First Edition · HIPAA & FDA

Ship a real health app
without getting blindsided.

The field guide for vibe coders who want to launch without a HIPAA fine or an FDA letter waiting on the other side.

See what's inside
12 chapters
~10,000 words
13 working templates
Reads in an evening
Ship Safe book cover — A Vibe Coder's Guide to HIPAA and FDA Compliance for Health Apps, by Khalid Nawab, MD, MPS-AI.

Vibe coding put a working health app in reach of anyone who can describe one. The regulators it answers to did not get easier.

Ship Safe is the handbook for builders who want to ship a real product, not a demo. Twelve chapters cover the rules that actually apply, the AI tools that will and will not sign a Business Associate Agreement, the architectural decisions that decide whether your app is a medical device, and the incident response plan you need before you have an incident.

Written from the builder's chair, not the auditor's. About 10,000 words. Reads in an evening. Gets used for years.

The bundle

One download. Everything you need.

PDF

The book, in print-ready PDF

The full text, optimized for screen and print. Twelve chapters plus seven appendices.

EPUB

Kindle & Apple Books edition

Same content as EPUB for Kindle, Apple Books, and every other e-reader.

XLSX

Editable BAA tracker

Spreadsheet with status dropdowns and five sample rows. Drop in your vendors and start tracking.

Fillable

Safeguards checklist

One-page pre-launch checklist with real form fields. Sign, date, and file it as your audit artifact.

Flowchart

SaMD decision flowchart

Full-page print version of the Software-as-a-Medical-Device classification tree.

9 cards

Quick reference cards

Nine single-page references: the 18 identifiers, BAA tree, breach clock, CDS test, self-audit, and more.

What you'll learn

Five parts, in the order they come up.

I

What HIPAA actually requires

Whether your app touches PHI, what kind of regulated entity that makes you, and what the Privacy, Security, and Breach Notification Rules each require in practical terms.

II

AI tools and HIPAA

Why AI-generated code fails HIPAA by default, which AI platforms will sign a BAA in 2026, and how to read the BAA landscape across LLM APIs, databases, hosting, email, SMS, and voice.

III

FDA and your app

The current SaMD framework, the four-part Clinical Decision Support exemption test, and the Predetermined Change Control Plan that lets you update AI models after shipping.

IV

Building compliance in

Five technical safeguards from § 164.312 written as code patterns, a 20-question pre-launch self-audit, and the difference between an app that passes its demo and one that passes its first real audit.

V

Operating after launch

Working with healthcare institutions when you get one as a customer, and the minimum viable incident response plan to have in the repo before you need it.

Who it's for

Builders, not auditors.

  • Solo founders building a health product on a modern stack.
  • Developers asked to add a "HIPAA-compliant" feature to an existing app.
  • Designers and PMs who need to understand what the engineers are deciding.
  • Physician-builders who can read code but have never thought through a BAA.
  • Anyone who prompted "build me a HIPAA-compliant patient portal" and wants to know what's missing from what came back.

Khalid Nawab, MD, MPS-AI, is a hospitalist physician with a Master of Professional Studies in Applied AI and a publication record in high-impact peer-reviewed journals. He builds health software the same way his readers do, with AI tools and an evening after clinical shifts. Ship Safe is the field guide he wishes he had the first time he shipped a HIPAA-touching app from a Sunday prompt session.

Khalid Nawab, MD · MPS in Applied AI
The full bundle
$24.99+

About the cost of a single billable hour with a healthcare-regulatory attorney. The book and templates save you several of those, plus the project time you'd lose discovering each rule the hard way.

First 100 buyers — founding price $29. Use code FOUNDING
7-day refund, no questions. Free updates for every buyer. Single-builder license.
Questions

Before you buy.

Will this make my app HIPAA-compliant?
No book can. What it does is tell you the questions an auditor will ask, the rules each maps to, the technical defaults that satisfy them in 2026, and the vendors that get you there. You still do the work. The book makes sure you know what work that is.
Is this legal advice?
No. Ship Safe is reference material written by a physician with applied-AI training, not an attorney. For any decision with real money or real patient data on the line, talk to a healthcare-regulatory lawyer. The book points you to the primary sources you and your attorney will want to read together.
How current is it?
Every regulatory claim was verified within thirty days of the First Edition publishing, and vendor BAA status reflects 2026. When something material changes, an updated bundle ships to every buyer through Gumroad.
I'm not a doctor. Will I follow it?
Yes. The book is written for builders. Clinical terms get defined the first time they appear; regulatory terms get one short clause each. The pace is set by what you need to ship a real app.
Can I share it with my team?
A single purchase covers one builder. For team or organizational licensing, email contact@knguides.com.
What's the refund policy?
Seven days, no questions, full refund. The book is honest about what it covers and what it doesn't. If it's not the right fit, send it back.

Ship safe.

If you're building anything in healthcare and you're not sure what HIPAA, the FDA, or your hosting vendor actually requires of you, this is the book.