Terraform patterns for HIPAA-aligned cloud
Terraform doesn't make you compliant, but it makes compliance repeatable and reviewable. These six patterns keep a HIPAA-aligned cloud consistent as it grows.
Keep state remote, locked, and encrypted
Never keep Terraform state for shared infrastructure on a laptop. Use a remote backend — an encrypted S3 bucket with a DynamoDB lock, or the equivalent — so state is versioned, access-controlled, and safe from two people applying at once. State often contains secrets; treat the backend like production data.
Build with modules, not copy-paste
Wrap your VPC, encrypted database, and cluster patterns in reusable modules. A good module bakes the secure defaults in — private subnets, KMS encryption, sane security groups — so every environment inherits them instead of re-deciding each time.
Least privilege, expressed in code
Scope IAM policies to specific actions and resources; avoid * wildcards and shared admin roles. Because it's code, access decisions are reviewable in a pull request and auditable over time — exactly what an assessor wants to see.
Encrypt and tag by default
Turn on KMS encryption for storage, databases, and backups as a default, not an option. Enforce consistent tags (owner, environment, data-classification) so you can find, govern, and bill PHI workloads later.
Scan before you apply
Run tfsec and Checkov in CI so misconfigurations — a public bucket, an open security group, an unencrypted volume — are caught in the pull request, not in production. Policy-as-code turns "please remember to" into "the pipeline won't let you."
Detect drift
Run terraform plan on a schedule and alert on drift. Manual console changes are how a compliant environment quietly stops being compliant; drift detection catches them early.
Working on something similar? We build and run these systems for healthcare and software teams. Talk to an engineer →