Why Symfony needs a HIPAA host, not a generic one
Symfony is chosen for systems meant to last: long support windows, explicit architecture, and a codebase a new team can still read in five years.
Built to outlive the build team
Healthcare systems are replaced far less often than they are handed over. Symfony long-term-support releases pair with a platform that is patched and monitored continuously, so age does not quietly become exposure.
Messenger and workers handle real records
Symfony Messenger moves work off the request. Those transports and their payloads sit inside the same isolated environment, under the same encryption, retention and audit-logging baseline as the database they came from.
Isolation you can describe to an auditor
Every tier is an AWS account dedicated to you. Being able to name the account, VPC and agreement turns an architecture diagram into something that survives an assessment.
Where our responsibility ends
Stated plainly, because knowing this before an incident is worth more than discovering it during one.
We run
- The AWS account, VPC and network isolation
- The operating system, patching and hardening
- PHP, the web server, the database and TLS
- CloudFront, the WAF, encryption, audit logging and backups
- Monitoring and infrastructure incident response
You run
- Your Symfony application, bundles and configuration
- Framework and dependency updates, unless scoped with us
- Security voters, roles and what your code does with PHI
- The systems your application integrates with and the data you send them
If a problem turns out to be the server, PHP or the infrastructure, open a ticket and we take it. If it is inside your application, we tell you what we found and hand it back with recommendations.
HIPAA hosting vs standard hosting
A $10 shared plan is not slightly less compliant; it is categorically different. Most mainstream hosts will not sign a BAA for shared hosting at any price.
Standard Hosting
Basic web hosting
HIPAA Compliant Hosting
Healthcare-grade security