Skip to content

Healthcare · DevOps and testing

HIPAA-compliant DevOps and software testing for healthcare products

The code is half of HIPAA compliance. The other half is how the product is hosted, deployed, tested and recovered. We set up and run that half, for products we build and for products other teams built.

Book a call
Earth at night seen from orbit, city lights linked like cloud infrastructure

Short answer

HIPAA-compliant DevOps means hosting protected health information only on cloud services covered by a Business Associate Agreement, deploying through an automated pipeline that never copies patient data into test environments, and keeping audit logs, encrypted backups and tested restores. HIPAA software testing adds checks for access control, audit logging and encryption to normal QA. Innovation Insight sets this up for $8k to $40k and runs it on a $1.5k to $8k monthly retainer.

Reviewed by Zain Khalid Malik, CTO & Co-founder · Updated

What makes DevOps HIPAA compliant?

Most HIPAA problems we find in inherited health apps are not in the application code. They are a staging database restored from production, patient names in error logs, a backup nobody has ever restored, an engineer who left with access still active, or a file bucket that was public for a demo. The HIPAA Security Rule asks for access control, audit controls, integrity, person or entity authentication, transmission security and a contingency plan. In practice those are owned by whoever runs the infrastructure and the release process.

HIPAA-compliant DevOps: what we set up

AreaWhat we put in place
Cloud accountAWS, Azure or Google Cloud in your name, with a signed Business Associate Agreement and only HIPAA-eligible services handling patient data
Infrastructure as codeEvery network, database and service defined in Terraform or the cloud's own tooling, reviewed like application code
EnvironmentsSeparate accounts or projects for production and non-production; no patient data outside production
AccessSingle sign-on with multi-factor authentication, least-privilege roles, time-limited production access and quarterly access reviews
SecretsKeys and credentials in a managed vault, rotated on a schedule and when people leave
EncryptionTLS everywhere, encrypted databases, storage and backups with managed keys
LoggingCentral logs with patient data masked or excluded, plus a separate application audit log of who viewed or changed what
Backups and recoveryAutomated encrypted backups, point-in-time recovery and a written restore procedure tested on a schedule
MonitoringUptime, error and security alerts routed to a named on-call engineer

A CI/CD pipeline that keeps patient data out

  1. Every change goes through a pull request with review; nobody deploys from a laptop.
  2. The pipeline runs unit, integration and access-control tests, dependency and container vulnerability scans, and static analysis for secrets in code.
  3. Infrastructure changes are planned and reviewed before they apply.
  4. Builds deploy to staging with synthetic data, then to production through an approval step.
  5. Database migrations are backward-compatible and reversible, and run before the code that needs them.
  6. Each deployment is recorded with who approved it and what changed, which answers the auditor's change-management questions.
Synthetic data is the rule we enforce most. Copying production into staging, even once to debug a problem, puts patient data in an environment with weaker controls and more people. If a bug can only be reproduced with real data, it is debugged in production under audit, not copied out.

HIPAA software testing

Healthcare QA covers everything normal QA covers, plus tests that prove the safeguards work. We write these as automated tests that run on every change, so a refactor cannot quietly remove one.

TestWhat it proves
Access controlEach role sees only what it should; a user from one clinic or tenant cannot read another's records
Audit loggingViewing, creating, changing and exporting patient data writes a complete audit record
Session handlingSessions expire, automatic logoff works and tokens cannot be reused after sign-out
EncryptionData is encrypted in transit and at rest, and no endpoint accepts plain HTTP
Data leakagePatient data does not appear in logs, analytics events, error reports, URLs or push notification text
Backup restoreA backup restores into a clean environment and the application runs against it
Security testingDependency scanning on every build and an independent penetration test before launch and after major changes
AccessibilityPatient-facing screens meet WCAG 2.1 AA, which public programmes and many health systems require

How do you test a health app without real patient data?

Generate it. Every environment except production runs on synthetic patients, so a leaked test database exposes nothing. Real data is used only when there is no alternative, and then only after de-identification under one of HIPAA's two recognised methods, with the process written down.

  • Generated synthetic patients, with realistic edge cases such as long names, multiple addresses and missing fields.
  • Open synthetic data sets such as Synthea for clinical test cases where the product needs realistic histories.
  • De-identified data only when there is a real need, prepared under HIPAA's Safe Harbor or Expert Determination method and documented.
  • Seeded test tenants in every environment so isolation tests run automatically.

For products another team built

Many clients come to us with a live health app and a security questionnaire from a hospital they cannot yet answer. We start with a two-week review of the cloud account, pipeline, logs, backups and access, ranked by risk, then fix the urgent items first. Our code takeover checklist shows the order we work in.

Healthcare work we have shipped

The Zeuss telehealth platform runs on Azure with secrets in Key Vault, Managed Identity between services, AES-256 encryption of sensitive data, a complete HTTP audit trail in a dedicated database, role-based access by route and masking of personal data in API responses, with monitoring through Sentry and Application Insights. We bring the same controls to every health product we host or support.

What it costs

ScopeRangeTimeline
Review of an existing setup, with a ranked risk report$3k to $8k1 to 2 weeks
HIPAA-ready cloud, CI/CD, logging and backups set up$8k to $40k3 to 8 weeks
QA engineer on your teamFrom $2,600 a monthOngoing
Hosting operations, patching, restore tests and monitoring$1.5k to $8k per monthMonthly

Cloud provider charges and independent penetration tests are paid directly to those providers and are not included.

Next step

Tell us what you're building and get a written estimate.

A senior engineer replies within one business day. NDA on request.

FAQ

Questions we get asked a lot.

What is HIPAA-compliant DevOps?

Running the infrastructure and release process for a health app in a way that meets the HIPAA Security Rule: BAA-covered cloud services, least-privilege access, encryption, audit logs, no patient data outside production, and backups that are tested by restoring them.

Which cloud providers sign a BAA?

AWS, Microsoft Azure and Google Cloud all sign Business Associate Agreements, but each covers only its listed HIPAA-eligible services. We check every service in the design against that list.

Can we use production data for testing?

We advise against it. Use synthetic data in all non-production environments. If real data is genuinely needed, de-identify it under HIPAA's Safe Harbor or Expert Determination method and document the process.

Do we need a penetration test for HIPAA?

The current Security Rule requires a risk analysis and regular evaluation rather than naming penetration testing. HHS proposed in January 2025 to require yearly penetration tests and vulnerability scans every six months; that rule was not final as of October 2026. Hospitals and enterprise buyers already ask for a test, so plan one before launch and after major changes.

Can you take over hosting for an app another agency built?

Yes. We start with a two-week review, fix the highest risks first and then run hosting, patching and monitoring on a monthly retainer.

Will you sign a Business Associate Agreement?

Yes. We sign a Business Associate Agreement before any engineer has access to protected health information, and we sign BAAs with the vendors we bring into the project.