Files
supabase/apps/docs/content/guides/platform/hipaa-projects.mdx
d1f71464f1 docs(security): document log_connections=off default and re-enable path (#47199)
## I have read the CONTRIBUTING.md file.

YES

## What kind of change does this PR introduce?

- docs update

Closes DOCS-1080.

## What is the current behavior?

- Linear item:
[DOCS-1080](https://linear.app/supabase/issue/DOCS-1080/update-hipaa-and-security-docs-to-reflect-the-log-connectionsoff)
(parent: PSQL-1307)
- Docs do not mention that Postgres `log_connections` defaults to off
for new projects, or how customers re-enable it for HIPAA/SOC 2 audit
needs.
- No customer-facing how-to for the Management API `log_connections`
setting.

## What is the new behavior?

- New guide: "Postgres connection logging" — default behavior, dashboard
instructions, Management API curl examples, compliance notes.
- HIPAA shared-responsibility, HIPAA projects, SOC 2, HIPAA compliance
FAQ, logs guide, custom-postgres-config, and product-security updated
with cross-links.
- Platform nav entry added under **Platform → Postgres Connection
Logging**.

### Proof: new guide and cross-links render

**Verified:** `pnpm lint:mdx` (pass) · local dev (all changed pages 200)
· Vercel preview (new page 200)

| Check | Result |
|-------|--------|
| `pnpm lint:mdx` | pass (exit 0) |
| Preview new guide |
[200](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/postgres-connection-logging)
|
| Preview HIPAA bullet |
[shared-responsibility-model#managing-healthcare-data](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data)
|

**Quick review links:**

- [Postgres connection logging — New guide for the `log_connections=off`
default and re-enabling via dashboard and Management
API](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/postgres-connection-logging)
- [Shared Responsibility Model — Managing healthcare data — Added
customer responsibility to keep connection logging
enabled](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data)
- [HIPAA Projects — Added connection logging to required project
configuration](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/hipaa-projects)

## Additional context

- **Before ready for review:** add dashboard screenshots once FE-3666
merges; add changelog cross-link when PSQL-1307 entry is published.
- CLI does not expose `log_connections`; how-to documents Management API
only until dashboard screenshots are added.

### Test plan

- [ ] Open [preview
guide](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/postgres-connection-logging)
— default behavior, API examples, compliance sections present
- [ ] Confirm [HIPAA shared-responsibility
bullet](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data)
links to the new guide
- [ ] Confirm Platform nav includes **Postgres Connection Logging**
- [ ] Spot-check Management API paths against
`/docs/reference/api/v1-update-postgres-config`
- [ ] After FE-3666: add Database Settings screenshots to the guide and
PR proof section

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Documentation**
* Added a full guide for enabling/disabling Postgres connection logging
(dashboard + Management API), including verification steps and examples.
* Clarified which Postgres parameters are Management API–only (CLI
limitations), with `log_connections` as an example.
* Updated HIPAA, SOC 2, and shared responsibility guidance to recommend
keeping Postgres connection logging enabled, plus added related
FAQ/resources.
* Expanded telemetry logs documentation with “Logging Postgres
connections” and Logs Explorer visibility notes.
* **UI / Navigation**
* Added the new “Postgres Connection Logging” entry to the Platform
configuration navigation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-06-23 08:14:56 -07:00

30 lines
1.9 KiB
Plaintext

---
id: 'hipaa'
title: 'HIPAA Projects'
description: 'Projects that store or process Protected Health Information (PHI) and other sensitive data'
---
You can use Supabase to store and process Protected Health Information (PHI). If you want to start developing healthcare apps on Supabase, reach out to the Supabase team [here](https://forms.supabase.com/hipaa2) to sign the Business Associate Agreement (BAA).
<Admonition type="note">
Organizations must have a signed BAA with Supabase and have the Health Insurance Portability and Accountability Act (HIPAA) add-on enabled when dealing with PHI.
</Admonition>
## Configuring a HIPAA project
When the HIPAA add-on is enabled on an organization, projects within the organization can be configured as _High Compliance_. This configuration can be found in the [General Project Settings page](/dashboard/project/_/settings) of the dashboard.
Once enabled, additional security checks will be run against the project to ensure the deployed configuration is compliant. These checks are performed on a continual basis and security warnings will appear in the [Security Advisor](/dashboard/project/_/advisors/security) if a non-compliant setting is detected.
The required project configuration is outlined in the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) for managing healthcare data.
These include:
- Enabling [Point in Time Recovery](/docs/guides/platform/backups#point-in-time-recovery) which requires at least a [small compute add-on](/docs/guides/platform/compute-add-ons).
- Turning on [SSL Enforcement](/docs/guides/platform/ssl-enforcement).
- Enabling [Network Restrictions](/docs/guides/platform/network-restrictions).
- Keeping [Postgres connection logging](/docs/guides/platform/postgres-connection-logging) enabled.
Additional security checks and controls will be added as the security advisor is extended and additional security controls are made available.