Industry guide
HIPAA for Cloud Providers
What cloud providers and customers should clarify about services, shared responsibility, contracts, and evidence.
Reviewed August 2026
Key considerations
- The exact service and account scope matter more than a general platform eligibility statement.
- Customer configuration, identity, logging, backups, and workload design remain material.
- Support, subprocessors, regions, and data lifecycle should be visible to customers.
Starting points
- Document service scope and inherited versus customer controls.
- Provide clear BAA and security documentation.
- Test incident, support access, key, backup, and deletion processes.