HIPAA
+3
May 1, 2026
•
2 min read
Public subnets, NAT gateways, and "we restrict by security group" don't survive a HIPAA review. Here's the pattern that does.
AWS Cost
+1
Apr 26, 2026
A screenshot is not evidence. A Slack message is not a control. Here's what works.
+2
Apr 12, 2026
S3 access logging is off, or it's logging to the same bucket. Both are fails. Here's what auditors actually want.