HIPAA on Render – Render Docs

HIPAA-enabled Workspaces
HIPAA-enabled workspaces require a Scale or Enterprise plan.
For details, see the pricing page.

HIPAA is a United States federal law that sets standards for protecting individuals' healthcare data. It defines administrative, physical, and technical safeguards for organizations that process or store protected health information (PHI).
Render provides HIPAA-enabled workspaces for organizations subject to HIPAA requirements. These workspaces run services and datastores on access-restricted hosts, helping to secure any PHI processed or stored by your applications. Access to these hosts by Render staff is subject to strict controls.

Setup

Before proceeding, review all important considerations below.

The following steps must be completed by a workspace admin:

  1. In the Render Dashboard, open your Workspace Settings page and scroll down to the Compliance section:

  2. Click Get Started. This opens a confirmation flow to receive Render's Business Associate Agreement (BAA).

  3. Review all enablement steps, best practices, and workspace details outlined in the confirmation flow.

  4. After you complete the confirmation flow, Render emails you a link to sign the BAA.

  5. After you sign the BAA, return to the Compliance section of your workspace settings. After about a minute, your HIPAA Compliance status updates to Pending:

  6. When you're ready, click Enable HIPAA to initiate the enablement process.

As part of enablement, Render redeploys all of your workspace's existing services and datastores to access-restricted hosts. Your services might become unavailable for a few minutes.

Render emails you when the enablement process begins, then a second time after it completes.

  1. After the process completes, your HIPAA Compliance status updates to Enabled:

Your workspace is now ready to host HIPAA-compliant applications.

Important Considerations

Before upgrading to a HIPAA-enabled workspace, note all of the following:

Where can I process and store PHI?

Never process or store PHI on Render outside of a HIPAA-enabled workspace.
Not all resources in a HIPAA-enabled workspace support HIPAA-compliant processing and storing of PHI. See the following table for details:

Resource PHI OK? Details
Live services
Web services 🟢
Static sites ❌ Static sites consist of static assets hosted at a publicly accessible URL. Those assets must not include any PHI.
Private services 🟢
Background workers 🟢
Pre-deploy commands 🟢 Pre-deploy commands can process PHI, such as when running a database migration. However, the pre-deploy command itself must not include PHI.
Cron jobs 🟢
Workflows ❌ Workflows are not available in HIPAA-enabled workspaces.
Service-generated logs ❌ Never include PHI in any message logged by any Render service, whether at build time or runtime.
Service previews and preview environments 🟢 Preview instances run on access-restricted hosts, like their production counterparts.
Datastores
Persistent disks 🟢 All disks and their daily snapshots are encrypted at rest.
Render Postgres databases 🟢 Your primary databases, read replicas, and high availability standby databases all support HIPAA-compliant workflows.
Render Key Value instances 🟢
Builds
Build artifacts ❌ This is the bundle generated by your service's build command. It includes application code, dependencies, static assets, and any other files needed to run your service. These generated files must not include PHI.
Service configuration
Infrastructure-as-code config ❌ This includes render.yaml files for Blueprints, along with Terraform configuration files.
Resource names ❌ Do not include PHI in the name you assign to any resource, including:
- Service names
- Environment variable names
- Secret file filenames
- Table or column names in your database