Skip to main content

The services listed below are eligible to create, receive, process, maintain, or transmit electronic protected health information (ePHI). AWS has demonstrated its compliance with the HIPAA requirements with respect to each service below, subject to the shared responsibility model. Customers still must configure these services consistent with HIPAA requirements. All features of HIPAA Eligible services are also eligible to create, receive, process, maintain, or transmit ePHI unless specifically noted otherwise below.
 

Last Updated: June 17, 2025


NOTE: If you are a Covered Entity or Business Associate as defined by the Health Insurance Portability and Accountability Act of 1996 (as amended, “HIPAA”), you agree not to use these HIPAA Eligible Services for any purpose or in any manner involving Protected Health Information (as defined by HIPAA) without first entering into an AWS business associate agreement.

Unless specifically excluded, generally available features of each of the HIPAA eligible services listed are also considered HIPAA eligible.

The services listed above are eligible for workloads involving electronic Protected Health Information (ePHI). It's important to note that some AWS services are not listed here. Customers still may use services not listed here, including within HIPAA Accounts, provided that the services do not process or store ePHI. For more information, please speak to your AWS account representative. Customers are responsible for ensuring their own HIPAA compliance when using any AWS service.