Technology guide
AWS and HIPAA
A service-specific starting point for reviewing AWS workloads, shared responsibility, BAA scope, identity, logging, and recovery.
Reviewed August 2026
Key considerations
- Review the exact AWS services used and the current AWS HIPAA-eligible service information.
- Customer identity, configuration, workload architecture, logging, key management, and backups remain customer responsibilities to analyze.
- A BAA and eligible service do not automatically make an application compliant.
Questions to ask
- Which services process or can access ePHI?
- How are IAM, KMS, CloudTrail, backups, and support access configured and reviewed?
- What is the recovery and incident path for this workload?