase Postgres database + auth + storage (PHI) AWS us-east-2 (Virginia) in progress Type II
Twilio SMS messaging — patient outreach (PHI) AWS us-east-1 + multi-region in progress Type II
Mailgun Transactional email — patient outreach (PHI) AWS us-east-1 in progress Type II
AWS us-east-2 Underlying cloud infrastructure (PHI) Virginia, USA Type II
GoHighLevel Sales demo booking + prospect intake (PII only) AWS us-east-1 PII only · BAA not required Type II
Hostinger VPS Static marketing site (no PHI / no PII) AWS-backed, US-East no PHI n/a
Cloudflare DNS + CDN for static assets (no PHI / no PII) Global edge no PHI Type II
We give 30-day notice before adding any new subprocessor that touches PHI.
Compliance roadmap

What's live · what's next.

Live

HIPAA Privacy + Security Rules

Full compliance with the HIPAA Privacy and Security rules across all platform operations. BAA execution standard, AES-256 + TLS 1.3 encryption, audit logging, breach notification runbook.

Live

Subprocessor BAAs

Subprocessor BAAs in progress with Supabase, Twilio, and Mailgun (HIPAA tiers); AWS BAA executed. All run on SOC 2 Type II-certified infrastructure. 30-day change notice policy.

Q4 2026

SOC 2 Type II audit

Active engagement with audit firm. Type II observation period in progress (covers 6 months of controls in operation). Target attestation: Q4 2026.

Q1 2027

Penetration testing program

Annual third-party penetration testing on production infrastructure. Results available under NDA. First engagement scheduled for early 2027.

Q2 2027

HITRUST CSF certification

Healthcare-specific certification on top of HIPAA. Targeted for late-2027. Required by some large dental groups and specialty medical health systems.

Ongoing

Internal security reviews

Quarterly access reviews, runbook drills, and threat model updates. Continuous monitoring of subprocessor compliance certificates.

Security FAQ

The questions every privacy officer asks.

01 Is TechStack HIPAA compliant?
+
Yes. TechStack operates a HIPAA-compliant infrastructure across the platform. All PHI is encrypted at rest with AES-256 and in transit with TLS 1.3. Access is role-based, MFA-required for privileged accounts, and audit-logged with 7-year retention. We sign a Business Associate Agreement (BAA) with every healthcare-covered customer before any patient data moves.
02 When do you sign the BAA?
+
Before any patient data leaves your system. We don't use click-through BAAs. Every covered entity signs an executed, dated agreement with TechStack LLC; counter-signed copies return within two business days. State-level attachments (California CMIA, Texas HB 300, New York SHIELD, etc.) are added when applicable to your jurisdiction.
03 What is your subprocessor compliance posture?
+
Subprocessors that touch PHI: Supabase (Postgres + auth, AWS us-east-2 HIPAA-compliant tier), Twilio (HIPAA program enrollment), and Mailgun (HIPAA-eligible transactional email tier) — BAA execution is in progress on each as we transition our infrastructure to HIPAA-aligned tiers. Subprocessors that touch PII only (no PHI): GoHighLevel for sales demo booking and prospect lead intake (HighLevel maintains SOC 2 Type II; BAA not required because no patient data flows through this surface). Subprocessors that touch neither PHI nor PII: Hostinger (static marketing site) and Cloudflare (DNS + CDN). We provide 30-day notice before adding any new subprocessor that touches PHI.
04 What happens if there's a breach?
+
We notify the covered entity within 72 hours of breach discovery. Notification includes: nature of the breach, individuals affected, types of PHI involved, remediation actions taken, and recommended response steps. Our incident response runbook is reviewed quarterly and tested annually.
05 Is your infrastructure SOC 2 compliant?
+
SOC 2 Type II is on the roadmap for 2026. Our infrastructure runs on SOC 2 Type II-certified vendors today (Supabase, AWS us-east-2, Twilio, Mailgun, GoHighLevel). We can provide our subprocessor compliance certificates on request as part of the security questionnaire process.
06 Can patients exercise their HIPAA rights through TechStack?
+
Yes. Patient requests for access, amendment, accounting of disclosures, restriction, or right-to-erasure are processed within HIPAA-required timeframes (30-60 days depending on request type). Requests are routed to the covered entity for clinical authorization, then fulfilled programmatically through the practice's dashboard or via direct support.
07 Where is patient data stored?
+
Primary storage: Supabase Postgres in AWS us-east-2 (Northern Virginia), HIPAA-compliant tier. Backups: encrypted daily, 30-day retention. SMS message bodies: ephemeral on Twilio's HIPAA-compliant infrastructure. Email message bodies: ephemeral on Mailgun (HIPAA-eligible tier, BAA execution in progress). No PHI is stored outside the United States.

Want our complete security questionnaire?

We respond to standard vendor security questionnaires (CAIQ, SIG, HECVAT) and can provide subprocessor compliance certificates under NDA. Most practice IT directors or privacy officers complete their review in under a week with our materials in hand.

Want to walk the security posture with our team?

15-minute call with a real engineer. We'll answer subprocessor questions, BAA timing, breach response, and anything your privacy officer flagged. No sales handoff.

15 minutes · no sales pitch Works with your booking platform HIPAA · BAA available