Healthcare Compliance in the Cloud
Build applications that store, process, and transmit sensitive health-related information, consistent with your privacy and security obligations.
Health and Social Care Cloud Security – Good Practice Guide

At AWS, security and privacy is the top priority
Roles and Responsibilities
Your data, stored in AWS, is your data. Our shared security model ensures ownership and control of your data remains with you at all times. We offer a robust set of solutions to keep healthcare data protected and readily available. AWS provides access to more than 130 HIPAA eligible services as well as numerous certifications for industry-relevant global IT and compliance standards, including support for GDPR, HITRUST, ENS High, HDS, and C5. And, with twice as many Availability Zones as any other cloud provider, health organizations can benefit from the scale, security, and reliability of AWS.
AWS & Data Privacy

Shared Responsibility

AWS Healthcare Compliance Alignments / Frameworks
AWS Compliance Certifications:
The AWS compliance certifications demonstrate the “security of the cloud” and the operating effectiveness of AWS controls. Customers are responsible for the security in the cloud.
Customers inherit these compliance certifications and can use them to demonstrate part of their compliance to auditor and regulators.
Certifications / Attestations:
Compliance certifications and attestations are assessed by a third-party, independent auditor and result in a certification, audit report, or attestation of compliance.
Laws / Regulations / Privacy:
AWS customers remain responsible for complying with applicable compliance laws and regulations. In some cases, AWS offers functionality (such as security features), enablers, and legal agreements (such as the AWS Data Processing Agreement and Business Associate Addendum) to support customer compliance.
No formal certification is available to (or distributable by) a cloud service provider within these law and regulatory domains.
Compliance alignments and frameworks include published security or compliance requirements for a specific purpose, such as a specific industry or function. AWS provides functionality (such as security features) and enablers (including compliance playbooks, mapping documents, and whitepapers) for these types of programs.
It is important to mention the shared responsibility model while discussing regulatory compliance. AWS bring in state of the art technologies, goes through the industry standard certifications and attestations both globally and regionally where possible and align to industry frameworks to help facilitate the compliant implementation of AWS services for healthcare compliance. Under the aegis of shared responsibility model, customers can inherit the compliant controls and capabilities to meet the needs of healthcare compliance in that region.
