Technology Guides
Technology choices need a compliance context.
Evaluate the services, data flows, contracts, settings, and evidence around systems that handle ePHI.
Reviewed August 2026
Available guidance
- AWS and HIPAA
A service-specific starting point for reviewing AWS workloads, shared responsibility, BAA scope, identity, logging, and recovery.
- Microsoft Azure and HIPAA
A practical review frame for Azure services, identity, monitoring, encryption, and shared responsibility.
- Google Cloud and HIPAA
How to evaluate Google Cloud services, configurations, access, logging, and recovery for workloads involving ePHI.
- SaaS and HIPAA
Evaluate hosted applications through data flows, support, retention, identity, subprocessors, and the actual service contract.
- Generative AI and HIPAA
A focused review of prompts, outputs, model providers, retention, RAG, human review, and PHI leakage.
- APIs and HIPAA
Protect PHI at the boundaries where applications authenticate, transmit, log, transform, and authorize data.
- Email and HIPAA
A workflow-based guide to email, PHI, patient requests, misdirection, encryption decisions, and vendor responsibilities.
- Backup and HIPAA
Evaluate backup confidentiality, integrity, availability, retention, access, and restoration evidence.
- Identity Management and HIPAA
Use lifecycle, privilege, authentication, service-account, and access-review practices to protect ePHI.