Logo
Search
Login
Sign Up
Oliver Buchannon
Manan Qayas

I'm Manan Qayas — a technology leader focused exclusively on healthcare. I founded Transivone to provide fractional CTO services to health tech startups, biotech companies, and healthcare organizations that need senior technology leadership without the overhead of a full-time executive.

The HIPAA loophole you've been leaning on is closing

Jun 12, 2026

•

2 min read

The HIPAA loophole you've been leaning on is closing

The proposed Security Rule overhaul kills the safeguard you've been documenting your way around, and AWS is where it bites first.

Manan Qayas
Manan Qayas
IAM least-privilege for PHI workloads — what auditors actually check

May 8, 2026

•

3 min read

IAM least-privilege for PHI workloads — what auditors actually check

"We follow least privilege" is a policy statement. Auditors want to see the IAM configuration that proves it.

Manan Qayas
Manan Qayas

HIPAA

+3

VPC and PrivateLink for PHI workloads — the network architecture auditors love

May 1, 2026

•

2 min read

VPC and PrivateLink for PHI workloads — the network architecture auditors love

Public subnets, NAT gateways, and "we restrict by security group" don't survive a HIPAA review. Here's the pattern that does.

Manan Qayas
Manan Qayas

AWS Cost

+1

Issue 3: SOC 2 evidence that auditors actually accept

Apr 26, 2026

•

2 min read

Issue 3: SOC 2 evidence that auditors actually accept

A screenshot is not evidence. A Slack message is not a control. Here's what works.

Manan Qayas
Manan Qayas

HIPAA

+1

Issue 2: Three AWS cost patterns specific to health tech

Apr 24, 2026

•

2 min read

Issue 2: Three AWS cost patterns specific to health tech

Generic cost optimization advice misses the patterns that show up in HIPAA-shaped workloads. Here are three I find on every audit.

Manan Qayas
Manan Qayas

HIPAA

+2

Issue 1: The HIPAA mistake I find in 8 of 10 AWS audits

Apr 12, 2026

•

2 min read

Issue 1: The HIPAA mistake I find in 8 of 10 AWS audits

S3 access logging is off, or it's logging to the same bucket. Both are fails. Here's what auditors actually want.

Manan Qayas
Manan Qayas

Transivone Dispatch

Field notes on AWS infrastructure, HIPAA, and SOC 2 for health tech engineering leaders.

© 2026 Transivone.
beehiivPowered by beehiiv