Healthcare · DevOps and testing
HIPAA-compliant DevOps and software testing for healthcare products
The code is half of HIPAA compliance. The other half is how the product is hosted, deployed, tested and recovered. We set up and run that half, for products we build and for products other teams built.

Short answer
HIPAA-compliant DevOps means hosting protected health information only on cloud services covered by a Business Associate Agreement, deploying through an automated pipeline that never copies patient data into test environments, and keeping audit logs, encrypted backups and tested restores. HIPAA software testing adds checks for access control, audit logging and encryption to normal QA. Innovation Insight sets this up for $8k to $40k and runs it on a $1.5k to $8k monthly retainer.
Reviewed by Zain Khalid Malik, CTO & Co-founder · Updated
What makes DevOps HIPAA compliant?
Most HIPAA problems we find in inherited health apps are not in the application code. They are a staging database restored from production, patient names in error logs, a backup nobody has ever restored, an engineer who left with access still active, or a file bucket that was public for a demo. The HIPAA Security Rule asks for access control, audit controls, integrity, person or entity authentication, transmission security and a contingency plan. In practice those are owned by whoever runs the infrastructure and the release process.
HIPAA-compliant DevOps: what we set up
| Area | What we put in place |
|---|---|
| Cloud account | AWS, Azure or Google Cloud in your name, with a signed Business Associate Agreement and only HIPAA-eligible services handling patient data |
| Infrastructure as code | Every network, database and service defined in Terraform or the cloud's own tooling, reviewed like application code |
| Environments | Separate accounts or projects for production and non-production; no patient data outside production |
| Access | Single sign-on with multi-factor authentication, least-privilege roles, time-limited production access and quarterly access reviews |
| Secrets | Keys and credentials in a managed vault, rotated on a schedule and when people leave |
| Encryption | TLS everywhere, encrypted databases, storage and backups with managed keys |
| Logging | Central logs with patient data masked or excluded, plus a separate application audit log of who viewed or changed what |
| Backups and recovery | Automated encrypted backups, point-in-time recovery and a written restore procedure tested on a schedule |
| Monitoring | Uptime, error and security alerts routed to a named on-call engineer |
A CI/CD pipeline that keeps patient data out
- Every change goes through a pull request with review; nobody deploys from a laptop.
- The pipeline runs unit, integration and access-control tests, dependency and container vulnerability scans, and static analysis for secrets in code.
- Infrastructure changes are planned and reviewed before they apply.
- Builds deploy to staging with synthetic data, then to production through an approval step.
- Database migrations are backward-compatible and reversible, and run before the code that needs them.
- Each deployment is recorded with who approved it and what changed, which answers the auditor's change-management questions.
HIPAA software testing
Healthcare QA covers everything normal QA covers, plus tests that prove the safeguards work. We write these as automated tests that run on every change, so a refactor cannot quietly remove one.
| Test | What it proves |
|---|---|
| Access control | Each role sees only what it should; a user from one clinic or tenant cannot read another's records |
| Audit logging | Viewing, creating, changing and exporting patient data writes a complete audit record |
| Session handling | Sessions expire, automatic logoff works and tokens cannot be reused after sign-out |
| Encryption | Data is encrypted in transit and at rest, and no endpoint accepts plain HTTP |
| Data leakage | Patient data does not appear in logs, analytics events, error reports, URLs or push notification text |
| Backup restore | A backup restores into a clean environment and the application runs against it |
| Security testing | Dependency scanning on every build and an independent penetration test before launch and after major changes |
| Accessibility | Patient-facing screens meet WCAG 2.1 AA, which public programmes and many health systems require |
How do you test a health app without real patient data?
Generate it. Every environment except production runs on synthetic patients, so a leaked test database exposes nothing. Real data is used only when there is no alternative, and then only after de-identification under one of HIPAA's two recognised methods, with the process written down.
- Generated synthetic patients, with realistic edge cases such as long names, multiple addresses and missing fields.
- Open synthetic data sets such as Synthea for clinical test cases where the product needs realistic histories.
- De-identified data only when there is a real need, prepared under HIPAA's Safe Harbor or Expert Determination method and documented.
- Seeded test tenants in every environment so isolation tests run automatically.
For products another team built
Many clients come to us with a live health app and a security questionnaire from a hospital they cannot yet answer. We start with a two-week review of the cloud account, pipeline, logs, backups and access, ranked by risk, then fix the urgent items first. Our code takeover checklist shows the order we work in.
Healthcare work we have shipped
The Zeuss telehealth platform runs on Azure with secrets in Key Vault, Managed Identity between services, AES-256 encryption of sensitive data, a complete HTTP audit trail in a dedicated database, role-based access by route and masking of personal data in API responses, with monitoring through Sentry and Application Insights. We bring the same controls to every health product we host or support.
What it costs
| Scope | Range | Timeline |
|---|---|---|
| Review of an existing setup, with a ranked risk report | $3k to $8k | 1 to 2 weeks |
| HIPAA-ready cloud, CI/CD, logging and backups set up | $8k to $40k | 3 to 8 weeks |
| QA engineer on your team | From $2,600 a month | Ongoing |
| Hosting operations, patching, restore tests and monitoring | $1.5k to $8k per month | Monthly |
Cloud provider charges and independent penetration tests are paid directly to those providers and are not included.
Sources and further reading
Next step
Tell us what you're building and get a written estimate.
A senior engineer replies within one business day. NDA on request.
Products we've shipped, and what happened next.
Case studies written from the technical documentation of each project: the stack, the scale and the outcome.
Questions we get asked a lot.
What is HIPAA-compliant DevOps?
Running the infrastructure and release process for a health app in a way that meets the HIPAA Security Rule: BAA-covered cloud services, least-privilege access, encryption, audit logs, no patient data outside production, and backups that are tested by restoring them.
Which cloud providers sign a BAA?
AWS, Microsoft Azure and Google Cloud all sign Business Associate Agreements, but each covers only its listed HIPAA-eligible services. We check every service in the design against that list.
Can we use production data for testing?
We advise against it. Use synthetic data in all non-production environments. If real data is genuinely needed, de-identify it under HIPAA's Safe Harbor or Expert Determination method and document the process.
Do we need a penetration test for HIPAA?
The current Security Rule requires a risk analysis and regular evaluation rather than naming penetration testing. HHS proposed in January 2025 to require yearly penetration tests and vulnerability scans every six months; that rule was not final as of October 2026. Hospitals and enterprise buyers already ask for a test, so plan one before launch and after major changes.
Can you take over hosting for an app another agency built?
Yes. We start with a two-week review, fix the highest risks first and then run hosting, patching and monitoring on a monthly retainer.
Will you sign a Business Associate Agreement?
Yes. We sign a Business Associate Agreement before any engineer has access to protected health information, and we sign BAAs with the vendors we bring into the project.

