Why self-hosted n8n, and not n8n Cloud
Automation that touches PHI has a different set of constraints from automation that does not.
Your data stays in your account
Workflow executions, payloads and credentials live on a server inside an AWS account dedicated to you. Nothing transits a shared multi-tenant automation platform.
A BAA that covers the automation layer
If a workflow moves PHI between an EHR, a form and a database, the system executing it needs to be covered. Ours is, and the agreement is signed before you go live.
Encrypted, logged and backed up
Encryption at rest and in transit, six-year audit logging, and snapshots of your workflows and credentials, configured before handover, not left to you.
Where our responsibility ends
Stated plainly, because knowing this before an incident is worth more than discovering it during one.
We run
- The AWS account, VPC and network isolation
- The server, its patching and hardening
- The n8n process, version updates and TLS
- CloudFront, the WAF, encryption, audit logging and backups
- Monitoring and infrastructure incident response
You run
- Your workflows and what they do
- Your credentials and the systems you connect to
- What data you choose to move, and where
- Any custom nodes or community nodes you install
If a problem turns out to be the server or the n8n process, open a ticket and we take it. If a workflow is doing the wrong thing, we tell you what we found and hand it back with recommendations.
HIPAA hosting vs standard hosting
A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.
Standard Hosting
Basic web hosting
HIPAA Compliant Hosting
Healthcare-grade security