Skip to main contentChat with us

HIPAA · AWS Cloud Compliance

AWS HIPAA Compliance
Complete Implementation Guide

Build HIPAA-compliant healthcare applications on AWS. Learn about BAA signing, eligible services, architecture patterns, and implementation best practices.

AWS offers a Business Associate Addendum (BAA) through AWS Artifact — you must accept it before storing PHI, then restrict workloads to the 100+ HIPAA-eligible services it covers.

100+HIPAA-eligible AWS services
8Weeks typical implementation
500+Audits delivered

45 CFR Part 164 · HHS OCR · AWS BAA via AWS Artifact · Last reviewed June 2026

Direct Answer

To run HIPAA-regulated PHI on AWS, you accept the AWS Business Associate Addendum (BAA) through AWS Artifact and then restrict your workload to AWS's 100+ HIPAA-eligible services. Under the shared responsibility model AWS secures the underlying infrastructure, while you remain responsible for encryption, access control, audit logging, and your application — so eligibility alone does not make you compliant.

AWS Artifact

How to Sign AWS BAA

AWS offers a Business Associate Addendum (BAA) through AWS Artifact. You must sign this before storing PHI.

1

Sign into AWS Console

Log in with admin credentials

2

Navigate to AWS Artifact

Go to AWS Artifact in the console

3

Download BAA

Download the AWS Business Associate Addendum

4

Review Terms

Review the BAA terms and conditions

5

Accept Agreement

Electronically accept the BAA

6

Verify Coverage

Ensure all services you use are HIPAA-eligible

BAA Coverage

100+ HIPAA-Eligible AWS Services

AWS offers over 100 HIPAA-eligible services. Here are the most commonly used for healthcare applications:

Healthcare

AWS HealthLake

FHIR-based data store for healthcare data

Storage

Amazon S3

Object storage with encryption at rest

Database

Amazon RDS

Managed relational databases (MySQL, PostgreSQL, SQL Server)

Compute

Amazon EC2

Virtual servers with full control

Compute

AWS Lambda

Serverless compute for PHI processing

Database

Amazon DynamoDB

NoSQL database with encryption

Containers

Amazon ECS/EKS

Container orchestration services

Security

AWS KMS

Key management for encryption

Monitoring

Amazon CloudWatch

Logging and monitoring

Audit

AWS CloudTrail

API activity logging

Network

Amazon VPC

Isolated network environment

Backup

AWS Backup

Centralized backup service

Note: For a complete list of HIPAA-eligible services, visit AWS HIPAA Eligible Services Reference

Build It Right

AWS HIPAA Architecture Best Practices

Use VPC with private subnets for PHI workloads
Enable encryption at rest using AWS KMS
Enable encryption in transit (TLS 1.2+)
Implement least privilege IAM policies
Enable CloudTrail for all API activity
Use CloudWatch for monitoring and alerting
Enable S3 bucket versioning and MFA delete
Implement automated backup with AWS Backup
Use AWS Config for compliance monitoring
Enable GuardDuty for threat detection

Indicative Spend

AWS HIPAA Cost Estimates

Typical monthly costs for a small-to-medium healthcare application on AWS:

ServiceEstimated CostUsage
EC2 (t3.medium)$30-50/monthApplication server
RDS (db.t3.medium)$50-80/monthDatabase
S3 Standard$23/TB/monthPHI storage
CloudTrail$2/100k eventsAudit logging
KMS$1/key/monthEncryption keys
AWS Backup$0.05/GB/monthBackup storage

Total Estimated Cost: $200-400/month for a basic HIPAA-compliant application. Costs scale with usage, data volume, and additional services.

8-Week Plan

AWS HIPAA Implementation Timeline

Week 1-2: Planning & BAA

Sign AWS BAA, design architecture, select HIPAA-eligible services

Week 3-4: Infrastructure Setup

Configure VPC, set up encryption, implement IAM policies, enable logging

Week 5-6: Application Deployment

Deploy applications, configure monitoring, set up backups, test disaster recovery

Week 7-8: Security & Compliance

Security assessment, penetration testing, compliance documentation, training

Who Owns What

AWS Shared Responsibility for HIPAA

AWS secures the cloud; you secure what you run in it. The split below shows who owns each control for a typical PHI workload — the customer-owned rows are where most compliance gaps appear.

Control AreaOwnerWhat it covers
Physical data-center securityAWSFacilities, hardware, and global infrastructure
Hypervisor & host isolationAWSVirtualization layer separating tenants
Managed-service patchingAWSOS/runtime patching for managed services (e.g. RDS, Lambda)
Encryption configuration (KMS)CustomerEnabling encryption at rest and in transit
IAM & access managementCustomerLeast-privilege policies, MFA, key rotation
Audit logging (CloudTrail)CustomerTurning on, retaining, and reviewing logs
Guest OS patching (EC2 / IaaS)CustomerPatching the OS on instances you run
Application & data securityCustomerSecure code, input validation, PHI handling

HIPAA is enforced by the US Department of Health and Human Services — see the HHS HIPAA portal for the Security Rule, and the AWS HIPAA compliance page for the BAA.

Frequently Asked Questions

How do I sign the AWS HIPAA BAA?

AWS provides a self-serve Business Associate Addendum (BAA) through AWS Artifact in the AWS Management Console. An account administrator reviews and electronically accepts it. Once accepted, it applies to your account, and you should restrict PHI workloads to AWS HIPAA-eligible services.

Is AWS HIPAA certified?

AWS is not "HIPAA certified" — there is no such certification. Instead, AWS signs a BAA and publishes a list of HIPAA-eligible services. Compliance is shared: AWS secures the infrastructure, and you are responsible for configuring services correctly and documenting your controls through a Security Risk Assessment.

Which AWS services are HIPAA-eligible?

AWS lists 100+ HIPAA-eligible services, including AWS HealthLake, Amazon S3, RDS, EC2, Lambda, DynamoDB, EKS, KMS, CloudWatch, CloudTrail, and VPC. Eligibility changes over time, so always confirm a specific service against the current AWS HIPAA Eligible Services Reference before placing PHI on it.

What am I responsible for under the AWS shared responsibility model?

You are responsible for security "in" the cloud: encryption settings (via KMS), IAM and access control, CloudTrail audit logging, guest-OS patching on EC2, network isolation with VPC, backups, and your application code. AWS handles security "of" the cloud — the physical infrastructure, hardware, and hypervisor.

Does AWS HealthLake make my application HIPAA compliant?

No single service makes you compliant. AWS HealthLake is a HIPAA-eligible, FHIR-based data store, but you still must sign the BAA, configure encryption and access controls, enable audit logging, run a Security Risk Assessment, and execute BAAs with your US clients. The service is a building block, not a compliance guarantee.

Written By Expert Auditors

Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations