Why Joomla needs a HIPAA host, not a generic one
Joomla's access control levels and extension ecosystem make it a common choice for member-facing healthcare sites. The host underneath it decides whether those sites can lawfully hold patient data.
Member areas and forms carry PHI
Patient registration, secure downloads and contact forms that invite health details all make a Joomla site a system that stores or transmits protected health information.
A BAA before anything else
Under 45 CFR § 164.308(b) the host must be a business associate under a signed agreement. We sign it within 24 hours of signup and before migration begins.
The compliance baseline, configured for you
Single-tenant AWS, encryption at rest and in transit, six-year audit logging, CloudFront and a WAF are set up before handover, not left as an exercise.
Every Joomla tier runs on hardened, single-tenant infrastructure with encryption, logging and monitoring configured before handover.
Where our responsibility ends
Stated plainly, because knowing this before an incident is worth more than discovering it during one.
We run
- The AWS account, VPC and network isolation
- The operating system, patching and hardening
- PHP, the web server, the database and TLS
- CloudFront, the WAF, encryption, audit logging and backups
- Monitoring and infrastructure incident response
You run
- Your Joomla site, templates and extensions
- Joomla core and extension updates, unless scoped with us
- Content, users, access levels and permissions
- The systems your site integrates with and the data you send them
If a problem turns out to be the server, the runtime or the infrastructure, open a ticket and we take it. If it is inside Joomla, we tell you what we found and hand it back with recommendations.
HIPAA hosting vs standard hosting
A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.
Standard Hosting
Basic web hosting
HIPAA Compliant Hosting
Healthcare-grade security