← Rōvn home
HIPAA posture

Honest HIPAA snapshot

Rōvn is direct healthcare hiring infrastructure. We are building inside a HIPAA-eligible AWS foundation and are formalizing the operating-company program before connecting any production traffic to PHI. This page is the public version of our posture and is updated as evidence is added.

Foundation

Application-layer controls

Program status

Control areaStatus
AWS HIPAA-eligible foundation (BAA, KMS, VPC, audit, backup, restore drill)In place
Application consent ledger and signed packet eventsIn place
Formal HIPAA Security Risk AssessmentIn progress
Vendor BAA / DPA inventory and signed agreementsIn progress
Formal HIPAA policies + workforce acknowledgementsIn progress
Documented quarterly access reviewIn progress
Incident response tabletop and runbookIn progress
Production secrets fully in AWS Secrets Manager / SSMIn progress
Reviewed production application image pushed to ECR + ECS service enabledPending review
Production traffic connected to PHI backendPending
Independent third-party HIPAA assessment / SOC 2 readiness auditPlanned

What this means for hospitals

Hospitals can run direct hiring workflows on Rōvn today using verified, primary-source-checked credential data. Rōvn does not move PHI into production until the formal program above is complete. Customers contracting Rōvn for production PHI workloads will sign a BAA with Rōvn and may request the latest evidence binder under NDA.

What this means for nurses

Your credential data is yours. Rōvn does not release a packet to a hospital without your explicit consent. Every release is logged and you can revoke release at any time.

Last updated 2026-04-25. We update this page when a status changes from in progress to in place.