HIPAA and Network Security
The Health Insurance Portability and Accountability Act requires covered entities to implement technical safeguards for electronic Protected Health Information (ePHI). This includes encryption of data in transit.
What HIPAA Requires
Technical Safeguards (§ 164.312)
- **Encryption** — ePHI must be encrypted when transmitted over electronic networks
- **Audit controls** — Record and examine activity in systems containing ePHI
- **Access control** — Only authorised persons can access ePHI
- **Integrity** — Ensure ePHI is not improperly altered or destroyed
How VynVPN Addresses Each Requirement
Encryption
- AES-256 encryption on all tunnel traffic
- TLS 1.3 for control plane communications
- Forward secrecy prevents retroactive decryption
Audit Controls
- Immutable connection logs (who connected, when, which server)
- Exportable audit reports for compliance reviews
- Integration with SIEM systems (Enterprise plan)
Access Control
- Per-user provisioning and deprovisioning
- Role-based access to different server regions
- MFA required before VPN connection established
Integrity
- No data modification in transit (authenticated encryption)
- Certificate pinning prevents man-in-the-middle attacks
- DNS leak protection ensures all queries are encrypted
Business Associate Agreement
For healthcare organisations, VynVPN provides a Business Associate Agreement (BAA) on Enterprise plans. This contractually obligates us to handle connection metadata in compliance with HIPAA requirements.
Deployment Recommendation
For healthcare organisations, we recommend:
- Enterprise plan with BAA
- Strict kill switch enabled (no split tunneling)
- Australian or US server regions only
- All staff on mandatory VPN policy
- Integration with your existing identity provider via SSO