Search Support Login
← Back to Blog
Engineering July 2026

The Other CIA: Why We Built DispoHealth's Architecture on AWS

Confidentiality, Integrity, and Availability — and why HIPAA compliance and HITRUST readiness had to be structural, not aspirational.

Rosa L. Smothers
Rosa L. Smothers
Co-Founder & Chief Technology Officer

As I mentioned in my previous post, there's a running joke on our team that I brought two "CIAs" to this company. The first is the mission-centric instinct I carry from my years at the CIA — the belief that you don't build systems for their own sake, you build them because lives and time-critical decisions depend on getting the right signal to the right person before the window closes. I've written about that side of the story elsewhere.

This post is about the second CIA: Confidentiality, Integrity, and Availability — the foundational triad of information security. In most industries, that triad is a best practice. In healthcare, it's not optional. It's the whole game, and it's shaped nearly every architectural decision we've made at DispoHealth.

Why This Had to Be a Day-One Decision, Not a Retrofit

DispoHealth orchestrates patient disposition workflows across care teams, which means we're touching protected health information (PHI) by definition. That's not a side effect of what we're building — it's central to it. So the question was never "how do we bolt on compliance before a sales call." It was "how do we architect this so that HIPAA compliance and HITRUST readiness are structural, not aspirational."

We're building toward HITRUST CSF v11.7.0 e1 certification from day one, and we made a deliberate choice to build our infrastructure on AWS to get there. Here's the actual reasoning, not just the marketing version.

Confidentiality: Keeping PHI Where It Belongs

Confidentiality is about ensuring that only the people and systems authorized to see patient data can see it — nothing more, nothing less.

AWS maintains HIPAA eligibility across a broad set of its services and offers a streamlined process for executing Business Associate Agreements (BAAs), which is the legal backbone that allows us to process PHI on the platform at all. Practically, that means we can architect DispoHealth using AWS's HIPAA-eligible services with a clear, auditable trail of exactly which components are in scope for PHI handling and which aren't — an important distinction when an assessor eventually walks through our environment.

On top of that legal foundation, AWS provides end-to-end encryption for data in transit and at rest, along with granular Identity and Access Management (IAM). That combination lets us enforce least-privilege access down to the individual role — a case manager's workflow tooling doesn't need, and doesn't get, the same access as a billing system integration. Confidentiality isn't a policy document in our environment; it's enforced at the infrastructure layer.

Integrity: Making Sure the Data — and the Signal — Can Be Trusted

Integrity means the data hasn't been tampered with, and that when our platform tells a case manager a patient is likely ready for discharge in 24 to 48 hours, that signal is trustworthy and traceable.

This is where network isolation and segmentation matter. AWS gives us the tools to keep our production PHI environment logically and physically separated from lower-trust surfaces, like our public marketing infrastructure, which we deliberately run in a completely separate AWS account. That boundary means a compromise or misconfiguration on the marketing side has no path to the systems that actually touch patient data.

In a regulated healthcare environment, "we believe the data is correct" isn't good enough; you need to be able to prove it, months later, to an auditor.

Integrity also depends on comprehensive audit trails and fine-grained access controls — knowing not just who could access something, but who did, and when.

Availability: Being There When It Matters Most

Availability is the leg of the triad that's easiest to overlook until it fails at the worst possible moment. A predictive orchestration platform that goes down during a discharge crunch isn't just an inconvenience — it's actively in the way of the exact workflow it's supposed to be accelerating.

AWS's global infrastructure, spanning more Availability Zones than any other major cloud provider, gives us the resilience backbone to keep the platform running through regional failures, traffic spikes, and the unpredictable rhythm of hospital operations, which don't pause for maintenance windows.

The Compliance Pedigree Behind the Infrastructure

Beyond the individual technical controls, we leaned on AWS because of the depth of its independent, third-party-assessed compliance posture:

HITRUST CSF certification

Directly relevant to our own HITRUST v11.7.0 e1 certification path, since we inherit a mature security baseline rather than building one from scratch.

SOC 1, 2, and 3 reports · ISO 27001, 27017, and 27018

The kind of independently audited evidence that healthcare security and compliance teams expect to see during vendor due diligence.

FedRAMP authorization

Not an immediate requirement for us today, but relevant to where I believe the compliance bar for healthcare infrastructure vendors is heading, and something I want us positioned for rather than scrambling toward later.

Shared Responsibility: We Don't Get to Outsource This

One of the most important things about building on AWS isn't what AWS does for us — it's the clarity of what AWS explicitly does not do for us. Under the shared responsibility model, AWS secures the cloud: the physical facilities, the host operating system, the virtualization layer, the infrastructure that everything else sits on. We are responsible for security in the cloud: our guest operating systems and patching, our application-level security, our encryption key management, and our own access controls and audit logging.

I like that division of labor, honestly. It means we can't quietly point to a vendor's certifications and call our compliance obligations satisfied. We're accountable, architecturally, for the parts of this system that are actually ours — which is exactly how it should be when the data in question belongs to someone in a hospital bed who never got a vote in how it's protected.

Why This Matters Beyond the Checkbox

None of this is about collecting logos for a compliance page. Confidentiality, Integrity, and Availability map directly onto trust — the trust of hospital security and compliance teams evaluating us as a vendor, and the trust of patients whose most sensitive information flows through our platform during one of the more vulnerable moments of their lives.

Building this the right way, from day one, on infrastructure designed for exactly this kind of regulated workload, is how we earn that trust before we ever have to defend it in an audit.

Become a Founding DispoHealth Partner

We're partnering with a small group of forward-looking health systems ahead of launch.

Get in touch