See how we host HIPAA workloads
In this short overview, we walk through how Revion designs HIPAA-ready environments, what Revion takes off your plate, and how the shared responsibility model works in practice.
Who does what under HIPAA?
We use a simple shared-responsibility model so your security, compliance, and dev teams all know exactly who owns what.
You own security in your application and how PHI is used. Revion owns security of the hosting platform. A short list of controls sits between the two and is run jointly.
| Responsibility | Owned by |
|---|---|
| PHI data and how it is used | Customer |
| Application logic, workflows and user permissions | Customer |
| End-user devices, policies and training | Customer |
| Data retention and deletion policies | Customer |
| Third-party apps and integrations that access PHI | Customer |
| Access reviews | Shared |
| Audit logging | Shared |
| Incident coordination | Shared |
| Cloud infrastructure, regions and data centers | Revion |
| Networking, VPNs, firewalls and WAF | Revion |
| OS hardening, patching, backups and restores | Revion |
| Platform IAM for admin and support access | Revion |
| Security tooling, monitoring, alerts and response | Revion |