Aptible vs Raw Cloud for a Small Healthcare Workload
Short answer: Aptible and raw cloud solve different parts of a healthcare workload. Aptible can provide a managed control-plane and documented security model that may reduce operational work; raw cloud offers more direct control but leaves the customer responsible for assembling and proving every safeguard. As of August 15, 2026, compare the exact BAA, services, regions, support, evidence, and exit path rather than treating either option as automatically compliant.
Vendor scope and BAA boundary
Aptible’s security and compliance overview describes a managed approach for customers evaluating regulated workloads. Raw cloud providers publish eligible services and shared-responsibility terms, but the customer must assemble the architecture. In both cases, the BAA covers a defined relationship. It does not certify the application, decide legal status, or prove the data flow is minimal.
Start with the workload rather than the brand. List compute, database, storage, queue, secrets, keys, logging, monitoring, backups, support, deployment, regions, and subprocessors. For Aptible, ask which parts are included in the managed boundary and which remain customer-managed. For raw cloud, identify the service-level eligibility and the configuration owner for each part.
Record provider facts retrieved August 15, 2026. BAA terms, pricing, service coverage, region options, and support commitments can change. A current page is evidence for a dated decision, not a permanent guarantee.
Feature, region, and subprocessor review
| Decision factor | Managed control-plane question | Raw-cloud question |
|---|---|---|
| Scope | What services, features, and support does the agreement cover? | Which exact services are eligible and covered by the BAA? |
| Configuration | Which controls are platform defaults versus customer settings? | Who builds and tests every identity, network, key, log, and backup? |
| Evidence | What provider artifacts and customer logs are available? | How will the customer produce and retain proof? |
| Regions | Where are runtime, storage, backup, logs, and support located? | How are region restrictions and cross-border access enforced? |
| Exit | How are records and configuration exported? | How are resources, keys, backups, and logs deleted? |
Managed does not mean opaque is acceptable. Ask how support access works, which subprocessors are involved, how incidents are reported, and how a customer can verify deletion. Raw cloud does not mean every team should build from primitives. If the operator cannot maintain a control inventory, more flexibility can create more unowned risk.
Minimum necessary design applies in either model. Keep booking source records separate from aggregate reporting. For Google Ads, use only generic conversion data after tenant-specific legal approval. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. Keep the outbound route disabled until the tenant and counsel approve the exact payload.
Use the managed workspace review, the hosting operations review, and the shared-responsibility map to compare alternatives.
Operational burden and proof work
Estimate work in control categories, not slogans. A raw-cloud implementation typically needs a documented account or organization boundary, identity and MFA, least privilege, network controls, encryption and keys, audit logs, monitoring, backup and restore, incident response, deployment controls, vulnerability management, and offboarding. A managed platform may provide some of those, but the customer still needs application authorization, data minimization, risk analysis, and user lifecycle.
- People: who operates, approves, reviews, and responds?
- Process: how are changes, incidents, restores, and access reviews recorded?
- Technology: which services enforce or merely document the control?
- Evidence: can an auditor reproduce the current state and its effective date?
NIST SP 800-53 can provide a control vocabulary for evidence. It is not a HIPAA certification and should not be presented as one. Use the risk analysis to select controls proportionate to the workload and record residual risk.
Exit, support, and evidence questions
Test both routes with synthetic data. Deploy a small service, create a test tenant, validate denied access, inspect logs, perform a backup and restore, revoke support credentials, export the record, and verify deletion. Capture the effort, failure points, and evidence quality. This is more useful than comparing an abstract feature list.
| Gate | Pass condition | Stop condition |
|---|---|---|
| Contract | BAA covers actual services, features, and recipients. | Scope is inferred from a badge. |
| Operations | Named owner can run and test every safeguard. | Critical control has no owner. |
| Evidence | Configuration and tests are reproducible. | Only provider marketing documents exist. |
| Exit | Return, revoke, delete, and restore are tested. | Backups or keys are not addressed. |
Escalate when a managed platform excludes a needed feature, when raw cloud requires more operational coverage than the team can provide, when support crosses a region, or when a contract requires dedicated isolation. Price is an estimate until verified with current terms and workload assumptions.
Comparison decision checklist
- Define workload, data, roles, regions, and operational owners.
- Compare current BAA and service scope for Aptible or raw cloud.
- Map provider, customer, and shared controls.
- Estimate implementation and recurring evidence work, labelling estimates.
- Run synthetic access, restore, incident, support, and exit tests.
- Obtain legal, security, procurement, and tenant approval before production.
Choose the model that leaves the fewest unowned controls for this workload. Do not make a compliance claim merely because a provider uses healthcare language.
Score operational fit, not marketing breadth
Use a short scorecard with evidence behind every score: contract clarity, service scope, region control, identity, encryption, logging, backups, incident response, support, export, deletion, and operator effort. A managed platform may score higher on day-one setup while raw cloud may score higher on customization. The score is an internal planning tool, not an independent compliance rating.
Weight the score by the workload’s actual risk. A team with one operator may value a managed control-plane because it reduces the number of controls that must be assembled. A larger platform team may prefer raw primitives if it can staff 24-hour response, review changes, and produce evidence. Do not choose a model that requires an owner the business does not have.
Keep application and contract work in both budgets
Raw cloud can look inexpensive when only requests and storage are counted. Add identity, keys, logs, backups, network, deployment, monitoring, support, incident response, restore exercises, and engineering time. Managed hosting can look expensive when only a surcharge is visible. Add migration, configuration, contract review, data export, and offboarding. Label all prices and hours as estimates with assumptions and dates.
The cloud option does not decide the booking data model. Test tenant membership, minimum fields, support reveals, logs, backup restore, and deletion in either model. If the provider makes a control easier, retain evidence showing the actual configuration. If raw cloud requires a custom control, leave an executable test behind.
Keep outbound attribution independent
Do not let hosting selection become an excuse to send more information to an advertising platform. If tenant-specific counsel approves a generic conversion flow, queue it server-side, gate it by tenant, and keep a safe disabled default. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. If counsel rejects per-booking sync, the product should still support aggregate campaign reporting.
Revisit the choice when tenant count, contract requirements, region, support hours, or insurer controls change. A managed platform can be a reasonable migration step, while raw cloud can be a later optimization. The decision should be reversible where possible and supported by an exit test.
Make the selection reversible
Keep an export format, restore exercise, control inventory, and ownership record for both options. A future move is safer when the team can enumerate data, keys, logs, backups, and dependencies.
Do not lock the business into a managed or raw path before the operator has tested support, incident, restore, and deletion workflows with synthetic records.
FAQ
What is the first verification step for Aptible versus raw cloud HIPAA?
Map the workload and compare each service, region, support path, BAA term, and control owner across both options.
Which source or configuration detail could change the answer?
Provider BAA scope, managed features, region, support terms, raw-cloud service eligibility, operator capacity, and customer contract can change the decision.
Does a managed platform remove the need for risk analysis?
No. It may reduce infrastructure work, but the customer still needs a risk analysis, application controls, data minimization, and operational evidence.
What must be approved before a production claim or outbound action?
Approve the BAA, service scope, control matrix, risk analysis, and exact payload. For Google Ads, require tenant-specific legal approval and keep the event off by default.
References
- Aptible, “Security and Compliance Overview,” retrieved August 15, 2026: https://www.aptible.com/docs/core-concepts/security-compliance/overview
- National Institute of Standards and Technology, “SP 800-53 Revision 5 Update 1,” retrieved August 15, 2026: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- U.S. Department of Health and Human Services, “Cloud Computing and HIPAA,” retrieved August 15, 2026: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
Related articles
How to Run a Tabletop Exercise for Breach Notification
A breach-notification tabletop should test roles, facts, evidence, risk assessment, communications, recovery, and post-exercise actions…
Proposed HIPAA Security Rule Changes for Incident Plans
As of August 15, 2026, distinguish the HIPAA Security Rule currently in effect from proposed modifications. Prepare incident,…
HIPAA Contingency Plans: Backup, Restore, and Testing
A HIPAA contingency plan should cover backup, disaster recovery, emergency mode, restore testing, recovery objectives, and evidence. The…