Logo
Search
Login
Sign Up

SOC 2

HIPAA

+3

VPC and PrivateLink for PHI workloads — the network architecture auditors love

May 1, 2026

•

2 min read

VPC and PrivateLink for PHI workloads — the network architecture auditors love

Public subnets, NAT gateways, and "we restrict by security group" don't survive a HIPAA review. Here's the pattern that does.

Manan Qayas
Manan Qayas

AWS Cost

+1

Issue 3: SOC 2 evidence that auditors actually accept

Apr 26, 2026

•

2 min read

Issue 3: SOC 2 evidence that auditors actually accept

A screenshot is not evidence. A Slack message is not a control. Here's what works.

Manan Qayas
Manan Qayas

HIPAA

+2

Issue 1: The HIPAA mistake I find in 8 of 10 AWS audits

Apr 12, 2026

•

2 min read

Issue 1: The HIPAA mistake I find in 8 of 10 AWS audits

S3 access logging is off, or it's logging to the same bucket. Both are fails. Here's what auditors actually want.

Manan Qayas
Manan Qayas

Transivone Dispatch

Field notes on AWS infrastructure, HIPAA, and SOC 2 for health tech engineering leaders.

© 2026 Transivone.
beehiivPowered by beehiiv