Why self-hosted Strapi, on a host that signs a BAA
A headless CMS that serves patient-facing apps and portals is part of the system that handles PHI, and its API is the front door.
Your content API is in the data path
When a mobile app or patient portal reads from Strapi, the content, the users and the API tokens all live on the server. That server needs to be BAA-covered and isolated.
Self-hosted keeps the data in your environment
Running Strapi on a single-tenant AWS environment keeps the database, uploads and admin panel inside infrastructure dedicated to you, behind CloudFront and a WAF.
Memory-optimised for Node.js and the database
Strapi runs on our memory-optimised tiers, with 16 GB of RAM at Solo, room for the Node.js process, the database and the admin build side by side.
The content API, its database and its uploads stay inside infrastructure dedicated to you, behind CloudFront and a WAF.
Where our responsibility ends
Stated plainly, because knowing this before an incident is worth more than discovering it during one.
We run
- The AWS account, VPC and network isolation
- The operating system, patching and hardening
- The Node.js runtime, the database, the process manager and TLS
- CloudFront, the WAF, encryption, audit logging and backups
- Monitoring and infrastructure incident response
You run
- Your Strapi project, content types, plugins and customisations
- Strapi version upgrades, unless scoped with us
- Content, admin users, roles and API tokens
- The apps and systems that consume your API, and the data you expose to them
If a problem turns out to be the server, the runtime or the infrastructure, open a ticket and we take it. If it is inside your Strapi project, we tell you what we found and hand it back with recommendations.
HIPAA hosting vs standard hosting
A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.
Standard Hosting
Basic web hosting
HIPAA Compliant Hosting
Healthcare-grade security