The book, in print-ready PDF
The full text, optimized for screen and print. Twelve chapters plus seven appendices.
The field guide for vibe coders who want to launch without a HIPAA fine or an FDA letter waiting on the other side.
Vibe coding put a working health app in reach of anyone who can describe one. The regulators it answers to did not get easier.
Ship Safe is the handbook for builders who want to ship a real product, not a demo. Twelve chapters cover the rules that actually apply, the AI tools that will and will not sign a Business Associate Agreement, the architectural decisions that decide whether your app is a medical device, and the incident response plan you need before you have an incident.
Written from the builder's chair, not the auditor's. About 10,000 words. Reads in an evening. Gets used for years.
The full text, optimized for screen and print. Twelve chapters plus seven appendices.
Same content as EPUB for Kindle, Apple Books, and every other e-reader.
Spreadsheet with status dropdowns and five sample rows. Drop in your vendors and start tracking.
One-page pre-launch checklist with real form fields. Sign, date, and file it as your audit artifact.
Full-page print version of the Software-as-a-Medical-Device classification tree.
Nine single-page references: the 18 identifiers, BAA tree, breach clock, CDS test, self-audit, and more.
Whether your app touches PHI, what kind of regulated entity that makes you, and what the Privacy, Security, and Breach Notification Rules each require in practical terms.
Why AI-generated code fails HIPAA by default, which AI platforms will sign a BAA in 2026, and how to read the BAA landscape across LLM APIs, databases, hosting, email, SMS, and voice.
The current SaMD framework, the four-part Clinical Decision Support exemption test, and the Predetermined Change Control Plan that lets you update AI models after shipping.
Five technical safeguards from § 164.312 written as code patterns, a 20-question pre-launch self-audit, and the difference between an app that passes its demo and one that passes its first real audit.
Working with healthcare institutions when you get one as a customer, and the minimum viable incident response plan to have in the repo before you need it.
About the cost of a single billable hour with a healthcare-regulatory attorney. The book and templates save you several of those, plus the project time you'd lose discovering each rule the hard way.
If you're building anything in healthcare and you're not sure what HIPAA, the FDA, or your hosting vendor actually requires of you, this is the book.