Hello,
I've read HIPAA implementation post and the Implementation guide and there's no clear process for reviewing apps in advance of adopting or migrating to the cloud.
The only guidance I saw was "Ensure that all third-party applications integrated with Jira and Confluence Cloud are running in a HIPAA-compliant manner"
How does one do that? The security pages for app listings in the marketplace doesn't call out HIPAA (or BYOK) compliance.
There is an instructional page for tagging apps but that requires you to be in the cloud.
I am looking to assess in advance of adopting cloud.