So I am the web admin for a non-profit that deals with and discusses private medical information. My country has laws around keeping this information safe which ironically I take more seriously than a lot of the public health services I personally interact with but I digress.
With all the push for increased surveillance lately and my trying to keep pushing people towards safer alternatives, the idea I've had for setting up a private forum is starting to become more important (maybe that and my yearning for the internet of old where people on the internet were people and not a high chance of being a bot). Currently the orgs main discussion is on Facebook (yep, don't get me started on that - I did not decide that, it was many years ago and I've always hated that it excluded people who don't use FB).
We have shared hosting for the website but this severely limits options. All the software that I can install on shared hosting through cpanel has resulted in ugly, difficult to use options or gotchas like not being able to make the community private (i.e. people will want to talk about their own medical situations with other group members, not the whole world).
So my next steps are to investigate what hosting infrastructure is secure and what software will best allow for a private and secure community. I was considering Discourse but this might be overkill and I don't know if posts and DMs can be encrypted, etc. Interested in suggestions for other forum or community software that is better.
I could get AWS for non-profits but it's Amazon and I don't trust them as far as I can kick them so I don't know how safe it would be to have or if encryption would help mitigate the Amazon factor.
My knowledge of these sorts of things is pretty outdated (I'm mostly just a web des).