# hipaa

Published articles for hipaa.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL

DevFeed: [Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL](<https://devfeed.tech/articles/scaling-kubernetes-governance-a-platform-engineer-s-guide-to-kyverno-and-cel-12220.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/scaling-kubernetes-governance-a-platform-engineers-guide-to-kyverno-and-cel>)

Author: Koray Oksay

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [opa](<https://devfeed.tech/topics/opa.md>), [rego](<https://devfeed.tech/topics/rego.md>)

Tags: [common-expression-language](<https://devfeed.tech/tags/common-expression-language.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [platform](<https://devfeed.tech/tags/platform.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A guide to using Kyverno and its Common Expression Language support for Kubernetes governance. It explains how platform engineering teams can enforce policies, automate resource changes, generate resources, verify image signatures, and maintain security and compliance while preserving developer velocity.

### Source excerpt

Kyverno with CEL support provides Policy-as-Code for Kubernetes governance. Enforce security, automate guardrails, and boost developer velocity for platform engineering teams.

## Announcing the CIS Benchmark for CockroachDB v25.x

DevFeed: [Announcing the CIS Benchmark for CockroachDB v25.x](<https://devfeed.tech/articles/announcing-the-cis-benchmark-for-cockroachdb-v25-x-23757.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/cis-benchmark-cockroachdb-security>)

Author: Adam Brennick,Ayog Mohanty

Published: 2026-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cockroach Labs](<https://devfeed.tech/topics/cockroach-labs.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Database](<https://devfeed.tech/topics/database.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cockroach-labs](<https://devfeed.tech/tags/cockroach-labs.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [published](<https://devfeed.tech/tags/published.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

The Center for Internet Security has published the CIS CockroachDB v25.x Benchmark, providing a consensus-driven security configuration guide for self-hosted CockroachDB deployments. The article explains how the benchmark can support standardized security practices, audits, compliance reviews, and production configuration validation.

### Source excerpt

We're proud to announce that the Center for Internet Security (CIS) has published the CIS CockroachDB v25.x Benchmark.

## Handling Protected Health Information Under HIPAA: Best Practices for Developers

DevFeed: [Handling Protected Health Information Under HIPAA: Best Practices for Developers](<https://devfeed.tech/articles/handling-protected-health-information-under-hipaa-best-practices-for-developers-5331.md>)

Original publisher: [Read original article](<https://neon.com/blog/hipaa-best-practices-for-developers>)

Author: Andrew Tate

Published: 2025-06-13T15:36:17Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [App](<https://devfeed.tech/topics/app.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>), [Database](<https://devfeed.tech/topics/database.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [database](<https://devfeed.tech/tags/database.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [health](<https://devfeed.tech/tags/health.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains HIPAA and Protected Health Information (PHI) for developers building healthtech applications. It describes how identifiable health data is regulated, including data that becomes PHI when combined with health information, and highlights security measures such as encryption, role-based access controls, and continuous audit logging in a Neon Postgres database.

### Source excerpt

You're building a healthtech app. Maybe you've decided to take on the insane complexity of electronic health records, or maybe you're building an app for doctors to communicate with patients, or perhaps you're creating a platform for managing clinical trials. Whatever your specif...

## The Difference Between Postgres Logging and PGAudit

DevFeed: [The Difference Between Postgres Logging and PGAudit](<https://devfeed.tech/articles/the-difference-between-postgres-logging-and-pgaudit-5734.md>)

Original publisher: [Read original article](<https://neon.com/blog/postgres-logging-vs-pgaudit>)

Author: Monica Steinke

Published: 2025-05-28T20:26:29Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [config](<https://devfeed.tech/tags/config.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [iso](<https://devfeed.tech/tags/iso.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [process](<https://devfeed.tech/tags/process.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

The article compares PostgreSQL's built-in logging with PGAudit. PostgreSQL logging supports operational monitoring and troubleshooting, while PGAudit is designed for compliance auditing with detailed records of database access and changes. It describes PGAudit's session and object auditing modes and the information recorded in audit log entries.

### Source excerpt

Postgres has some excellent internal logging capabilities. With a simple logging_collector = on and a couple of other config flags, you can get an incredibly detailed picture of your Postgres operations, from individual SQL statements to connection attempts, error messages, and l...

## Neon is HIPAA Compliant

DevFeed: [Neon is HIPAA Compliant](<https://devfeed.tech/articles/neon-is-hipaa-compliant-5328.md>)

Original publisher: [Read original article](<https://neon.com/blog/hipaa>)

Author: Busra Demir

Published: 2025-03-13T16:17:42Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Database](<https://devfeed.tech/topics/database.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Shared Responsibility Model](<https://devfeed.tech/topics/shared-responsibility-model.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [company](<https://devfeed.tech/tags/company.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [shared-responsibility](<https://devfeed.tech/tags/shared-responsibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Neon announces completion of its HIPAA compliance audit, enabling customers to store Protected Health Information (PHI) on its database platform. The article describes safeguards including encryption, role-based access control, audit logging, continuous monitoring, incident response, breach notification, employee training, third-party requirements, and shared customer responsibilities.

### Source excerpt

Neon has completed its HIPAA compliance audit, adding to our security achievements: SOC 2 Type 2, ISO 27001, ISO 27701, GDPR, and CCPA. If your company needs a HIPAA-compliant database, Neon can now securely store Protected Health Information (PHI). What is HIPAA Compliance? The...

## Proposed HIPAA Security Rule Updates for Vulnerability Management

DevFeed: [Proposed HIPAA Security Rule Updates for Vulnerability Management](<https://devfeed.tech/articles/hipaa-s-new-vulnerability-management-guidelines-what-you-need-to-know-13081.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/hipaas-new-vulnerability-management-guidelines-what-you-need-to-know>)

Published: 2025-02-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains proposed updates to HIPAA's Security Rule, including requirements for container security, risk analysis, data-security practices, and remediation of Common Vulnerabilities and Exposures (CVEs). It states that the proposal would require healthcare organizations to address Critical CVEs within 15 calendar days of discovery.

### Source excerpt

New guidelines for HIPAA's Security Rule have been proposed, which include updated requirements for vulnerability management, risk management, and more.

## Securing Infrastructure in Healthcare: Reducing Breaches and Building Resiliency

DevFeed: [Securing Infrastructure in Healthcare: Reducing Breaches and Building Resiliency](<https://devfeed.tech/articles/securing-infrastructure-in-healthcare-reducing-breaches-and-building-resiliency-29830.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/securing-infrastructure-in-healthcare/>)

Author: jack.pitts@goteleport.com (Jack Pitts)

Published: 2024-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [audit](<https://devfeed.tech/topics/audit.md>), [resiliency](<https://devfeed.tech/topics/resiliency.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Network](<https://devfeed.tech/topics/network.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [audit](<https://devfeed.tech/tags/audit.md>), [data](<https://devfeed.tech/tags/data.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [healthtech](<https://devfeed.tech/tags/healthtech.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [network](<https://devfeed.tech/tags/network.md>), [resiliency](<https://devfeed.tech/tags/resiliency.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article examines infrastructure, security, privacy, and compliance challenges faced by digital healthcare companies operating telehealth and remote patient monitoring systems. It uses a fictional company to discuss remote device access, data transmission, role-based access control, databases, and audit logging for HIPAA compliance, and describes how Teleport is presented as a solution.

### Source excerpt

Ensure HIPAA compliance, protect patient data, and streamline telehealth access. Learn how HealthTech Innovations uses Teleport to overcome infrastructure challenges.

## Improving Laravel Application Security with Aikido

DevFeed: [Improving Laravel Application Security with Aikido](<https://devfeed.tech/articles/improving-laravel-application-security-with-aikido-3720.md>)

Original publisher: [Read original article](<https://laravel.com/blog/improving-laravel-application-security-with-aikido>)

Author: James Brooks

Published: 2024-07-08T14:30:00Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [PHP](<https://devfeed.tech/topics/php.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [soc2](<https://devfeed.tech/tags/soc2.md>)

### AI overview

Laravel has partnered with Aikido to add security scanning for Laravel applications using Forge. The integration identifies potential vulnerabilities and security flags, surfaces findings within Forge, and combines code and cloud security scanners to help developers manage application security and compliance requirements.

### Source excerpt

As your Laravel application grows, managing security objectives becomes more challenging, especially for small teams or solo developers. Today, Laravel has teamed up with Aikido to provide a seamless solution for securing your Laravel application. With Aikido, Laravel developers using Forge can effortlessly scan for and identify potential security vulnerabilities, all in less than 1 minute.

## Evaluating Doximity GPT with Ground Truths and LLM Performance Metrics

DevFeed: [Evaluating Doximity GPT with Ground Truths and LLM Performance Metrics](<https://devfeed.tech/articles/beyond-accuracy-20023.md>)

Original publisher: [Read original article](<https://technology.doximity.com/articles/beyond-accuracy>)

Author: Doximity

Published: 2024-05-10T13:00:00Z

Content type: article

Language: en

Sources: [Doximity](<https://devfeed.tech/sources/doximity.md>)

Topics: [LLM evaluation / benchmarking](<https://devfeed.tech/topics/llm-evaluation-benchmarking.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [evaluation](<https://devfeed.tech/tags/evaluation.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [llm-evaluation](<https://devfeed.tech/tags/llm-evaluation.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>)

### AI overview

This article explains how Doximity evaluates its Doximity GPT medical writing assistant. It discusses using ground truths and golden datasets to establish baseline metrics, comparing contender models, and combining standard metrics, manual review, benchmarks, and LLM-assisted evaluation to assess relevance, coherence, factual accuracy, and ethical compliance.

### Source excerpt

At Doximity, we go to great lengths to ensure the quality of our products aligns with the standards physicians require. Across various industries, Large Language Models (LLMs) have become the backbone of numerous applications, driving advancements in everything from natural language processing to automated content creation. As we continue to develop products that make use of these LLMs, the need for rigorous and comprehensive evaluation of their outputs has never been more critical. Strap in as we explore the process for evaluating our Doximity GPT product, Doximity's HIPAA-compliant medical writing assistant, focusing on the importance of using "ground truths" to establish baseline metrics and the relative performance of contender models. A Brief Overview of How LLMs Generate Outputs LLMs are trained on vast amounts of textual data in order to learn patterns, structures, and nuances of language. By processing this data, these models develop the ability to generate text that mimics human writing. The output generation process involves the model understanding the input prompt, enhancing its focus via a system prompt, running all of that through its learned information and constructing a coherent and contextually relevant response. While this capability makes LLMs incredibly versatile, it also introduces unique challenges in ensuring the outputs meet specific quality and accuracy standards. LLM Evaluation: What is it and Why Does it Matter? Accuracy, precision, and recall are standard metrics that help evaluate different aspects of classification model quality in machine learning, and these metrics are still incredibly important for LLM evaluation as well. Additional traditional methods include manual review and comparison against predefined benchmarks. However, as LLMs grow more complex, these methods become less feasible due to the sheer volume of outputs and the nuanced understanding required to assess them. In addition to standard machine learning performance metr

## Temporal Cloud is now HIPAA compliant

DevFeed: [Temporal Cloud is now HIPAA compliant](<https://devfeed.tech/articles/temporal-cloud-is-now-hipaa-compliant-36009.md>)

Original publisher: [Read original article](<https://temporal.io/blog/temporal-cloud-is-now-hipaa-compliant>)

Author: Jim Walker

Published: 2024-02-05T16:00:00Z

Content type: release

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [data-security](<https://devfeed.tech/tags/data-security.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [health](<https://devfeed.tech/tags/health.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [product-news](<https://devfeed.tech/tags/product-news.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Temporal Cloud has achieved HIPAA compliance, enabling organizations handling protected health information to use the managed service while meeting applicable legal requirements. The article describes identity management, access controls, encryption settings, and data conversion capabilities that support sensitive health information security.

### Source excerpt

Temporal Cloud has achieved compliance with HIPAA, the national privacy and security standard for health-related information.

## Supabase is now HIPAA and SOC2 Type 2 compliant

DevFeed: [Supabase is now HIPAA and SOC2 Type 2 compliant](<https://devfeed.tech/articles/supabase-is-now-hipaa-and-soc2-type-2-compliant-671.md>)

Original publisher: [Read original article](<https://supabase.com/blog/supabase-soc2-hipaa>)

Author: Inian Parameshwaran

Published: 2023-08-11T07:00:00Z

Content type: article

Language: en

Sources: [Supabase Blog](<https://devfeed.tech/sources/supabase-blog.md>)

Topics: [Supabase](<https://devfeed.tech/topics/supabase.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announcement](<https://devfeed.tech/tags/announcement.md>), [audits](<https://devfeed.tech/tags/audits.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [soc2](<https://devfeed.tech/tags/soc2.md>)

### AI overview

Supabase announces that it is SOC2 Type 2 and HIPAA compliant. The article explains the transition from SOC2 Type 1, the evidence and process changes required for the Type 2 audit, and HIPAA's requirements for companies handling sensitive healthcare data.

### Source excerpt

This documents our journey from SOC2 Type 1 to SOC2 Type2 and HIPAA compliance. You can start building healthcare apps on Supabase today.

## Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones

DevFeed: [Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones](<https://devfeed.tech/articles/teleport-achieves-iso-27001-hipaa-and-soc-2-compliance-milestones-29855.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-iso-27001-hipaa/>)

Author: reed@goteleport.com (Reed Loden)

Published: 2023-08-11T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Security](<https://devfeed.tech/topics/security.md>), [trust](<https://devfeed.tech/topics/trust.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Teleport announces ISO 27001 certification, HIPAA compliance, and an expanded SOC 2 Type II report covering the Confidentiality and Availability trust service criteria.

### Source excerpt

An overview of Teleport Achieved ISO 27001, HIPAA, and SOC 2 Compliance Milestones