Independent vendor compliance review
Is AWS Bedrock HIPAA compliant?
Amazon Bedrock may support HIPAA-regulated AI workloads because AWS lists it as HIPAA eligible, with stated exclusions for Fable and Mythos models. PHI use still requires the AWS BAA plus model, region, prompt, output, logging, agent, knowledge-base, storage, and integration review.
Direct compliance answer
AWS Bedrock HIPAA, BAA, PHI, and SOC 2 snapshot
Last checked: 2026-09-17 | Confidence: High
| Direct answer | Amazon Bedrock may support HIPAA-regulated AI workloads because AWS lists it as HIPAA eligible, with stated exclusions for Fable and Mythos models. PHI use still requires the AWS BAA plus model, region, prompt, output, logging, agent, knowledge-base, storage, and integration review. |
|---|---|
| BAA availability | PHI use requires the relevant AWS account or organization to be covered by the AWS BAA and every service, model, region, and connected component to remain within current eligible scope. |
| Can it handle PHI? | Bedrock PHI can appear in prompts, files, retrieved context, embeddings, vector stores, agent memory, tool calls, outputs, logs, evaluations, traces, support cases, and downstream application databases. |
| SOC 2 caveat | AWS compliance artifacts are available through AWS Artifact. Review the latest report scope for Amazon Bedrock, the selected region and model, and supporting AWS services. |
| What to verify | Whether the AWS BAA is accepted for the account or organization invoking Amazon Bedrock. Whether the exact model, region, endpoint, agents, knowledge bases, guardrails, evaluation features, logging, storage, and support path are currently eligible. |
Scope of this profile
Use this profile for Amazon Bedrock model eligibility, AWS BAA prerequisites, stated model exclusions, and prompts, outputs, logs, agents, knowledge bases, storage, and integration review.
Independent research view
AWS Bedrock HIPAA model and data-path checklist
Bedrock eligibility is a vendor-side prerequisite. The AI workload still depends on the AWS BAA, exact model and region, data paths, application behavior, and customer controls.
| Review area | Vendor public signal | Buyer verification |
|---|---|---|
| Model eligibility | AWS lists Amazon Bedrock as HIPAA eligible while excluding Fable and Mythos models in the current reference. | Re-check the current model and region list before deployment and after material model changes. |
| AWS BAA | PHI use requires the relevant AWS account or organization to be covered by the AWS BAA. | Verify agreement acceptance and account ownership before sending PHI to a Bedrock endpoint. |
| AI data copies | Prompts, files, outputs, retrieved context, embeddings, vector stores, traces, evaluations, and invocation logs can contain PHI. | Map storage, logging, retention, encryption, deletion, access, and human-review paths for every copy. |
| Application responsibility | Bedrock eligibility does not cover prompt design, output accuracy, application logic, agents, tools, or downstream vendors. | Govern minimum-necessary use, IAM, network isolation, hallucination risk, monitoring, incident response, and integrations. |
HIPAA status signal
Conditional
BAA public signal
AWS BAA required
SOC 2 evidence signal
AWS public evidence
PHI warning: Bedrock PHI can appear in prompts, files, retrieved context, embeddings, vector stores, agent memory, tool calls, outputs, logs, evaluations, traces, support cases, and downstream application databases.
Search query answers
Is AWS Bedrock HIPAA compliant?
AWS lists Amazon Bedrock as HIPAA eligible, excluding Fable and Mythos models. That eligibility is conditional: verify the AWS BAA, current model and region scope, prompts, outputs, logs, agents, knowledge bases, guardrails, support access, and connected services before PHI use.
Does Amazon Bedrock require a BAA for PHI?
Yes. A PHI workflow should use an AWS account or organization covered by the AWS BAA and only current HIPAA-eligible services, models, regions, and downstream components.
Does Amazon Bedrock use customer data to train foundation models?
AWS states that Amazon Bedrock does not share customer prompts and outputs with model providers or use them to improve base models. Buyers should still verify current terms, invocation logging, evaluation data, support paths, and every connected service.
Which Amazon Bedrock models are excluded from HIPAA eligibility?
The AWS HIPAA Eligible Services Reference reviewed on September 17, 2026 lists Amazon Bedrock while excluding Fable and Mythos models. Re-check the current AWS list before implementation because model availability and eligibility can change.
Can Amazon Bedrock process PHI?
Potentially, but only within a reviewed AWS architecture under the AWS BAA. Govern prompts, uploaded data, outputs, embeddings, vector stores, agents, knowledge bases, logs, evaluation datasets, retention, human review, and downstream applications.
HIPAA, BAA, and SOC 2 summary
| HIPAA | AWS lists Amazon Bedrock as HIPAA eligible and explicitly excludes Fable and Mythos models in the current reference. Eligibility does not establish compliance for the customer's AI application or data flow. |
|---|---|
| BAA | PHI use requires the relevant AWS account or organization to be covered by the AWS BAA and every service, model, region, and connected component to remain within current eligible scope. |
| SOC 2 | AWS compliance artifacts are available through AWS Artifact. Review the latest report scope for Amazon Bedrock, the selected region and model, and supporting AWS services. |
| PHI risk | Bedrock PHI can appear in prompts, files, retrieved context, embeddings, vector stores, agent memory, tool calls, outputs, logs, evaluations, traces, support cases, and downstream application databases. |
| Category | HIPAA-Compliant AI Chatbots and Assistants |
| Last checked | 2026-09-17 |
| Confidence | High |
Public evidence and open questions
What public sources say
- AWS lists Amazon Bedrock as HIPAA eligible, excluding Fable and Mythos models.
- AWS states that Amazon Bedrock encrypts data in transit and at rest and supports AWS KMS and PrivateLink controls.
- AWS states that Amazon Bedrock does not share customer prompts and outputs with model providers or use them to improve base models.
What remains unconfirmed
- Whether the buyer's exact model, region, API feature, agent, knowledge base, guardrail, evaluation, support path, and downstream services are covered.
- Whether invocation logs, CloudWatch or S3 destinations, vector stores, data sources, retrieved context, outputs, and human review tools contain PHI.
- Whether the customer's application policies, identity controls, prompt design, minimum-necessary rules, testing, monitoring, and incident response are sufficient.
What it may be used for
- HIPAA-regulated AI workloads after AWS BAA acceptance and exact model, region, service, logging, storage, and integration review.
- PHI-minimized summarization, classification, extraction, or assistant workflows with governed prompts, outputs, access, retention, and human review.
- Architecture review for teams comparing AWS Bedrock with other BAA-backed enterprise AI services.
What not to use it for
- Submitting PHI before the AWS BAA and current Bedrock model, region, feature, and connected-service eligibility are verified.
- Using Fable or Mythos models for PHI based on the current AWS exclusion.
- Assuming Bedrock service eligibility covers the customer's application, prompt design, output accuracy, logs, vector database, agents, or downstream vendors.
What to verify with the vendor
- Whether the AWS BAA is accepted for the account or organization invoking Amazon Bedrock.
- Whether the exact model, region, endpoint, agents, knowledge bases, guardrails, evaluation features, logging, storage, and support path are currently eligible.
- Where prompts, files, outputs, retrieved context, embeddings, traces, invocation logs, and evaluation data are stored and retained.
- How IAM, network isolation, KMS keys, minimum-necessary prompting, human review, hallucination risk, deletion, monitoring, and incident response are governed.
Safer alternatives and related profiles
Safer alternatives to consider
- ChatGPT or the OpenAI API only where the exact eligible product and BAA scope are verified for the intended PHI workflow.
- A healthcare-specific AI platform with explicit BAA, retention, model, and integration scope.
- A de-identified workflow that excludes PHI when full AI architecture review is not available.
FAQ
Is AWS Bedrock HIPAA compliant?
AWS lists Amazon Bedrock as HIPAA eligible, excluding Fable and Mythos models. That eligibility is conditional: verify the AWS BAA, current model and region scope, prompts, outputs, logs, agents, knowledge bases, guardrails, support access, and connected services before PHI use.
Does Amazon Bedrock require a BAA for PHI?
Yes. A PHI workflow should use an AWS account or organization covered by the AWS BAA and only current HIPAA-eligible services, models, regions, and downstream components.
Does Amazon Bedrock use customer data to train foundation models?
AWS states that Amazon Bedrock does not share customer prompts and outputs with model providers or use them to improve base models. Buyers should still verify current terms, invocation logging, evaluation data, support paths, and every connected service.
Which Amazon Bedrock models are excluded from HIPAA eligibility?
The AWS HIPAA Eligible Services Reference reviewed on September 17, 2026 lists Amazon Bedrock while excluding Fable and Mythos models. Re-check the current AWS list before implementation because model availability and eligibility can change.
Can Amazon Bedrock process PHI?
Potentially, but only within a reviewed AWS architecture under the AWS BAA. Govern prompts, uploaded data, outputs, embeddings, vector stores, agents, knowledge bases, logs, evaluation datasets, retention, human review, and downstream applications.
Will AWS Bedrock sign a BAA?
PHI use requires the relevant AWS account or organization to be covered by the AWS BAA and every service, model, region, and connected component to remain within current eligible scope.
Can AWS Bedrock be used with PHI?
Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.
Does SOC 2 mean AWS Bedrock is HIPAA compliant?
No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.
What should buyers verify before using AWS Bedrock with PHI?
Whether the AWS BAA is accepted for the account or organization invoking Amazon Bedrock. Whether the exact model, region, endpoint, agents, knowledge bases, guardrails, evaluation features, logging, storage, and support path are currently eligible. Where prompts, files, outputs, retrieved context, embeddings, traces, invocation logs, and evaluation data are stored and retained. How IAM, network isolation, KMS keys, minimum-necessary prompting, human review, hallucination risk, deletion, monitoring, and incident response are governed.
Last checked and source notes
- Last checked
- 2026-09-17
- Confidence
- High
- Dataset rows
- 274 vendors
- Reviewed the AWS HIPAA Eligible Services Reference, last updated August 3, 2026, and Amazon Bedrock security documentation on 2026-09-17.
- The reviewed AWS reference lists Amazon Bedrock but excludes Fable and Mythos models; buyers should re-check the live reference before deployment.
- ComplySaaS did not verify a private AWS agreement, model configuration, architecture, or customer-specific BAA status.
- AWS HIPAA Eligible Services Reference
- Amazon Bedrock security
- Data protection in Amazon Bedrock