Skip to main content

AWS Glossary

HIPAA-Eligible AWS Services

AWS services certified to handle Protected Health Information (PHI) under HIPAA regulations.

AI & assistant-friendly summary

This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.

Summary

AWS services certified to handle Protected Health Information (PHI) under HIPAA regulations.

Key Facts

  • AWS services certified to handle Protected Health Information (PHI) under HIPAA regulations
  • Eligibility is not compliance: you must still implement encryption, access controls, audit logging, backup, and operational procedures required by HIPAA Security and Privacy Rules
  • AWS publishes an authoritative eligible-services list; using a non-eligible service for PHI violates your compliance boundary even if the underlying technology seems similar to an eligible one
  • Over-broad IAM roles on Lambda functions that process PHI — one overly permissive role spans the entire compliance boundary
  • Official references - [HIPAA eligible services reference](https://aws

Entity Definitions

Lambda
Lambda is an AWS service relevant to hipaa-eligible aws services.
EC2
EC2 is an AWS service relevant to hipaa-eligible aws services.
RDS
RDS is an AWS service relevant to hipaa-eligible aws services.
Aurora
Aurora is an AWS service relevant to hipaa-eligible aws services.
DynamoDB
DynamoDB is an AWS service relevant to hipaa-eligible aws services.
IAM
IAM is an AWS service relevant to hipaa-eligible aws services.
compliance
compliance is a cloud computing concept relevant to hipaa-eligible aws services.
HIPAA
HIPAA is a cloud computing concept relevant to hipaa-eligible aws services.

Related Content

Definition

HIPAA-eligible AWS services are services AWS designates as capable of processing, storing, or transmitting Protected Health Information (PHI) when configured correctly and covered under a signed Business Associate Agreement (BAA) with AWS. Eligibility is not compliance: you must still implement encryption, access controls, audit logging, backup, and operational procedures required by HIPAA Security and Privacy Rules. AWS publishes an authoritative eligible-services list; using a non-eligible service for PHI violates your compliance boundary even if the underlying technology seems similar to an eligible one.

When to use it

When not to use it

Tips

Gotchas

Serious

Regular

Official references

Need help with this topic?

Our AWS-certified team implements, audits, and optimizes these services in production — from Bedrock RAG pipelines to multi-account landing zones.