Skip to content
Industries · Healthcare

Healthcare and health tech, and the changes that break things.

For hospitals and health systems, health tech and digital health, health plans and payers, and life-sciences software teams that ship software and are examined on change and incident controls. Written for the security officer, compliance and internal audit, and for the engineering teams whose changes break things.

Error events and pull-request diffs can carry patient data, and Déjà keeps parts of both. Section 02 says which, before you connect anything.

01 · Where HIPAA sits

The administrative safeguards, control by control.

3 of the 4 HIPAA controls listed here have a receipt type that maps evidence to them. The other 1 is evidenced outside Déjà.

The Security Rule's administrative safeguards, 45 CFR 164.308, only, and of those only the standards listed here: the rest of 164.308 is evidenced outside Déjà, and is not listed. The physical safeguards (164.310), the technical safeguards (164.312) and the organisational and documentation requirements (164.314 and 164.316) are not mapped.

  • 164.308(a)(1)Security management processEvidenced by R1R1-L
  • 164.308(a)(5)Security awareness and trainingEvidenced outside Déjà
  • 164.308(a)(6)Security incident proceduresEvidenced by R1R1-L
  • 164.308(a)(8) (evidenced only by an R2)EvaluationEvidenced by R2

† 164.308(a)(8) gets evidence from a resolution receipt (R2) only. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic. Until one is issued, it gets no evidence from Déjà.

A receipt is evidence for a control, never the whole of it. What each receipt type records, and how an auditor checks it, is on HIPAA controls.

02 · Patient data: read this first

What Déjà receives and keeps, before you connect anything.

Déjà receives error events from the tools you connect and reads the diffs of your pull requests. Either can contain protected health information if your systems put it there: a patient's name in an exception message, a record number in an event tag, real records in a test fixture.

Nothing on this page says Déjà is fit to receive patient data. It says exactly what happens to patient data that reaches it.

What Déjà keeps from an error event

The alert's or issue's title becomes the title of the incident Déjà opens for it, and the incident keeps the error's type and message. From Sentry, the issue's title is also kept in Déjà's record of the delivery, for 90 days, and in the job Déjà queues to score it, and it appears in Déjà's application logs.

What reaches a receipt

When Déjà scores the incident, the receipt it issues (an R1, R1-L or R1-N) holds a signal observation: the source, the error's type, its message as the incident records it, and the field name Déjà extracted. The observation's SHA-256 hash is signed into the receipt. Receipts are not edited or deleted, so text that reaches one stays.

What Déjà does not keep

The event's full body. Déjà stores no raw webhook payload, and a delivery it cannot process is recorded by its SHA-256 digest and its length, never its body.

Older Sentry connections

A Sentry connection made through Déjà's earlier Sentry setup, which no longer creates connections, also keeps an event record: the exception's type and message; each stack frame's file, path, function, module, line and column, and whether the frame is in your app; the environment, server name and release; every tag on the event; and the Sentry user ID. Local variables and source lines are dropped when the payload is parsed.

What is removed from an error event

Nothing. No step on the error-event path looks for patient data or removes it, and the secrets scrubber below does not run on error events.

What Déjà does to a pull request

Déjà reads each GitHub pull request's changed lines, with its title and description, as it is opened, updated and merged, and from past pull requests imported when a repository is connected, and stores them. Before storing, a secrets scrubber replaces whatever matches its fixed patterns with [REDACTED]:

  • Stripe secret and publishable keys
  • AWS access key IDs and secret access keys
  • Postgres, MongoDB, MySQL and Redis connection URLs
  • API keys assigned in code or sent in an X-API-Key header
  • Bearer tokens
  • GitHub personal access and OAuth tokens
  • JSON Web Tokens
  • PEM private keys
  • Values of 20 or more characters assigned to a name ending in SECRET, PASSWORD, TOKEN or KEY
  • Hexadecimal strings of 40 or more characters

It does not look for patient data. A name, a date of birth, a record number, a social security number or a diagnosis in a changed line, a test fixture or a description is stored as written. Jane Doe, 1984-03-02, MRN 00412977, 123-45-6789 and type 2 diabetes all pass through it unchanged.

From Azure DevOps, Déjà stores a pull request's title, scrubbed the same way, and no diff. From GitLab, a merge request's title and description, scrubbed the same way, and no diff.

Where it lives

The database it is stored in is in US West (N. California) · us-west-1 only, the region written into your organisation's genesis receipt.

How long it is kept

Receipts are not deleted on any tier: no scheduled job deletes a receipt. A plan's retention period is the period its terms commit to, and the weekly retention sweep applies it only to incidents that no attribution or resolution receipt points at, and to records of signals that could not be taken in. No retention sweep or other scheduled job deletes the Sentry event records, the stored pull requests or the queued scoring jobs.

A business associate agreement

[Awaiting owner: whether Déjà signs a HIPAA business associate agreement (BAA)] Until a BAA is in place, keep patient data out of everything Déjà receives.

Your control, not Déjà's

Keep patient data out of error events where they start, with your error tracker's own scrubbing. In Sentry, that is the SDK's beforeSend hook, which runs before an event leaves your application, and Sentry's data scrubbing settings. Keep real patient records out of test fixtures, seed files and pull-request descriptions. These controls are yours, set in your own tools; Déjà does not provide them.

03 · What a health-tech SaaS gets

Selling software to health systems, SOC 2 evidence first.

A health system's security review of your software asks how you control changes and respond to incidents, often against SOC 2. Signals from Sentry, Datadog, Splunk On-Call and Alertmanager · Grafana are sealed when Déjà scores them: each one that reaches scoring ends in a signed receipt, whether or not a cause is found.

7 of the 33 SOC 2 controls listed here have a receipt type that maps evidence to them. The other 26 are evidenced outside Déjà. A receipt maps evidence to a control, never the whole of it.

Those receipts are what you show a customer's security review, and what your auditor checks. SaaS and technology providers says more about selling to regulated customers.

04 · What doesn't fit yet

Better you read it here before a sales call does.

If one of these is a requirement for the system you have in mind, Déjà does not fit it today.

A signed BAA before patient data reaches a vendor
[Awaiting owner: whether Déjà signs a HIPAA business associate agreement (BAA)] Until one is in place, patient data stays out of error events and pull requests.
HITRUST CSF mapping
Déjà's control table has no HITRUST framework, so no receipt type maps evidence to a HITRUST requirement.
Evidence for HIPAA's technical or physical safeguards
No control in Déjà's table names 164.312 or 164.310. Access control, audit controls, integrity and transmission security are evidenced outside Déjà.
Patient-data detection or redaction
Déjà does not look for patient data in what it receives. Its scrubber removes secrets that match fixed patterns, and only from pull requests.
EU or UK data residency, now
Data is held in US West (N. California) · us-west-1 only, and the region is written into your organisation's genesis receipt. No EU or UK region is offered. [Awaiting owner: EU or UK residency date, if any]
An estate mostly in Java, .NET or Go
Attribution reads Python, TypeScript and JavaScript source, and .proto and .avsc schemas. Java, C# (.NET) and Go have no parser: a changed file in one is recorded as unsupported.
GitLab, Bitbucket or GitHub Enterprise Server as your main source control
Merged changes are read from GitHub and Azure DevOps. GitHub Enterprise Server and GitLab connect but are not read, and Bitbucket cannot be connected, so changes there are never candidates.
A completed SOC 2 report before contract
No SOC 2 report is complete. Type I is in preparation. [Awaiting owner: SOC 2 Type I target date, or none]
Alerting that is Datadog only
Each alert that reaches scoring ends in a signed no-attribution record (R1-N) reading that no field was extracted. Déjà's intake keeps no title, message or stack trace, Error Tracking included, so a Datadog alert cannot name the field an attribution needs.

Walk your controls with us, before anything is connected.

Bring your control matrix and the tools you would connect. We will say which rows a receipt maps evidence to, and what Déjà would keep from each tool.

Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.