Home / Companies / Postman / Blog / Post Details
Content Deep Dive

Postman is HIPAA-Compliant

Blog post from Postman

Post Details
Company
Date Published
Author
Sam Chehab
Word Count
572
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

Postman demonstrates a strong commitment to ensuring HIPAA compliance by continuously testing and enhancing its security measures to protect customer data while minimizing friction for users. Historically, Postman required customers to implement Advanced Security Administration (ASA) features like Bring Your Own Key (BYOK) encryption, which posed challenges for customers not using AWS environments. However, advancements in Postman's baseline security controls now independently satisfy HIPAA's technical safeguards, eliminating the need for mandatory ASA features, though BYOK remains available for those who prefer managing their encryption keys. The company dedicated approximately 700 hours over a year to thoroughly examine data movement within its platform, validate controls, and enhance data protection measures such as encryption, access control, and data classification, thereby ensuring robust protection of sensitive information. Postman continues to innovate by investing in stronger security controls and governance practices, particularly as it explores new areas like AI, and encourages potential healthcare customers to engage with its Trust Center for further information.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 5,735 1,391 247 -9%
Secrets Management 1 2,152 360 101 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.