Skip to main contentChat with us

HIPAA · Cloud Compliance

HIPAA in the Cloud
AWS, Azure & GCP Guide

Running PHI workloads in the cloud requires understanding the shared responsibility model, signing BAAs, and implementing cloud-specific security controls.

Each provider requires you to sign its Business Associate Agreement (BAA) and stay within its published HIPAA-eligible services before PHI touches the cloud.

3Major clouds compared
100+AWS HIPAA-eligible services
500+Audits delivered

45 CFR Part 164 · HHS OCR · Last reviewed June 2026

Direct Answer

You can run HIPAA-regulated PHI on AWS, Azure, or Google Cloud, but each provider first requires you to sign its Business Associate Agreement (BAA) and stay within its published list of HIPAA-eligible services. Cloud HIPAA works on a shared-responsibility model: the provider secures the infrastructure while you remain responsible for configuration, encryption, access control, and your application.

Who Owns What

Shared Responsibility Model

Cloud providers secure the infrastructure; you're responsible for securing your data and applications.

Security AreaCloud ProviderCustomer
Physical Security
Network Infrastructure
Hypervisor Security
OS Patching (managed services)
OS Patching (IaaS)
Application Security
Data Encryption
Access Management
Audit Logging Config
Backup & Recovery

Build It Right

Cloud HIPAA Best Practices

Sign BAA before storing PHI
Use only HIPAA-eligible services
Enable encryption at rest and in transit
Implement least privilege access
Enable comprehensive audit logging
Configure network isolation (VPC/VNet)
Use managed key services (KMS)
Enable multi-factor authentication
Regular security assessments
Document cloud architecture

Side by Side

BAA & HIPAA-Eligible Services by Provider

All three major clouds support HIPAA workloads, but they differ in how you sign the BAA and how broadly eligibility is scoped. Always confirm a specific service against the provider's current eligibility list before placing PHI on it.

ProviderHow to sign the BAAEligible-service coverageHealthcare-native service
AWSSelf-serve via AWS Artifact100+ HIPAA-eligible servicesAWS HealthLake (FHIR)
Microsoft AzureIncluded in the Online Services / Product TermsMost Azure services coveredAzure Health Data Services
Google CloudAccept via Cloud ConsoleBAA covers all in-scope GCP servicesCloud Healthcare API

HIPAA is enforced by the US Department of Health and Human Services. See the official HHS HIPAA portal. Provider-specific, deep-dive guides: AWS, Azure, and GCP.

Frequently Asked Questions

Is AWS, Azure, or Google Cloud "HIPAA certified"?

No cloud provider is "HIPAA certified" — HIPAA is a compliance obligation, not a certification, and there is no official HIPAA certificate. What the major providers do is sign a Business Associate Agreement (BAA) and publish a list of HIPAA-eligible services. Compliance is a shared outcome: the provider covers the infrastructure, and you cover how you configure and use it.

Do I need a BAA with my cloud provider?

Yes. Before you store, process, or transmit PHI on AWS, Azure, or GCP, you must execute the provider's BAA. Without it, the provider has not agreed to its HIPAA obligations and your use of the platform for PHI is not compliant. The BAA also defines which services are in scope.

What is the shared responsibility model for HIPAA in the cloud?

The cloud provider secures the underlying infrastructure — physical data centers, networking, and the hypervisor. You are responsible for everything you control: encryption settings, identity and access management, audit logging, OS patching on IaaS, application security, and backups. Using a HIPAA-eligible service does not transfer those duties to the provider.

Does using a HIPAA-eligible service make my application compliant?

No. A HIPAA-eligible service simply means the provider will cover it under the BAA. You still have to configure it correctly — enable encryption at rest and in transit, restrict access to least privilege, turn on audit logging, isolate networks, and document it all in a Security Risk Assessment. Misconfiguration is the most common cause of cloud PHI exposure.

Which cloud is best for HIPAA workloads from India?

All three (AWS, Azure, GCP) support fully HIPAA-eligible architectures, so the right choice usually depends on your existing stack, the healthcare-specific services you need (such as AWS HealthLake, Azure Health Data Services, or the GCP Cloud Healthcare API), and your team's expertise. Tranquility Cybersecurity helps Indian teams pick and validate the right configuration for their US clients.

Written By Expert Auditors

Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations