CompyMax

HIPAA compliant cloud hosting

Hosting for applications that handle health data. Coverage is granted per service, from a published eligibility list that moves.

Accepting the addendum on a major cloud platform is the easy part, often a few clicks in a console at no extra cost. What follows is harder. Coverage comes from a published list of eligible services, and that list is long, revised often, and full of exclusions buried inside services that are themselves eligible: a particular studio or labs edition, a specific messaging channel, certain database engines, certain models. A team can be well inside the list at service level and outside it two menus down.

The platform also does very little for you. These vendors are explicit that using an eligible service does not by itself protect anything, and that encryption, key management, network isolation, access control, logging and backup are yours to design. Organizations that handle this well treat the eligibility list as a procurement gate every new service must pass before an engineer switches it on.

Can be used with patient information

Each of these requires a signed agreement and, usually, specific settings. Open an entry for the exact conditions.

What to check before you adopt one

  • Read the eligibility entry for each service you plan to use, footnotes included, since exclusions often sit inside a service that does appear on the list.
  • Establish who is permitted to accept the addendum and whether it can be applied once across every account in your organization.
  • Decide in advance which accounts or projects may hold patient data, and keep experimentation on separate accounts that never receive any.
  • Write down the encryption, logging and access-control configuration the platform expects of you, because none of it is applied automatically when the addendum is accepted.
  • Add a step to your change process requiring the eligibility list to be re-checked before any new service is adopted.

The expensive mistake

Treating the signed addendum as though it covered the whole platform. An engineer picks a convenient managed service to solve a problem, and nobody checks whether that service, or the specific feature within it, appears on the eligibility list. The list is the boundary, not the account. Anything outside it holding patient data is outside the agreement regardless of what you signed.

Tracking which of these your organization uses?

The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.

Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.