This document discusses best practices for developing HIPAA compliant applications, focusing on cloud and mobile applications. It covers compliance requirements before and during use of public clouds, recommends using a HIPAA compliant cloud provider and signing a business associate agreement. It also discusses software development practices like separating environments, data integration and third party integrations. Additional topics include operating a HIPAA compliant solution, and keeping mobile apps compliant by encrypting data and limiting PHI in notifications.