Cloud & security · 4 August 2026 · 6 min read

A practical HIPAA checklist for AWS healthcare workloads

HIPAA compliance is an organisational programme, not a product you can buy — but a lot of it comes down to how you configure your cloud. Here's a practical checklist of the technical safeguards that matter most for healthcare workloads on AWS.

Note: this is a technical starting point, not legal advice. HIPAA also requires policies, a risk analysis, and administrative safeguards beyond the cloud.

Foundations

  • Sign the AWS BAA and use only HIPAA-eligible services for anything touching PHI.
  • Encrypt everything. At rest with KMS (S3, EBS, RDS, backups); in transit with TLS everywhere.
  • Least-privilege IAM. No shared root, MFA enforced, roles over long-lived keys, and access scoped to what each person or service actually needs.

Network & data isolation

  • Run PHI workloads in private subnets; keep databases off the public internet.
  • Tighten security groups and NACLs; front public services with a WAF.
  • Separate environments (dev / staging / prod) — ideally separate accounts.

Logging, monitoring & detection

  • CloudTrail on across all regions, logs protected and centralised.
  • AWS Config, GuardDuty, and Security Hub for posture, threat detection, and continuous checks.
  • Audit trails of who accessed PHI, with alerts on anomalies.

Resilience

  • Automated, encrypted backups with tested restores — an untested backup is a guess.
  • A documented disaster-recovery plan with agreed RPO/RTO targets.

The part checklists miss

Every item above is necessary and none of it is sufficient on its own. HIPAA readiness is a state you maintain, not a box you tick once: codify these controls in Terraform so they're consistent and reviewable, monitor for drift, and revisit your risk analysis as the system changes. The cloud makes the safeguards easy to apply — the discipline of keeping them applied is the actual work.


Working on something similar? We build and run these systems for healthcare and software teams. Talk to an engineer →