Your first hospital deal is waiting on your infrastructure. We make it HIPAA-ready.
Encryption, audit trails, access controls, and a defensible answer to every line of the security questionnaire — engineered on AWS by the team that runs HIPAA-compliant telehealth infrastructure in production today. Fixed price. Senior engineers only.
AWS Managed Service Provider (audited) · Advanced Tier Services Partner · HIPAA telehealth infrastructure in production · Zero client security breaches
You're here because one of these just happened
- A hospital or payer sent a 200-question security review, and your honest answers would kill the deal.
- They asked for a BAA, and your infrastructure can’t back the promises it makes.
- Your product handles PHI, and “we’re on AWS, so we’re compliant” just failed with their compliance officer.
- A HIPAA consultant handed you a risk assessment full of technical findings, and your engineers build product, not safeguards.
- You’re growing past the stage where a breach would be survivable.
Every one of these is an infrastructure problem. The Security Rule’s technical safeguards are engineering requirements — and engineering them on AWS is what we do.
The technical safeguards, built as infrastructure — not as policy documents
PHI isolation & architecture
HIPAA-eligible AWS services only, in a dedicated account structure that separates PHI workloads from everything else. Your compliance scope shrinks; your answers to reviewers get simpler.
Encryption everywhere
KMS-managed encryption at rest, TLS in transit, key rotation automated. When the questionnaire asks how PHI is protected, the answer is architecture, not intention.
Audit controls (§164.312(b))
Tamper-evident, centralized logging of every access to PHI systems — CloudTrail, GuardDuty, SIEM integration — with retention a reviewer can verify.
Access control (§164.312(a))
Least-privilege IAM, MFA enforced, unique user identification, automatic session termination, emergency access procedures that exist in code, not in a binder.
Integrity & transmission security
Versioned, checksummed storage, backup and disaster recovery with tested restore times — because the Security Rule asks not only who touched PHI, but whether it survived.
Evidence, on demand
Everything is Terraform. When a reviewer asks how a safeguard is enforced, the answer is a file, not a meeting.
Fixed price. Explicit scope. Built for the deal you're trying to close.
1. Scoping call — 30 minutes
You describe where PHI lives and what the customer's security review demands. You leave with a first read on your gaps, whether we work together or not.
2. Gap review
We map your AWS environment against the Security Rule's technical safeguards — or against the risk assessment your consultant already produced.
3. Fixed-price remediation
Explicit list of what gets built and fixed, priced after discovery. Miss a milestone — you don't pay for that phase.
4. Questionnaire & review support
When the hospital's security team asks how controls are enforced, we answer in their language — on the call with you if needed.
5. Keep it compliant (optional)
Under our audited MSP practice we operate the environment year-round — monitoring, patching, access reviews, log retention — so the next customer review is a formality, not a project.
Healthcare infrastructure that holds up to review
QliqSOFT — secure healthcare communication, USA
HIPAA-compliant infrastructure migrated to Amazon EKS and operated in production. Secure texting and patient engagement for healthcare organizations — PHI in motion, every day. Case study →
Zero security breaches across every client environment we have ever operated — including years of production PHI workloads.
Why us, not a compliance consultancy
We build, they advise
HIPAA consultants produce risk assessments and policies. Somebody still has to engineer the encryption, the audit trails, the access controls. That somebody is us.
No conflict with your consultant or assessor
We're the engineering counterpart, not the competition. Your consultant keeps the compliance program; we make the infrastructure match it.
Audited ourselves
AWS independently reviewed our operations, security, and incident management before granting the MSP designation. We know what it's like to be on the reviewed side of the table.
Senior engineers, founder-led
The people on the call are the people doing the work. No account managers, no juniors on systems that touch PHI.
Consultants: an engineering partner for your technical findings
Your risk assessments surface technical gaps your clients can’t close themselves — and implementing them yourself blurs the line you need to keep. IT-Magic works as the remediation counterpart: your client gets the safeguards engineered on AWS at a fixed price, and your assessment stays independent. For a standing partnership, write to [email protected].
FAQ
Can you get us HIPAA certified?
No one can — there is no official HIPAA certification, and anyone selling you one is a red flag. HIPAA is compliance with the Privacy and Security Rules. What we do is engineer and operate infrastructure that satisfies the technical safeguards, so your risk assessment, your BAAs, and your customers’ security reviews hold up.
Will you sign a BAA?
Yes. When our engineers operate systems containing PHI, we act as a business associate and sign a BAA — that’s how the regulation works, and refusing it would tell you everything about a vendor.
Does AWS being HIPAA-eligible make us compliant?
No. AWS signs a BAA and offers HIPAA-eligible services, but compliance depends on how your environment is architected and operated — encryption, access control, audit trails, backups. That’s the shared responsibility line, and everything on your side of it is our work.
We already have a risk assessment. Can you fix the technical findings?
Yes. A findings list from your consultant is the ideal starting point — we price remediation against it directly, fixed price after a scoping review.
We're on Railway / Vercel / Heroku and a customer demands HIPAA. What now?
This is one of the most common ways companies find us. We migrate your workloads to a HIPAA-ready AWS architecture without touching your application code — your team keeps shipping while the infrastructure grows up.
Can you keep us compliant after the build?
Yes — that’s our core business. As an audited AWS MSP we operate PHI environments year-round: monitoring, patching, access reviews, log retention. Customer security reviews stop being emergencies.
Thirty minutes, one engineer, your PHI data flows
Bring the security questionnaire that’s blocking your deal — or just describe where PHI lives in your system. You’ll leave the call knowing your real gaps and what closing them costs. The read is yours either way.