Community

AWS HIPAA Compliance: What Healthcare Organizations Need to Know

By 4 min read 458 views
Featured image for AWS HIPAA Compliance: What Healthcare Organizations Need to Know

AWS HIPAA Compliance Overview

AWS is designated as a HIPAA-compliant cloud provider, meaning it has signed Business Associate Agreements (BAAs) with healthcare customers and maintains the administrative, physical, and technical safeguards required under the HIPAA Security Rule. This designation allows covered entities and their business associates to use select AWS services for handling protected health information (PHI). However, AWS compliance is a shared responsibility: AWS secures the underlying infrastructure, while customers must configure services properly and manage their own data handling practices.

More from this site

Keep reading the latest coverage

Browse latest →

AWS Services Eligible for HIPAA Workloads

Not every AWS service is authorized to process PHI. AWS maintains a growing list of HIPAA-eligible services that have been reviewed and can be used under a BAA. Common services used in healthcare environments include Amazon EC2 for compute, Amazon S3 for object storage, Amazon RDS for managed databases, Amazon Lambda for serverless functions, and AWS Key Management Service (KMS) for encryption key management. Customers must verify that the specific service they intend to use is on the current eligible services list and configure it according to HIPAA requirements before storing or transmitting PHI.

Key AWS HIPAA-eligible service categories

  • Compute: Amazon EC2, AWS Lambda, Amazon ECS, Amazon EKS
  • Storage: Amazon S3, Amazon EBS, Amazon FSx
  • Databases: Amazon RDS, Amazon DynamoDB, Amazon Redshift
  • Networking and security: AWS VPC, AWS Shield, AWS WAF, AWS IAM
  • Monitoring and logging: Amazon CloudWatch, AWS CloudTrail, Amazon GuardDuty

HIPAA Compliance Requirements on AWS

AWS provides the tools and infrastructure to meet HIPAA requirements, but the customer bears the responsibility for implementing them. Key requirements include conducting a risk assessment, implementing access controls that enforce the principle of least privilege, encrypting PHI both at rest and in transit, maintaining audit logs of all access and changes, and establishing incident response and disaster recovery procedures. AWS Config, AWS Security Hub, and Amazon Macie can help customers continuously monitor their configurations and detect potential compliance gaps.

Shared responsibility model for HIPAA on AWS

AWS ResponsibilityCustomer Responsibility
Physical security of data centersConfiguring IAM policies and access controls
Infrastructure and hypervisor patchingEncrypting PHI at rest and in transit
Network infrastructure securityEnabling and reviewing audit logs (CloudTrail, CloudWatch)
Compliance certifications and attestationsConducting risk assessments and business continuity planning

Business Associate Agreement (BAA) and Account Setup

To use AWS for HIPAA-eligible workloads, an organization must first execute a BAA with AWS. The BAA is available for most commercial AWS customers and outlines the permitted uses of PHI and each party's obligations under HIPAA. Once the BAA is in place, the customer should create a dedicated AWS account or organizational unit for healthcare workloads, apply service control policies, and restrict access to only HIPAA-eligible services. Mixing non-HIPAA workloads with PHI in the same account increases the risk of accidental exposure and complicates compliance audits.

Best Practices for Maintaining AWS HIPAA Compliance

Healthcare organizations should adopt a defense-in-depth approach. This includes enabling encryption by default using AWS KMS or customer-managed keys, enforcing multi-factor authentication for all users with access to PHI, using VPCs with private subnets and security groups to isolate workloads, and leveraging AWS Organizations to apply consistent guardrails across accounts. Regularly reviewing AWS Trusted Advisor and AWS Security Hub findings, conducting periodic penetration tests (with prior AWS approval), and maintaining an inventory of all resources that store or process PHI are essential ongoing practices.

AWS HIPAA Compliance and the Cloud Controls Matrix

AWS maps its controls to the HIPAA Security Rule and the NIST Cybersecurity Framework, and makes these mappings available through the AWS Artifact portal. Customers can download compliance reports, including SOC 2 and HITRUST CSF attestations, to support their own compliance documentation. While these reports provide evidence of AWS's control environment, customers must still validate that their own configurations and processes meet HIPAA requirements for their specific use case.

Editor's pick

Keep exploring our latest stories

Fresh reads, picked daily.

Browse latest
Share: