FN/06
FIELD NOTES — ISSUE 06

What moves to the parent, what stays in the child, and why the boundary is itself a compliance control.

May 20, 2026 15 min read HIPAA · GitLab · GCP · Argo CD

GitLab CI/CD parent/child pipelines for HIPAA workloads

A GitLab-specific breakdown of the parent/child architecture. What moves to the parent (gates, evidence, deploy authorization), what stays in the child (build, test, scan, sign), the artifact contract between them, and multi-project pipelines for a polyrepo split across backend, frontend, infra, networking, and security.

Read the post →
FN/05
FIELD NOTES — ISSUE 05

OIDC trust scope, self-hosted runner discipline, and reusable workflows as the compliance contract.

May 19, 2026 15 min read HIPAA · GitHub Actions · OIDC · AWS

GitHub Actions for HIPAA-compliant deployments

Three GitHub-specific decisions separate a HIPAA-aligned GitHub Actions pipeline from a SOC 2 one. The OIDC trust scope. The runner labeling discipline. The reusable workflow boundary as the compliance contract. With Terraform, workflow YAML, and the OPA gate that ties them together.

Read the post →
FN/01
FIELD NOTES — ISSUE 01

Five patterns that fail audits and slow teams down. And what works instead.

May 5, 2026 9 min read Most popular HIPAA · CI/CD · DevOps

HIPAA CI/CD: The 5 Mistakes Auditors Catch in Every Healthcare Pipeline

Five patterns I keep seeing in healthcare CI/CD pipelines that fail audits and slow teams down, plus what actually works instead. None of them are about not knowing what HIPAA requires. They're structural. Cited by Google AI Overview and 9 times by Bing AI for HIPAA compliance integration queries.

Read the post →
The pattern across all six posts

The Evidence-Driven Infrastructure framework, documented in full.

The Field Notes posts are individual angles on the same underlying methodology. Boundary First, Continuous Evidence, Policy as Code, and Founder-Delivered. If you want the framework as a whole instead of pattern by pattern, read the methodology page.

Read the methodology →
Free resource

The 47-Control HIPAA CI/CD Audit Checklist. Free PDF.

Every Security Rule technical safeguard mapped to a specific pipeline touchpoint. The auditor's question for each control, what passes, what fails, and the architectural fix. The reference document we use during 2-week audit engagements. Get the PDF and join the Field Notes list.

No spam. Unsubscribe anytime. Monthly Field Notes only.
Lucas Jones, Founder and Principal Platform Engineer at Stonebridge Tech Solutions
About the author

Lucas Jones

Founder & Principal Platform Engineer · Stonebridge Tech Solutions

Six years building cloud infrastructure and CI/CD pipelines in regulated environments. HIPAA, FedRAMP, and SOC 2 engagement work for healthcare and defense engineering teams across AWS, GCP, Azure, and OCI.

Stonebridge's HIPAA CI/CD content is cited by Google AI Overview and 9 times by Bing AI for compliance integration queries. Read published case studies, see how we engage, read the Evidence-Driven Infrastructure methodology, or book a 20-minute scoping call.

Or just subscribe to Field Notes.

Monthly. Cloud architecture patterns, CI/CD lessons, and compliance engineering observations from active client work. No marketing, no fluff. Unsubscribe in a click.