Vercel now supports HIPAA compliance for enterprise customers

Vercel has announced support for HIPAA compliance for its enterprise customers, allowing healthcare organizations and other entities that handle protected health information (PHI) to use its Frontend Cloud while meeting industry-specific regulatory requirements.

With this move, Vercel becomes a business associate for healthcare customers such as hospitals, medical providers, research facilities, and insurers. Under HIPAA, these organizations are covered entities, and Vercel's role as a business associate carries certain compliance obligations.

Depending on configuration, Vercel's records may contain healthcare information that could pertain to PHI. Any additional data collected on the platform is determined by customers; Vercel does not manage or review this information. Instead, the company works to ensure customer data is stored securely within their own systems and remains highly available, consistent with its Shared Responsibility Model.

Secure Compute and network controls

Enterprise customers can further harden their digital presence with Vercel Secure Compute, which adds a layer of security by placing deployments and build containers in an isolated network. This network uses dedicated IP addresses in a customer-chosen region and is logically separated from other containers.

An isolated network with dedicated IPs gives customers more control over which resources can access their infrastructure. For AWS environments, VPC peering support allows secure tunnels within a customer's AWS infrastructure, and VPN connections are also supported, both of which reduce the number of entry points into their networks.

How the compliance milestone was reached

To support HIPAA compliance, Vercel underwent an independent third-party audit covering the HIPAA Security Rule and HITECH Breach Notification Requirements, applying the same rigor used for its SOC 2 Type 2, PCI DSS, and ISO 27001 frameworks.

The evaluation process included several steps:

  1. Understanding HIPAA requirements: Reviewing the obligations of business associates to covered entities regarding PHI protection.
  2. Conducting a risk assessment: Identifying potential risks and vulnerabilities and determining where improvements were needed.
  3. Implementing safeguards: Updating policies and procedures, including the incident response plan, with HIPAA-specific breach notification requirements. This included HIPAA-specific staff training and reviews of encryption, access, and backup controls to protect the availability and integrity of PHI should Vercel store or transmit it.
  4. Signing business associate agreements (BAAs): Vercel signs BAAs with enterprise customers who are covered entities, outlining each party's responsibilities for protecting PHI.
  5. Conducting regular audits and monitoring: Ongoing review of systems and processes, including access log reviews, vulnerability scans, and risk assessments, to maintain continuous HIPAA compliance.
  6. Staying current: Monitoring updates to the Security Rule, HITECH Breach Notification Requirements, and industry standards to keep the platform aligned with evolving requirements.

Security posture for healthcare

Healthcare organizations can now host websites and applications on Vercel with the assurance that the platform supports HIPAA compliance. The completed independent HIPAA audit reflects an ongoing commitment to protecting customer information across industries.