Definition
Cloud HIPAA compliance is a shared responsibility: the provider secures the services it operates while the customer configures, uses, monitors, and governs its workload.
In practice
- A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.
Who this applies to
- Organizations hosting or processing ePHI in cloud services
- Cloud and SaaS providers
- Engineering, security, privacy, and compliance teams
What the rule asks for
- Confirm the specific service and account are covered by appropriate contractual terms.
- Configure identity, network, secrets, logging, backups, and data lifecycle controls.
- Maintain evidence of configuration, access review, monitoring, and incident response.
How teams put it into practice
- Document which controls are inherited, configured by the customer, or shared.
- Use least privilege and separate production access from everyday accounts.
- Test restore, key rotation, alerting, and break-glass access paths.
Common mistakes
- Treating a cloud provider's eligible-services list as a compliance certificate.
- Leaving audit logs, backups, or support access outside the threat model.
- Failing to review regions, subprocessors, and data residency expectations.
Questions that come up
Does a HIPAA-eligible cloud service make my app compliant?
No. Eligibility and contractual coverage are only part of the analysis. The customer still owns important architecture, configuration, process, and workforce responsibilities.
References
- Cloud Computing Guidance U.S. Department of Health & Human Services