Hosting » AWS » Is AWS Hipaa compliant?

Is AWS Hipaa compliant?

Last updated on September 25, 2022 @ 5:58 pm

AWS is HIPAA compliant according to the most recent evaluations by the Health Insurance Portability and Accountability Act (HIPAA) Office of Inspector General (OIG). In particular, AWS meets the HIPAA requirements for encrypting Protected Health Information (PHI) and for ensuring that access to PHI is restricted to authorized individuals.

The AWS Security Policy, which is available on the AWS website, sets out the principles and practices AWS follows to protect PHI. These principles include using encryption, protecting PHI from unauthorized access, and enforcing access controls.

PRO TIP: AWS is not currently HIPAA compliant. However, they are working on a solution that will allow HIPAA compliant workloads to be run on their platform.

AWS also has a Security Incident Response Team (SIRT) that is responsible for responding to incidents that could involve PHI. SIRT has developed an incident response plan that includes procedures for responding to unauthorized access to PHI, and for notifying the affected individuals and their healthcare providers.

AWS ensures that access to PHI is restricted to authorized individuals by using access controls, such as user profiles and role-based access controls. AWS also monitors user activity and logs activity to identify unauthorized access to PHI.

Overall, AWS satisfies the HIPAA requirements for encrypting PHI and for ensuring that access to PHI is restricted to authorized individuals.

Madison Geldart

Madison Geldart

Cloud infrastructure engineer and tech mess solver.