FN/08
FIELD NOTES · ISSUE 08

The Trust Services Criteria as Terraform modules, and where the Type II evidence comes from.

June 2, 2026 13 min read SOC 2 · Terraform · IaC · AWS

SOC 2 controls in Terraform, mapped to the Trust Services Criteria

SOC 2 Type II grades whether your controls operated for months, not whether they existed on audit day. Map CC6.1 access, CC6.6 and CC6.7 encryption, CC7 detection, and CC8.1 change management to Terraform modules that produce the operating-effectiveness evidence automatically, with real HCL.

Read the post →
FN/07
FIELD NOTES · ISSUE 07

The module layout that puts your Security Rule controls in code, so the auditor reads Terraform.

June 2, 2026 14 min read HIPAA · Terraform · IaC · AWS

HIPAA Terraform reference architecture for the PHI boundary

The reference module layout for a HIPAA environment: account isolation, customer-managed keys with rotation, least-privilege IAM, centralized tamper-evident audit logging, and a plan-time policy gate around the PHI boundary, with the control-to-module crosswalk an auditor can read.

Read the post →
FN/06
FIELD NOTES — ISSUE 06

What moves to the parent, what stays in the child, and why the boundary is itself a compliance control.

May 20, 2026 15 min read HIPAA · GitLab · GCP · Argo CD

GitLab CI/CD for HIPAA: Audit-Ready Pipeline Architecture

A GitLab-specific breakdown of the parent/child architecture. What moves to the parent (gates, evidence, deploy authorization), what stays in the child (build, test, scan, sign), the artifact contract between them, and multi-project pipelines for a polyrepo split across backend, frontend, infra, networking, and security.

Read the post →
FN/05
FIELD NOTES — ISSUE 05

OIDC trust scope, self-hosted runner discipline, and reusable workflows as the compliance contract.

May 19, 2026 15 min read HIPAA · GitHub Actions · OIDC · AWS

Is GitHub HIPAA Compliant? GitHub Actions for Healthcare

Three GitHub-specific decisions separate a HIPAA-aligned GitHub Actions pipeline from a SOC 2 one. The OIDC trust scope. The runner labeling discipline. The reusable workflow boundary as the compliance contract. With Terraform, workflow YAML, and the OPA gate that ties them together.

Read the post →
FN/04
FIELD NOTES — ISSUE 04

The control map auditors actually use, with the architectural fix for each one.

May 16, 2026 15 min read HIPAA · CI/CD · Audit

HIPAA CI/CD Audit Checklist: 47 Controls Mapped (Free PDF)

The practitioner's control map we use during 2-week audit engagements. Every Security Rule control mapped to a specific pipeline touchpoint, with the CFR section, the auditor's question, what passes, what fails, and the architectural fix. Includes a printable PDF.

Read the post →
The pattern across all six posts

The Evidence-Driven Infrastructure framework, documented in full.

The Field Notes posts are individual angles on the same underlying methodology. Boundary First, Continuous Evidence, Policy as Code, and Founder-Delivered. If you want the framework as a whole instead of pattern by pattern, read the methodology page.

Read the methodology →
Free resource

The 47-Control HIPAA CI/CD Audit Checklist. Free PDF.

Every Security Rule technical safeguard mapped to a specific pipeline touchpoint. The auditor's question for each control, what passes, what fails, and the architectural fix. The reference document we use during 2-week audit engagements. Get the PDF and join the Field Notes list.

No spam. Unsubscribe anytime. Monthly Field Notes only.
Lucas Jones, Founder and Principal Platform Engineer at Stonebridge Tech Solutions
About the author

Lucas Jones

Founder & Principal Platform Engineer · Stonebridge Tech Solutions

Six years building cloud infrastructure and CI/CD pipelines in regulated environments. HIPAA, FedRAMP, and SOC 2 engagement work for healthcare and defense engineering teams across AWS, GCP, Azure, and OCI.

Read published case studies, see how we engage, read the Evidence-Driven Infrastructure methodology, or book a 20-minute scoping call.

Or just subscribe to Field Notes.

Monthly. Cloud architecture patterns, CI/CD lessons, and compliance engineering observations from active client work. No marketing, no fluff. Unsubscribe in a click.