apointoo.
HIPAA

Aptible vs Raw Cloud for a Small Healthcare Workload

cmsapointoo··8 min read

Short answer: Aptible and raw cloud solve different parts of a healthcare workload. Aptible can provide a managed control-plane and documented security model that may reduce operational work; raw cloud offers more direct control but leaves the customer responsible for assembling and proving every safeguard. As of August 15, 2026, compare the exact BAA, services, regions, support, evidence, and exit path rather than treating either option as automatically compliant.

Vendor scope and BAA boundary

Aptible’s security and compliance overview describes a managed approach for customers evaluating regulated workloads. Raw cloud providers publish eligible services and shared-responsibility terms, but the customer must assemble the architecture. In both cases, the BAA covers a defined relationship. It does not certify the application, decide legal status, or prove the data flow is minimal.

Start with the workload rather than the brand. List compute, database, storage, queue, secrets, keys, logging, monitoring, backups, support, deployment, regions, and subprocessors. For Aptible, ask which parts are included in the managed boundary and which remain customer-managed. For raw cloud, identify the service-level eligibility and the configuration owner for each part.

Record provider facts retrieved August 15, 2026. BAA terms, pricing, service coverage, region options, and support commitments can change. A current page is evidence for a dated decision, not a permanent guarantee.

Feature, region, and subprocessor review

Decision factor Managed control-plane question Raw-cloud question
Scope What services, features, and support does the agreement cover? Which exact services are eligible and covered by the BAA?
Configuration Which controls are platform defaults versus customer settings? Who builds and tests every identity, network, key, log, and backup?
Evidence What provider artifacts and customer logs are available? How will the customer produce and retain proof?
Regions Where are runtime, storage, backup, logs, and support located? How are region restrictions and cross-border access enforced?
Exit How are records and configuration exported? How are resources, keys, backups, and logs deleted?

Managed does not mean opaque is acceptable. Ask how support access works, which subprocessors are involved, how incidents are reported, and how a customer can verify deletion. Raw cloud does not mean every team should build from primitives. If the operator cannot maintain a control inventory, more flexibility can create more unowned risk.

Minimum necessary design applies in either model. Keep booking source records separate from aggregate reporting. For Google Ads, use only generic conversion data after tenant-specific legal approval. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. Keep the outbound route disabled until the tenant and counsel approve the exact payload.

Use the managed workspace review, the hosting operations review, and the shared-responsibility map to compare alternatives.

Operational burden and proof work

Estimate work in control categories, not slogans. A raw-cloud implementation typically needs a documented account or organization boundary, identity and MFA, least privilege, network controls, encryption and keys, audit logs, monitoring, backup and restore, incident response, deployment controls, vulnerability management, and offboarding. A managed platform may provide some of those, but the customer still needs application authorization, data minimization, risk analysis, and user lifecycle.

  • People: who operates, approves, reviews, and responds?
  • Process: how are changes, incidents, restores, and access reviews recorded?
  • Technology: which services enforce or merely document the control?
  • Evidence: can an auditor reproduce the current state and its effective date?

NIST SP 800-53 can provide a control vocabulary for evidence. It is not a HIPAA certification and should not be presented as one. Use the risk analysis to select controls proportionate to the workload and record residual risk.

Exit, support, and evidence questions

Test both routes with synthetic data. Deploy a small service, create a test tenant, validate denied access, inspect logs, perform a backup and restore, revoke support credentials, export the record, and verify deletion. Capture the effort, failure points, and evidence quality. This is more useful than comparing an abstract feature list.

Gate Pass condition Stop condition
Contract BAA covers actual services, features, and recipients. Scope is inferred from a badge.
Operations Named owner can run and test every safeguard. Critical control has no owner.
Evidence Configuration and tests are reproducible. Only provider marketing documents exist.
Exit Return, revoke, delete, and restore are tested. Backups or keys are not addressed.

Escalate when a managed platform excludes a needed feature, when raw cloud requires more operational coverage than the team can provide, when support crosses a region, or when a contract requires dedicated isolation. Price is an estimate until verified with current terms and workload assumptions.

Comparison decision checklist

  1. Define workload, data, roles, regions, and operational owners.
  2. Compare current BAA and service scope for Aptible or raw cloud.
  3. Map provider, customer, and shared controls.
  4. Estimate implementation and recurring evidence work, labelling estimates.
  5. Run synthetic access, restore, incident, support, and exit tests.
  6. Obtain legal, security, procurement, and tenant approval before production.

Choose the model that leaves the fewest unowned controls for this workload. Do not make a compliance claim merely because a provider uses healthcare language.

Score operational fit, not marketing breadth

Use a short scorecard with evidence behind every score: contract clarity, service scope, region control, identity, encryption, logging, backups, incident response, support, export, deletion, and operator effort. A managed platform may score higher on day-one setup while raw cloud may score higher on customization. The score is an internal planning tool, not an independent compliance rating.

Weight the score by the workload’s actual risk. A team with one operator may value a managed control-plane because it reduces the number of controls that must be assembled. A larger platform team may prefer raw primitives if it can staff 24-hour response, review changes, and produce evidence. Do not choose a model that requires an owner the business does not have.

Keep application and contract work in both budgets

Raw cloud can look inexpensive when only requests and storage are counted. Add identity, keys, logs, backups, network, deployment, monitoring, support, incident response, restore exercises, and engineering time. Managed hosting can look expensive when only a surcharge is visible. Add migration, configuration, contract review, data export, and offboarding. Label all prices and hours as estimates with assumptions and dates.

The cloud option does not decide the booking data model. Test tenant membership, minimum fields, support reveals, logs, backup restore, and deletion in either model. If the provider makes a control easier, retain evidence showing the actual configuration. If raw cloud requires a custom control, leave an executable test behind.

Keep outbound attribution independent

Do not let hosting selection become an excuse to send more information to an advertising platform. If tenant-specific counsel approves a generic conversion flow, queue it server-side, gate it by tenant, and keep a safe disabled default. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. If counsel rejects per-booking sync, the product should still support aggregate campaign reporting.

Revisit the choice when tenant count, contract requirements, region, support hours, or insurer controls change. A managed platform can be a reasonable migration step, while raw cloud can be a later optimization. The decision should be reversible where possible and supported by an exit test.

Make the selection reversible

Keep an export format, restore exercise, control inventory, and ownership record for both options. A future move is safer when the team can enumerate data, keys, logs, backups, and dependencies.

Do not lock the business into a managed or raw path before the operator has tested support, incident, restore, and deletion workflows with synthetic records.

FAQ

What is the first verification step for Aptible versus raw cloud HIPAA?

Map the workload and compare each service, region, support path, BAA term, and control owner across both options.

Which source or configuration detail could change the answer?

Provider BAA scope, managed features, region, support terms, raw-cloud service eligibility, operator capacity, and customer contract can change the decision.

Does a managed platform remove the need for risk analysis?

No. It may reduce infrastructure work, but the customer still needs a risk analysis, application controls, data minimization, and operational evidence.

What must be approved before a production claim or outbound action?

Approve the BAA, service scope, control matrix, risk analysis, and exact payload. For Google Ads, require tenant-specific legal approval and keep the event off by default.

References

Related articles