Why a dedicated host, not a container platform
Most managed container services put your workload on shared infrastructure. For PHI, the isolation boundary matters.
Single-tenant, no shared kernel
Your Docker host is an EC2 instance in an AWS account dedicated solely to you. Containers on a shared platform share a kernel with strangers; yours do not.
Your registry, your images
Pull from Docker Hub, ECR, GHCR or a private registry. We do not inspect, mirror or rehost your images, and there is no vendor build pipeline in the path.
BAA signed, baseline applied
Encryption at rest and in transit, six-year audit logging, snapshots, CloudFront, a WAF and network isolation are configured before you get access, not left as an exercise.
Where our responsibility ends
Stated plainly, because knowing this before an incident is worth more than discovering it during one.
We run
- The AWS account, VPC and network isolation
- The host operating system, patching and hardening
- The Docker engine and its updates
- CloudFront, the WAF, encryption, audit logging and backups
- Monitoring and infrastructure incident response
You run
- Your images and how they are built
- Your containers and what runs inside them
- Application configuration, secrets and data handling
- Anything your containers connect out to
If a problem turns out to be at the host or infrastructure layer, open a ticket and we take it. If it is inside a container, we tell you what we found and hand it back with recommendations.
HIPAA hosting vs standard hosting
A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.
Standard Hosting
Basic web hosting
HIPAA Compliant Hosting
Healthcare-grade security