diff --git a/apps/docs/pages/guides/platform/going-into-prod.mdx b/apps/docs/pages/guides/platform/going-into-prod.mdx
index 6e8bd43de81..289e437cda0 100644
--- a/apps/docs/pages/guides/platform/going-into-prod.mdx
+++ b/apps/docs/pages/guides/platform/going-into-prod.mdx
@@ -20,6 +20,8 @@ After developing your project and deciding it's Production Ready, you should run
- Enable replication on tables containing sensitive data by enabling Row Level Security (RLS) and setting row security policies:
- Go to the Authentication > Policies page in the Supabase Dashboard to enable RLS and create security policies.
- Go to the Database > Replication page in the Supabase Dashboard to manage replication tables.
+- Turn on [SSL Enforcement](/docs/guides/platform/ssl-enforcement)
+- Enable [Network Restrictions](/docs/guides/platform/network-restrictions) for your database.
- Enable 2FA on GitHub. Since your GitHub account gives you administrative rights to your Supabase project, you should protect it with a strong password and 2FA using a U2F key or a TOTP app.
- Ensure email confirmations are enabled in the `Settings > Auth` page.
- Use a custom SMTP server for auth emails so that your users can see that the mails are coming from a trusted domain (preferably the same domain that your app is hosted on). Grab SMTP credentials from any major email provider such as SendGrid, AWS SES, etc.
diff --git a/apps/docs/pages/guides/platform/shared-responsibility-model.mdx b/apps/docs/pages/guides/platform/shared-responsibility-model.mdx
index 2ff4ac625ac..5675f33bfd0 100644
--- a/apps/docs/pages/guides/platform/shared-responsibility-model.mdx
+++ b/apps/docs/pages/guides/platform/shared-responsibility-model.mdx
@@ -46,6 +46,17 @@ You are responsible for using best-practices to optimize and manage your databas
You are responsible of provisioning enough compute to run the workload that your application requires. The Supabase Dashboard provides [observability tooling](https://supabase.com/dashboard/project/_/reports/database) to help with this.
+## Managing healthcare data
+
+You can use Supabase to store and process Protected Health Information (PHI). You are responsible for the following
+
+- Signing a Business Associate Agreement with Supabase. Reach out to growth@supabase.io to get started.
+- Enabling [Point in Time Recovery](/docs/guides/platform/backups#point-in-time-recovery).
+- Turning on [SSL Enforcement](/docs/guides/platform/ssl-enforcement).
+- Enabling [Network Restrictions](/docs/guides/platform/network-restrictions).
+- Disabling [Supabase AI editor](https://supabase.com/dashboard/org/_/general) in our dashboard.
+- Encrypting PHI in your database. Consider using pgsodium's [Transparent Column Encryption](https://github.com/michelp/pgsodium#transparent-column-encryption) which comes bundled in with every Supabase project.
+
export const Page = ({ children }) =>
+
+Going from zero to a SOC2 certification was much harder, than going from SOC2 to HIPAA.
+
+We used the same auditor to streamline the process. Many of the controls required for HIPAA compliance could be mapped to the testing they had already done for SOC2. Additional evidence for encryption, audit logs, business continuity and disaster recovery exercises was unnecessary since the auditor already had access to it. And some of the HIPAA checks such as Facility Access Controls were not applicable to us since [we are a remote company](https://supabase.com/blog/why-supabase-remote).
+
+We also had to sign a Business Associate Agreement (BAA) with all of our vendors who would have access to PHI, such as AWS, and ensure that we follow their terms listed in the agreements. For example, when using AWS to store PHI, we could only use their [HIPAA Eligible Services](https://aws.amazon.com/compliance/hipaa-eligible-services-reference/). There were similar requirements from the other vendors we use and to ensure that we were complying with all their requirements.
+
+Similarly when you sign a BAA with us, you have some responsibilities you agree to when using Supabase to store PHI. These are documented in our [shared responsibility doc](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data).
+
+We made a significant change to our incident management process for HIPAA. The [HIPAA Breach Notification](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html) rules have strict requirements for handling breaches. For instance, business associates are required to notify the covered entity within 60 days of a breach. This also required us to appoint a HIPAA Security officer who would be responsible for reviewing any breach for PHI disclosure and communicating it’s impact to the Covered Entity.
+
+
+
+The not-so-fun but important stuff included updating a bunch of our policies to cover HIPAA requirements such as enforcing automatic log-offs as part of our workstation security policy. Shopping for a good Technology Errors and Omissions Insurance plan was another boring but important thing we had to finalize in the off-chance that we get hacked despite all our measures. [HIPAA fines](https://www.strongdm.com/blog/hipaa-violation-penalties) are no joke, you could rake up to 1.9 million dollars per violation per calendar year depending the severity of the breach!
+
+## Build Healthcare Apps on Supabase
+
+If you want to start developing healthcare apps on Supabase, reach out to our team [here](https://forms.supabase.com/hipaa) to sign our BAA. We are excited to see what you build!
+
+## More Launch Week 8
+
+- [Supabase Local Dev: migrations, branching, and observability](https://supabase.com/blog/supabase-local-dev)
+- [Hugging Face is now supported in Supabase](https://supabase.com/blog/hugging-face-supabase)
+- [Launch Week 8](https://supabase.com/launch-week)
+- [Coding the stars - an interactive constellation with Three.js and React Three Fiber](https://supabase.com/blog/interactive-constellation-threejs-react-three-fiber)
+- [Why we'll stay remote](https://supabase.com/blog/why-supabase-remote)
+- [Postgres Language Server](https://github.com/supabase/postgres_lsp)
diff --git a/apps/www/data/Footer.json b/apps/www/data/Footer.json
index cef2e1e8201..cf4f5de392d 100644
--- a/apps/www/data/Footer.json
+++ b/apps/www/data/Footer.json
@@ -70,6 +70,10 @@
{
"text": "SOC2",
"url": "https://forms.supabase.com/soc2"
+ },
+ {
+ "text": "HIPAA",
+ "url": "https://forms.supabase.com/hipaa"
}
]
},
diff --git a/apps/www/pages/security.mdx b/apps/www/pages/security.mdx
index 0fc22da630e..012ce8008ef 100644
--- a/apps/www/pages/security.mdx
+++ b/apps/www/pages/security.mdx
@@ -7,7 +7,7 @@ import {
CreditCardIcon,
ClipboardCheckIcon,
} from '@heroicons/react/outline'
-import { Button, IconGitHub } from 'ui'
+import { Button, IconGitHub, IconActivity } from 'ui'
import Layout from '../layouts/Layout'
import Link from 'next/link'
@@ -52,10 +52,21 @@ export const Section = ({ children, icon, img }) => (
### SOC 2
-Supabase is SOC2 Type 2 compliant. Enterprise and Teams customers can request a copy of our SOC2 [here](https://forms.supabase.com/soc2).
+Supabase is SOC2 Type 2 compliant. Enterprise and Teams customers can request a copy of our SOC2 report [here](https://forms.supabase.com/soc2).
-
+