HIPAAmart

Technology · 8 min read

Cloud and HIPAA

Understand shared responsibility, BAAs, identity, logging, encryption, and why an eligible cloud service is not the whole compliance program.

Reviewed August 2026

Definition

Cloud HIPAA compliance is a shared responsibility: the provider secures the services it operates while the customer configures, uses, monitors, and governs its workload.

In practice

  • A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.

Who this applies to

  • Organizations hosting or processing ePHI in cloud services
  • Cloud and SaaS providers
  • Engineering, security, privacy, and compliance teams

What the rule asks for

  • Confirm the specific service and account are covered by appropriate contractual terms.
  • Configure identity, network, secrets, logging, backups, and data lifecycle controls.
  • Maintain evidence of configuration, access review, monitoring, and incident response.

How teams put it into practice

  • Document which controls are inherited, configured by the customer, or shared.
  • Use least privilege and separate production access from everyday accounts.
  • Test restore, key rotation, alerting, and break-glass access paths.

Common mistakes

  • Treating a cloud provider's eligible-services list as a compliance certificate.
  • Leaving audit logs, backups, or support access outside the threat model.
  • Failing to review regions, subprocessors, and data residency expectations.

Questions that come up

Does a HIPAA-eligible cloud service make my app compliant?

No. Eligibility and contractual coverage are only part of the analysis. The customer still owns important architecture, configuration, process, and workforce responsibilities.

References