Problem
HIPAA requires Business Associate Agreements (BAAs) with any third party that stores, processes, or transmits PHI. Engram uses:
- Cloudflare (D1, Vectorize, Workers, AI) — BAA available on Enterprise plan
- Supabase (auth, user management) — BAA available on Team/Enterprise plan
Without BAAs, Engram cannot be HIPAA-compliant regardless of technical controls.
Action items
- Determine if Engram will target HIPAA compliance (healthcare use cases)
- If yes, upgrade Cloudflare to Enterprise (or confirm BAA availability on current plan)
- Upgrade Supabase to Team/Enterprise for BAA
- Execute BAAs with both providers
- Document BAA status in compliance docs
Notes
This is a business/contractual task, not a technical one. But it gates whether HIPAA compliance is achievable.
Labels
compliance, business
Problem
HIPAA requires Business Associate Agreements (BAAs) with any third party that stores, processes, or transmits PHI. Engram uses:
Without BAAs, Engram cannot be HIPAA-compliant regardless of technical controls.
Action items
Notes
This is a business/contractual task, not a technical one. But it gates whether HIPAA compliance is achievable.
Labels
compliance, business