HIPAA & SOC 2 Architecture for Healthcare SaaS

For healthcare SaaS founders facing hospital security reviews or SOC 2 preparation: architecture built to HIPAA requirements, with documented controls.

Engineering Approach

We work with healthcare SaaS founders facing hospital security reviews or SOC 2 preparation. We design encryption, audit logging, role-based access and tenant isolation built to HIPAA requirements, then build and document the technical controls. A licensed CPA firm performs the SOC 2 examination and issues the report; Opexia itself holds no SOC 2 report. Building a healthcare app is easy; securing it to the standards required by enterprise hospital IT departments is not. We engineer Zero-Trust cloud environments across AWS and GCP — KMS database encryption, automated audit trails, and strict IAM policies — the technical controls that SOC 2 Type II auditors and hospital security risk assessments examine. We engineer the technical controls auditors test; a CPA firm issues the report. Every healthcare software company that wants to sell to hospitals eventually hits the same wall: the enterprise security questionnaire. 200+ pages of technical requirements asking whether your database is encrypted, whether you log API access, whether your employees can access production PHI, and whether you've completed a SOC 2 Type II audit. Most startups answer 'no' to half these questions, which immediately disqualifies them from hospital procurement. Even if you have good intentions around security, implementing HIPAA technical safeguards retroactively is expensive, slow, and full of architectural traps. Encrypting a production database that was built without encryption requires downtime and data migration. Adding audit logging after launch means refactoring every API endpoint. Restricting employee access to production when your entire team has been SSH'ing into servers for two years creates operational chaos. The right time to architect for HIPAA and SOC 2 compliance is day one — not after your first enterprise deal requires it. We build healthcare cloud infrastructure with Zero Trust principles from the ground up: no engineer has direct access to production databases, all PHI is encrypted at rest with AWS KMS or GCP Cloud KMS, every API request is logged with full audit trails, and IAM policies enforce least-privilege access with time-limited session tokens. The goal is infrastructure where the answers on a hospital security questionnaire are already true, and where logs and configuration history are ready to serve as evidence when a licensed CPA firm examines your controls for a SOC 2 Type II report.

Core Benefits

Built for Security Reviews
KMS Encryption
Zero-Trust Security

Technical Capabilities

  • Terraform Infrastructure as Code (IaC)
  • Automated HIPAA Audit Logging
  • AWS Enclaves & VPC Peering
  • SOC 2 Remediation Engineering

Methodology

Our cloud architecture process starts with a security requirements review: we take your target hospital's vendor security questionnaire (VSQ) and map every requirement to a specific AWS or GCP security control. We then architect the infrastructure using Terraform Infrastructure as Code, ensuring every resource is version-controlled, peer-reviewed, and reproducible. The core architecture includes: (1) VPC isolation with private subnets for application servers and databases, (2) AWS RDS or Cloud SQL with KMS encryption at rest and SSL/TLS in transit, (3) Application Load Balancers with WAF rules to block SQL injection and XSS attacks, (4) IAM roles with least-privilege access and MFA enforcement for all human users, (5) CloudTrail or Cloud Audit Logs capturing every API call, database query, and configuration change, (6) AWS Secrets Manager or GCP Secret Manager for secure credential storage (no hardcoded secrets in code), (7) AWS CloudWatch or GCP Cloud Monitoring with PagerDuty alerts for suspicious access patterns. For SOC 2 readiness, we set up continuous monitoring with tools like Vanta or Drata that collect evidence for access control, encryption, and logging controls. We also configure automated vulnerability scanning with AWS Inspector or GCP Security Command Center, plus automated patching for OS-level dependencies. For production access, we enforce session-based authentication using AWS Systems Manager Session Manager or GCP Identity-Aware Proxy (IAP) — no SSH keys, no VPN, no direct database access. Every production action is logged and requires approval via PagerDuty or Slack-based workflows. Before your first hospital security review, we recommend an independent third-party penetration test and remediate its findings. We provide documentation packages (system security plans, data flow diagrams, encryption specifications) mapped to the HIPAA Security Rule and the SOC 2 Trust Services Criteria. Post-launch, quarterly security reviews and patching are available under a retainer.

Before a first call, you can do the vendor groundwork with our free, sourced references:

Technology Stack

Terraform / AWS CDK

Infrastructure as Code for reproducible deployments

AWS RDS / Cloud SQL

Managed databases with KMS encryption at rest

AWS KMS / Cloud KMS

Customer-managed encryption keys for PHI

CloudTrail / Cloud Audit Logs

Immutable audit logs for compliance evidence

AWS WAF / Cloud Armor

Web application firewall to block attacks

Vanta / Drata

Automated SOC 2 evidence collection

AWS Inspector / Security Command Center

Continuous vulnerability scanning

Security Patterns From the CCM/PCM Platform

The CCM/PCM platform described in the case study was built with these patterns from its first release: field-level encryption of patient identifiers (MRN/FIN), audit logging, and role-based access control enforced at the API layer. When it became a multi-tenant SaaS, each organization's data moved into its own PostgreSQL schema with row-level security and tenant-scoped encryption, so isolation is enforced by the database rather than by application code alone.

Frequently Asked Questions

Common questions about hipaa & soc 2 architecture for healthcare saas

Is HIPAA compliance a one-time project or ongoing?

Ongoing. HIPAA compliance requires continuous monitoring, regular risk assessments, employee training, and patching vulnerabilities as they're discovered. Treating it as a one-time checklist is a common way to drift out of compliance. We set up automated monitoring so configuration drift is caught as your infrastructure evolves.

Do we need SOC 2 if we're already HIPAA compliant?

Usually yes, if you're selling to enterprise hospitals. HIPAA is a legal requirement for handling PHI; a SOC 2 report is an attestation, issued by a licensed CPA firm, on how your security controls are designed and operate. No certificate is issued. Hospitals use SOC 2 reports to speed up vendor security reviews; without one, expect longer and more detailed questionnaires.

How long does it take to get a SOC 2 Type II report?

A SOC 2 Type II report is an attestation issued by a licensed CPA firm after it tests how your controls operated over an observation window — commonly 3 to 12 months; the AICPA does not set a fixed minimum. No certificate is issued. The window can only start once the controls are in place and documented, so the engineering comes first. We engineer the technical controls auditors test; a CPA firm issues the report.

Can we use AWS or GCP's default encryption, or do we need KMS?

HIPAA does not require customer-managed keys. Encryption is an addressable implementation specification that names no algorithm or key type (45 CFR 164.312(a)(2)(iv)). Customer-managed keys (KMS) are good practice — they give you control over key rotation, access policies, and revocation — and security questionnaires ask about them. HHS's January 2025 proposed Security Rule update would make encryption required, but it is not final. Last reviewed 2026-09-25. Source: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312

What's the difference between encryption at rest and encryption in transit?

Encryption at rest protects data stored in databases and S3 buckets (using KMS). Encryption in transit protects data as it moves between servers, browsers, and APIs (using SSL/TLS). The HIPAA Security Rule lists both as addressable specifications, and hospital security teams expect both. Many startups forget to enforce SSL/TLS on internal API calls between services, which fails hospital audits.

Does my engineering team need to lose production access for HIPAA compliance?

Not entirely, but direct SSH/database access must be restricted. Instead, we implement session-based access via AWS Systems Manager or GCP IAP, with all actions logged and time-limited. Engineers can still troubleshoot production, but they can't extract PHI without audit trails.

What happens if we have a data breach?

HIPAA requires breach notification to affected individuals, to HHS's Office for Civil Rights (OCR), and to prominent media outlets when a breach affects more than 500 residents of a state or jurisdiction. Civil money penalties are assessed per violation, not per patient record. Amounts in effect since Jan 28, 2026 (HHS inflation adjustment, 91 FR 3665): $145 to $73,011 per violation for tiers 1–3, and $73,011 to $2,190,294 for uncorrected willful neglect, with a calendar-year cap of $2,190,294 per identical provision. The architecture we build includes breach detection (CloudTrail anomaly detection) and incident response runbooks to limit exposure. Last reviewed 2026-09-25. Source: https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment

How much does HIPAA-compliant infrastructure cost vs. standard AWS?

KMS encryption, CloudTrail logging, and VPC isolation add to baseline cloud costs; how much depends mostly on log volume and key usage, and it can be estimated from your expected traffic before you commit. For a vendor selling to hospitals, that cost is usually small next to the value of the contracts it helps you qualify for.

Ready to Discuss Your Project?

Schedule a technical consultation to discuss your specific requirements, timeline, and budget. No sales pitch—just engineering.

Or explore the engineering glossary to learn more about healthcare software terminology.

Final Step

Outgrown Your
Spreadsheets?

If your care-management operation still runs on spreadsheets and manual monthly reporting, let's talk about what a custom platform would look like.

HIPAA

Built to its requirements

Custom

Built around your workflow

Direct

Access to the team building your system