HIPAA on AWS — PHI protected, safeguards proven.
For US healthcare and health-tech on AWS: the HIPAA Security Rule administrative, physical and technical safeguards implemented in your account — encryption, least-privilege access, audit logging — plus risk analysis, BAA guidance and the evidence to show it. CISA · AWS Pro · 16+ years.
Protect PHI, prove the safeguards
Protect PHI in AWS
- Encryption at rest and in transit with KMS
- Least-privilege IAM, MFA, access reviews
- PHI data-flow mapping and segmentation
Security Rule safeguards
- Administrative, physical and technical safeguards
- Audit logging and monitoring (CloudTrail, Config)
- Contingency plan, backup and disaster recovery
Risk analysis & evidence
- HIPAA risk analysis and risk management
- Policies and procedures
- Evidence to demonstrate compliance
BAAs & vendors
- AWS BAA scope guidance
- Subcontractor and BAA management
- Breach-response readiness
Track record
Questions buyers ask
Does using AWS make me HIPAA compliant?
No — AWS is HIPAA-eligible under a BAA, but compliance is a shared responsibility. You still have to implement and prove the Security Rule safeguards in your account, which is what I do.
Do you help with BAAs?
Yes — the AWS BAA scope and your downstream subcontractor BAAs, so the chain of responsibility for PHI is covered.
What about the Security Rule?
I implement the administrative, physical and technical safeguards as real AWS controls and produce the documentation and evidence.
Do you perform the risk analysis?
Yes — a HIPAA risk analysis and risk-management plan are foundational, and I deliver both.
PHI protected, safeguards you can prove.
Free 30-minute call — tell me your product, your PHI flows and your timeline.