HIPAAmart

Technology guide

AWS and HIPAA

A service-specific starting point for reviewing AWS workloads, shared responsibility, BAA scope, identity, logging, and recovery.

Reviewed August 2026

Key considerations

  • Review the exact AWS services used and the current AWS HIPAA-eligible service information.
  • Customer identity, configuration, workload architecture, logging, key management, and backups remain customer responsibilities to analyze.
  • A BAA and eligible service do not automatically make an application compliant.

Questions to ask

  • Which services process or can access ePHI?
  • How are IAM, KMS, CloudTrail, backups, and support access configured and reviewed?
  • What is the recovery and incident path for this workload?

References