Independent vendor compliance review
Which AWS services are HIPAA eligible?
AWS can support HIPAA-regulated workloads only under the AWS Business Associate Addendum, HIPAA-eligible services, and correct customer configuration. Do not process ePHI in non-eligible AWS services or accounts that are not governed by the appropriate AWS BAA and security controls.
Direct compliance answer
AWS HIPAA, BAA, PHI, and SOC 2 snapshot
Last checked: 2026-09-17 | Confidence: High
| Direct answer | AWS can support HIPAA-regulated workloads only under the AWS Business Associate Addendum, HIPAA-eligible services, and correct customer configuration. Do not process ePHI in non-eligible AWS services or accounts that are not governed by the appropriate AWS BAA and security controls. |
|---|---|
| BAA availability | AWS customers handling PHI need the AWS Business Associate Addendum and should confirm the current HIPAA Eligible Services Reference before storing, processing, or transmitting ePHI. |
| Can it handle PHI? | Cloud workloads can expose PHI through unsupported services, logs, backups, analytics, data lakes, support access, cross-region replication, IAM mistakes, or third-party marketplace products. |
| SOC 2 caveat | AWS makes compliance artifacts, including SOC reports, available through AWS compliance resources and AWS Artifact. Review the latest report scope for the exact services and regions used. |
| What to verify | Whether the AWS BAA is accepted for the account or organization that will process, store, or transmit PHI. Whether every compute, database, storage, queue, logging, analytics, monitoring, backup, and support service is HIPAA eligible for the workload. |
Scope of this profile
Use this profile for the AWS BAA, the current AWS HIPAA Eligible Services Reference, and shared-responsibility checks across an AWS architecture.
Independent research view
AWS HIPAA service ownership checklist
The AWS BAA and eligible-services list are umbrella prerequisites. Each workload still needs service-specific scope, configuration, logging, data-copy, and downstream-system review.
| Review area | Vendor public signal | Buyer verification |
|---|---|---|
| AWS account and BAA | AWS says customers should process PHI only in services listed as HIPAA eligible under the AWS BAA. | Confirm the account or organization is covered and re-check the current eligible-services list before deployment. |
| Relational databases | Amazon RDS and Amazon Aurora have service-specific engine, region, log, snapshot, replica, backup, and export considerations. | Use the dedicated RDS or Aurora profile instead of relying on the AWS umbrella conclusion. |
| Contact center | Amazon Connect appears on AWS's HIPAA eligible services list, while recordings, transcripts, profiles, logs, and integrations create separate data paths. | Verify Connect configuration and every storage, analytics, telephony, AI, and support destination before PHI use. |
| Generative AI | Amazon Bedrock appears on AWS's HIPAA eligible services list, but model, region, prompts, outputs, logging, agents, knowledge bases, and connected services remain workload decisions. | Review the exact Bedrock architecture and data path; service eligibility alone is not a compliant AI workflow. |
HIPAA status signal
Conditional
BAA public signal
AWS BAA required
SOC 2 evidence signal
Public evidence
PHI warning: Cloud workloads can expose PHI through unsupported services, logs, backups, analytics, data lakes, support access, cross-region replication, IAM mistakes, or third-party marketplace products.
Search query answers
What is the AWS HIPAA eligible services list?
AWS maintains a HIPAA Eligible Services Reference that identifies AWS services that may be used for HIPAA-regulated workloads under the AWS BAA. Buyers still need to verify the current list, regions, architecture, logging, encryption, IAM, and downstream vendors.
Does AWS sign a BAA?
AWS provides a Business Associate Addendum path for customers handling PHI. The BAA does not make every AWS service or customer application HIPAA-ready; customers must use HIPAA-eligible services and configure the workload appropriately.
Is AWS HIPAA compliance automatic?
No. AWS operates under a shared responsibility model. HIPAA eligibility, BAA terms, service selection, region choice, encryption, access controls, logging, backups, incident response, and application design must be reviewed together.
Which AWS database services are HIPAA eligible?
AWS publishes the current HIPAA Eligible Services Reference and services-in-scope list. Amazon RDS appears in that scope, but buyers should verify the current engine, region, account, backup, support, and downstream service coverage before storing PHI.
HIPAA, BAA, and SOC 2 summary
| HIPAA | AWS states that covered entities and business associates can use AWS for workloads involving PHI when the AWS BAA and HIPAA-eligible services requirements are satisfied. AWS also lists Amazon RDS in HIPAA BAA service scope, but customer architecture and configuration remain critical. |
|---|---|
| BAA | AWS customers handling PHI need the AWS Business Associate Addendum and should confirm the current HIPAA Eligible Services Reference before storing, processing, or transmitting ePHI. |
| SOC 2 | AWS makes compliance artifacts, including SOC reports, available through AWS compliance resources and AWS Artifact. Review the latest report scope for the exact services and regions used. |
| PHI risk | Cloud workloads can expose PHI through unsupported services, logs, backups, analytics, data lakes, support access, cross-region replication, IAM mistakes, or third-party marketplace products. |
| Category | HIPAA-Compliant Databases and Cloud Services: BAA Comparison |
| Last checked | 2026-09-17 |
| Confidence | High |
Public evidence and open questions
What public sources say
- AWS publishes HIPAA compliance materials for covered entities and business associates.
- AWS maintains a HIPAA Eligible Services Reference for services that may be used under the AWS BAA.
- AWS compliance artifacts, including SOC reports, are available through AWS compliance resources and AWS Artifact.
What remains unconfirmed
- Whether the customer's exact AWS account, region, services, Marketplace products, support path, and architecture are covered.
- Whether application logs, backups, analytics, observability tools, queues, exports, and data lakes keep ePHI inside HIPAA-eligible services.
- Whether the customer's own policies, workforce access, encryption, IAM, monitoring, retention, and incident response satisfy its obligations.
What it may be used for
- HIPAA-regulated SaaS infrastructure after the AWS BAA, HIPAA-eligible services, regions, and customer controls are verified.
- Amazon RDS database workloads where the selected engine and surrounding services remain inside AWS HIPAA BAA scope.
- Healthcare application backends that have documented encryption, IAM, network, audit logging, backup, retention, and incident response controls.
What not to use it for
- Processing ePHI in AWS services that are not HIPAA eligible for the intended workflow.
- Using default IAM, logging, storage, backup, or network settings without a HIPAA security architecture review.
- Assuming AWS compliance covers your application, SaaS product, data model, workforce access, or downstream vendors.
What to verify with the vendor
- Whether the AWS BAA is accepted for the account or organization that will process, store, or transmit PHI.
- Whether every compute, database, storage, queue, logging, analytics, monitoring, backup, and support service is HIPAA eligible for the workload.
- Whether every selected AWS service, region, account, support path, logging destination, backup service, and downstream processor remains within current HIPAA-eligible scope.
- Whether PHI is excluded from unsupported services, CloudWatch logs, support tickets, telemetry, object names, non-production data, and third-party integrations.
Safer alternatives and related profiles
Safer alternatives to consider
- Healthcare-specific hosting or managed infrastructure providers when the team cannot operate AWS controls directly.
- A managed HIPAA-ready application platform with explicit BAA scope for the app, database, logging, backups, and support path.
- Keeping PHI out of the AWS workload until architecture, BAA, service scope, and security operations are reviewed.
Amazon RDS HIPAA eligibility and supported engines
HIPAA: Conditional | SOC 2: AWS public evidence
Amazon Aurora HIPAA eligibility and configuration
HIPAA: Conditional | SOC 2: AWS public evidence
Amazon Connect HIPAA contact-center eligibility
HIPAA: Conditional | SOC 2: AWS public evidence
AWS Bedrock HIPAA model and BAA checklist
HIPAA: Conditional | SOC 2: AWS public evidence
Airtable
HIPAA: Conditional | SOC 2: Public evidence
FAQ
What is the AWS HIPAA eligible services list?
AWS maintains a HIPAA Eligible Services Reference that identifies AWS services that may be used for HIPAA-regulated workloads under the AWS BAA. Buyers still need to verify the current list, regions, architecture, logging, encryption, IAM, and downstream vendors.
Does AWS sign a BAA?
AWS provides a Business Associate Addendum path for customers handling PHI. The BAA does not make every AWS service or customer application HIPAA-ready; customers must use HIPAA-eligible services and configure the workload appropriately.
Is AWS HIPAA compliance automatic?
No. AWS operates under a shared responsibility model. HIPAA eligibility, BAA terms, service selection, region choice, encryption, access controls, logging, backups, incident response, and application design must be reviewed together.
Which AWS database services are HIPAA eligible?
AWS publishes the current HIPAA Eligible Services Reference and services-in-scope list. Amazon RDS appears in that scope, but buyers should verify the current engine, region, account, backup, support, and downstream service coverage before storing PHI.
Is AWS HIPAA compliant?
AWS can support HIPAA-regulated workloads only under the AWS Business Associate Addendum, HIPAA-eligible services, and correct customer configuration. Do not process ePHI in non-eligible AWS services or accounts that are not governed by the appropriate AWS BAA and security controls.
Will AWS sign a BAA?
AWS customers handling PHI need the AWS Business Associate Addendum and should confirm the current HIPAA Eligible Services Reference before storing, processing, or transmitting ePHI.
Can AWS be used with PHI?
Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.
Does SOC 2 mean AWS is HIPAA compliant?
No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.
What should buyers verify before using AWS with PHI?
Whether the AWS BAA is accepted for the account or organization that will process, store, or transmit PHI. Whether every compute, database, storage, queue, logging, analytics, monitoring, backup, and support service is HIPAA eligible for the workload. Whether every selected AWS service, region, account, support path, logging destination, backup service, and downstream processor remains within current HIPAA-eligible scope. Whether PHI is excluded from unsupported services, CloudWatch logs, support tickets, telemetry, object names, non-production data, and third-party integrations.
Last checked and source notes
- Last checked
- 2026-09-17
- Confidence
- High
- Dataset rows
- 274 vendors
- Reviewed the current AWS HIPAA compliance materials and the HIPAA Eligible Services Reference on 2026-09-17; AWS marked the reference as last updated August 3, 2026.
- The current AWS reference lists Amazon Aurora, Amazon RDS, Amazon Connect, and Amazon Bedrock, with product-specific qualifications and model or engine exclusions where stated.
- AWS RDS security documentation describes RDS as HIPAA eligible, but this still depends on an executed BAA and customer-side controls.
- AWS HIPAA compliance
- AWS HIPAA eligible services
- AWS services in scope for HIPAA BAA
- Amazon RDS security and compliance