A practical HIPAA checklist for AWS healthcare workloads
HIPAA compliance is an organisational programme, not a product you can buy — but a lot of it comes down to how you configure your cloud. Here's a practical checklist of the technical safeguards that matter most for healthcare workloads on AWS.
Note: this is a technical starting point, not legal advice. HIPAA also requires policies, a risk analysis, and administrative safeguards beyond the cloud.
Foundations
- Sign the AWS BAA and use only HIPAA-eligible services for anything touching PHI.
- Encrypt everything. At rest with KMS (S3, EBS, RDS, backups); in transit with TLS everywhere.
- Least-privilege IAM. No shared root, MFA enforced, roles over long-lived keys, and access scoped to what each person or service actually needs.
Network & data isolation
- Run PHI workloads in private subnets; keep databases off the public internet.
- Tighten security groups and NACLs; front public services with a WAF.
- Separate environments (dev / staging / prod) — ideally separate accounts.
Logging, monitoring & detection
- CloudTrail on across all regions, logs protected and centralised.
- AWS Config, GuardDuty, and Security Hub for posture, threat detection, and continuous checks.
- Audit trails of who accessed PHI, with alerts on anomalies.
Resilience
- Automated, encrypted backups with tested restores — an untested backup is a guess.
- A documented disaster-recovery plan with agreed RPO/RTO targets.
The part checklists miss
Every item above is necessary and none of it is sufficient on its own. HIPAA readiness is a state you maintain, not a box you tick once: codify these controls in Terraform so they're consistent and reviewable, monitor for drift, and revisit your risk analysis as the system changes. The cloud makes the safeguards easy to apply — the discipline of keeping them applied is the actual work.
Working on something similar? We build and run these systems for healthcare and software teams. Talk to an engineer →