Cloud & security · 5 August 2026 · 7 min read

Terraform patterns for HIPAA-aligned cloud

Terraform doesn't make you compliant, but it makes compliance repeatable and reviewable. These six patterns keep a HIPAA-aligned cloud consistent as it grows.

Keep state remote, locked, and encrypted

Never keep Terraform state for shared infrastructure on a laptop. Use a remote backend — an encrypted S3 bucket with a DynamoDB lock, or the equivalent — so state is versioned, access-controlled, and safe from two people applying at once. State often contains secrets; treat the backend like production data.

Build with modules, not copy-paste

Wrap your VPC, encrypted database, and cluster patterns in reusable modules. A good module bakes the secure defaults in — private subnets, KMS encryption, sane security groups — so every environment inherits them instead of re-deciding each time.

Least privilege, expressed in code

Scope IAM policies to specific actions and resources; avoid * wildcards and shared admin roles. Because it's code, access decisions are reviewable in a pull request and auditable over time — exactly what an assessor wants to see.

Encrypt and tag by default

Turn on KMS encryption for storage, databases, and backups as a default, not an option. Enforce consistent tags (owner, environment, data-classification) so you can find, govern, and bill PHI workloads later.

Scan before you apply

Run tfsec and Checkov in CI so misconfigurations — a public bucket, an open security group, an unencrypted volume — are caught in the pull request, not in production. Policy-as-code turns "please remember to" into "the pipeline won't let you."

Detect drift

Run terraform plan on a schedule and alert on drift. Manual console changes are how a compliant environment quietly stops being compliant; drift detection catches them early.


Working on something similar? We build and run these systems for healthcare and software teams. Talk to an engineer →