# HIPAA compliant ElasticSearch application

**URL:** <https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417>\
**Category:** Elasticsearch\
**Created:** [August 30, 2013, 11:31pm UTC](https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417 "2013-08-30T23:31:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charitha\_Sathkumara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charitha_sathkumara/32/2191_2.png) [@Charitha\_Sathkumara](https://discuss.elastic.co/u/Charitha_Sathkumara)\
**Post date:** [August 30, 2013, 11:31pm UTC](https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417/1 "2013-08-30T23:31:26Z")

</div>

I am trying to implement a logging solution as part of an application that  
handles sensitive medical data. I intend on using Elasticsearch + [Searchbox.io](http://Searchbox.io)  
Jest [https://github.com/searchbox-io/Jest](https://github.com/searchbox-io/Jest) for storage and retrieval of  
this data.

HIPAA rules state that I must ensure that communications between my  
application server and elasticsearch server are encrypted.

How would I go about protecting an Elasticsearch server and communications  
between the server and the Jest client?  
Any resources/tutorials/ideas would be much appreciated.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Mohit\_Anchlia](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@Mohit\_Anchlia](https://discuss.elastic.co/u/Mohit_Anchlia)\
**Post date:** [August 30, 2013, 11:41pm UTC](https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417/2 "2013-08-30T23:41:22Z")

</div>

You might find this helpful:

> **[GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)**
>
> Contribute to sonian/elasticsearch-jetty development by creating an account on GitHub.

I haven't used it yet but planning to

On Fri, Aug 30, 2013 at 4:31 PM, Charitha Sathkumara \<  
[srilankanchurro@gmail.com](mailto:srilankanchurro@gmail.com)\> wrote:

> I am trying to implement a logging solution as part of an application that  
> handles sensitive medical data. I intend on using Elasticsearch + [Searchbox.io](http://Searchbox.io)  
> Jest [https://github.com/searchbox-io/Jest](https://github.com/searchbox-io/Jest) for storage and retrieval of  
> this data.
> 
> HIPAA rules state that I must ensure that communications between my  
> application server and elasticsearch server are encrypted.
> 
> How would I go about protecting an Elasticsearch server and communications  
> between the server and the Jest client?  
> Any resources/tutorials/ideas would be much appreciated.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![ferhatsb](https://avatars.discourse-cdn.com/v4/letter/f/977dab/32.png) [@ferhatsb](https://discuss.elastic.co/u/ferhatsb)\
**Post date:** [August 31, 2013, 9:27am UTC](https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417/3 "2013-08-31T09:27:16Z")

</div>

You can also use Nginx proxy and terminate SSL with it.

On Saturday, August 31, 2013 2:31:26 AM UTC+3, Charitha Sathkumara wrote:

> I am trying to implement a logging solution as part of an application that  
> handles sensitive medical data. I intend on using Elasticsearch + [Searchbox.io](http://Searchbox.io)  
> Jest [https://github.com/searchbox-io/Jest](https://github.com/searchbox-io/Jest) for storage and retrieval of  
> this data.
> 
> HIPAA rules state that I must ensure that communications between my  
> application server and elasticsearch server are encrypted.
> 
> How would I go about protecting an Elasticsearch server and communications  
> between the server and the Jest client?  
> Any resources/tutorials/ideas would be much appreciated.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Paul\_Brown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_brown/32/1449_2.png) [@Paul\_Brown](https://discuss.elastic.co/u/Paul_Brown)\
**Post date:** [September 2, 2013, 7:27pm UTC](https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417/4 "2013-09-02T19:27:43Z")

</div>

Hi, Charitha --

You'll need to secure both the transport to the cluster (e.g., with HTTPS as some other posters suggested) and the internal transport within the cluster; see, e.g., [https://github.com/elasticsearch/elasticsearch/pull/2105](https://github.com/elasticsearch/elasticsearch/pull/2105).

—  
prb@mult.ifario.us | Multifarious, Inc. | [http://mult.ifario.us/](http://mult.ifario.us/)

On August 30, 2013 at 4:31:30 PM, Charitha Sathkumara ([srilankanchurro@gmail.com](mailto:srilankanchurro@gmail.com)) wrote:

I am trying to implement a logging solution as part of an application that handles sensitive medical data. I intend on using Elasticsearch + Searchbox.io Jest for storage and retrieval of this data.

HIPAA rules state that I must ensure that communications between my application server and elasticsearch server are encrypted.

## How would I go about protecting an Elasticsearch server and communications between the server and the Jest client? Any resources/tutorials/ideas would be much appreciated.

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:18am UTC](https://discuss.elastic.co/t/hipaa-compliant-elasticsearch-application/13417/5 "2017-07-06T02:18:26Z")

</div>


