Solution

HIPAA compliance for aws

AWS signs a BAA and lists HIPAA-eligible services. Everything above the hypervisor is still yours.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

AWS signs a BAA and lists HIPAA-eligible services. Everything above the hypervisor is still yours.

What you get

  • Automated evidence from CloudTrail, Config, GuardDuty, KMS, and IAM
  • HIPAA-eligible service verification across your actual account estate
  • Encryption, logging, and access control checks mapped to §164.312
  • Shared responsibility documentation your auditor accepts

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

How do we actually sign a BAA with AWS?

Self-service through AWS Artifact — accept the BAA at the account or organisation level, no negotiation required. The common miss is accepting it on one account while ePHI workloads run in another; we verify coverage across your whole account estate.

Can we use AWS services that are not on the HIPAA-eligible list?

Yes, but not for ePHI. Non-eligible services are fine for workloads that never touch patient data — the risk is drift, where an engineer wires a new managed service into an ePHI pipeline without checking the list. Continuous service inventory is how you catch that.

Which AWS misconfigurations cause the most HIPAA findings?

Public or over-permissive S3 buckets, CloudTrail disabled or not retained, wide-open security groups, and IAM users with long-lived keys and no MFA. None of these are exotic — they are defaults nobody revisited after the prototype shipped.

Do we have to use KMS customer-managed keys for everything?

Encryption is an addressable specification, so you need it implemented or a documented rationale — and in practice unencrypted ePHI at rest is indefensible. Default AWS-managed encryption often suffices; CMKs add key rotation control and audit visibility where you need to demonstrate it.

Can ePHI end up in our CloudWatch logs?

Easily — application logs, request payloads, and debug output all leak identifiers if nobody scrubs them. Treat log groups as potentially in scope: restrict access, set retention deliberately, and put log hygiene in your engineering standards.

Should ePHI live in its own AWS account?

It is the cleanest scoping decision you can make. A dedicated account (or OU) shrinks the audit boundary, simplifies IAM, and lets non-PHI environments move fast without dragging them into compliance scope. If you are early, do it now — retrofitting is much more painful.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo