HIPAA & SOC 2 Architecture for Healthcare SaaS
For healthcare SaaS founders facing hospital security reviews or SOC 2 preparation: architecture built to HIPAA requirements, with documented controls.
Engineering Approach
We work with healthcare SaaS founders facing hospital security reviews or SOC 2 preparation. We design encryption, audit logging, role-based access and tenant isolation built to HIPAA requirements, then build and document the technical controls. A licensed CPA firm performs the SOC 2 examination and issues the report; Opexia itself holds no SOC 2 report. Building a healthcare app is easy; securing it to the standards required by enterprise hospital IT departments is not. We engineer Zero-Trust cloud environments across AWS and GCP — KMS database encryption, automated audit trails, and strict IAM policies — the technical controls that SOC 2 Type II auditors and hospital security risk assessments examine. We engineer the technical controls auditors test; a CPA firm issues the report. Every healthcare software company that wants to sell to hospitals eventually hits the same wall: the enterprise security questionnaire. 200+ pages of technical requirements asking whether your database is encrypted, whether you log API access, whether your employees can access production PHI, and whether you've completed a SOC 2 Type II audit. Most startups answer 'no' to half these questions, which immediately disqualifies them from hospital procurement. Even if you have good intentions around security, implementing HIPAA technical safeguards retroactively is expensive, slow, and full of architectural traps. Encrypting a production database that was built without encryption requires downtime and data migration. Adding audit logging after launch means refactoring every API endpoint. Restricting employee access to production when your entire team has been SSH'ing into servers for two years creates operational chaos. The right time to architect for HIPAA and SOC 2 compliance is day one — not after your first enterprise deal requires it. We build healthcare cloud infrastructure with Zero Trust principles from the ground up: no engineer has direct access to production databases, all PHI is encrypted at rest with AWS KMS or GCP Cloud KMS, every API request is logged with full audit trails, and IAM policies enforce least-privilege access with time-limited session tokens. The goal is infrastructure where the answers on a hospital security questionnaire are already true, and where logs and configuration history are ready to serve as evidence when a licensed CPA firm examines your controls for a SOC 2 Type II report.
Core Benefits
Technical Capabilities
- Terraform Infrastructure as Code (IaC)
- Automated HIPAA Audit Logging
- AWS Enclaves & VPC Peering
- SOC 2 Remediation Engineering
Methodology
Before a first call, you can do the vendor groundwork with our free, sourced references:
- HIPAA self-assessment — check where your safeguards stand today.
- Our HIPAA BAA — when we sign one and what it covers.
- BAA review checklist — check any BAA against the terms HIPAA requires before you sign it.
- HIPAA BAA vendor list — which cloud, AI and SaaS vendors sign a BAA, and on which plan.
- Cloud provider comparison — AWS, Google Cloud and Azure side by side for a HIPAA build.
- HIPAA-eligible services lookup — whether a specific cloud service is covered by its provider's BAA.
Technology Stack
Terraform / AWS CDK
Infrastructure as Code for reproducible deployments
AWS RDS / Cloud SQL
Managed databases with KMS encryption at rest
AWS KMS / Cloud KMS
Customer-managed encryption keys for PHI
CloudTrail / Cloud Audit Logs
Immutable audit logs for compliance evidence
AWS WAF / Cloud Armor
Web application firewall to block attacks
Vanta / Drata
Automated SOC 2 evidence collection
AWS Inspector / Security Command Center
Continuous vulnerability scanning
Security Patterns From the CCM/PCM Platform
Frequently Asked Questions
Common questions about hipaa & soc 2 architecture for healthcare saas
Is HIPAA compliance a one-time project or ongoing?
Ongoing. HIPAA compliance requires continuous monitoring, regular risk assessments, employee training, and patching vulnerabilities as they're discovered. Treating it as a one-time checklist is a common way to drift out of compliance. We set up automated monitoring so configuration drift is caught as your infrastructure evolves.
Do we need SOC 2 if we're already HIPAA compliant?
Usually yes, if you're selling to enterprise hospitals. HIPAA is a legal requirement for handling PHI; a SOC 2 report is an attestation, issued by a licensed CPA firm, on how your security controls are designed and operate. No certificate is issued. Hospitals use SOC 2 reports to speed up vendor security reviews; without one, expect longer and more detailed questionnaires.
How long does it take to get a SOC 2 Type II report?
A SOC 2 Type II report is an attestation issued by a licensed CPA firm after it tests how your controls operated over an observation window — commonly 3 to 12 months; the AICPA does not set a fixed minimum. No certificate is issued. The window can only start once the controls are in place and documented, so the engineering comes first. We engineer the technical controls auditors test; a CPA firm issues the report.
Can we use AWS or GCP's default encryption, or do we need KMS?
HIPAA does not require customer-managed keys. Encryption is an addressable implementation specification that names no algorithm or key type (45 CFR 164.312(a)(2)(iv)). Customer-managed keys (KMS) are good practice — they give you control over key rotation, access policies, and revocation — and security questionnaires ask about them. HHS's January 2025 proposed Security Rule update would make encryption required, but it is not final. Last reviewed 2026-09-25. Source: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
What's the difference between encryption at rest and encryption in transit?
Encryption at rest protects data stored in databases and S3 buckets (using KMS). Encryption in transit protects data as it moves between servers, browsers, and APIs (using SSL/TLS). The HIPAA Security Rule lists both as addressable specifications, and hospital security teams expect both. Many startups forget to enforce SSL/TLS on internal API calls between services, which fails hospital audits.
Does my engineering team need to lose production access for HIPAA compliance?
Not entirely, but direct SSH/database access must be restricted. Instead, we implement session-based access via AWS Systems Manager or GCP IAP, with all actions logged and time-limited. Engineers can still troubleshoot production, but they can't extract PHI without audit trails.
What happens if we have a data breach?
HIPAA requires breach notification to affected individuals, to HHS's Office for Civil Rights (OCR), and to prominent media outlets when a breach affects more than 500 residents of a state or jurisdiction. Civil money penalties are assessed per violation, not per patient record. Amounts in effect since Jan 28, 2026 (HHS inflation adjustment, 91 FR 3665): $145 to $73,011 per violation for tiers 1–3, and $73,011 to $2,190,294 for uncorrected willful neglect, with a calendar-year cap of $2,190,294 per identical provision. The architecture we build includes breach detection (CloudTrail anomaly detection) and incident response runbooks to limit exposure. Last reviewed 2026-09-25. Source: https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
How much does HIPAA-compliant infrastructure cost vs. standard AWS?
KMS encryption, CloudTrail logging, and VPC isolation add to baseline cloud costs; how much depends mostly on log volume and key usage, and it can be estimated from your expected traffic before you commit. For a vendor selling to hospitals, that cost is usually small next to the value of the contracts it helps you qualify for.
Related Engineering Articles
Deep-dive technical guides related to hipaa & soc 2 architecture for healthcare saas
AI Governance for Medical Groups: A Practical Policy and Engineering Checklist
Read ArticleZero Trust Architecture for HIPAA-Compliant Cloud Infrastructure
Read ArticleSOC 2 Type II for Healthcare Startups: What the Audit Actually Requires
Read ArticleHIPAA Business Associate Agreements: What Every Healthcare SaaS Vendor Needs to Know
Read ArticleAWS HIPAA Eligible Services: Complete List and What's Not Covered
Read ArticleHIPAA Audit Logging Requirements: What to Log, How Long to Keep It
Read ArticleRelated Resources
ROI Calculator
Calculate how much you're spending on manual processes and how fast custom software pays for itself.
Calculate SavingsHIPAA Checklist
Download a practical checklist of HIPAA Security Rule safeguards to review before you launch.
Get ChecklistCase Studies
Read the published CCM/PCM engagement: Excel to a multi-tenant platform serving 8,000+ patients.
Read the Case StudyReady to Discuss Your Project?
Schedule a technical consultation to discuss your specific requirements, timeline, and budget. No sales pitch—just engineering.
Or explore the engineering glossary to learn more about healthcare software terminology.