AWS Security and Compliance: UK GDPR, NCSC Guidance and Automated Assurance
Manage AWS UK GDPR compliance with NCSC guidance, Audit Manager, data sovereignty, and assurance.
HIPAA compliance in the cloud is not a feature a provider switches on. It is a shared set of obligations between the covered entity, its business associates and every cloud vendor with access to Protected Health Information.
The Health Insurance Portability and Accountability Act sets federal standards for how PHI must be handled, protected and disclosed. When that data moves into a cloud environment, the compliance obligations move with it.
The HHS Office for Civil Rights is the enforcement body. It does not distinguish between a health system managing its own data centre and one running workloads on AWS or Azure.
If PHI is involved, HIPAA applies to the healthcare organisation, its software vendors, its cloud infrastructure partners and any analytics or communication tool that touches patient data.
Cloud teams that assume their provider’s HIPAA certification covers their own obligations are operating on a misunderstanding that regulators and auditors correct quickly.
For a broader explanation of how HIPAA, PCI DSS and SOC 2 differ in cloud environments, read HIPAA, PCI DSS and SOC 2: Key Differences for Cloud Teams.

The healthcare breach figures remain concerning. According to the HIPAA Journal, 2023 saw over 133 million healthcare records exposed, the highest annual total on record.
Many of these incidents involved third-party vendors and misconfigured cloud environments rather than internal system failures.
The pattern is consistent. A healthcare organisation onboards a cloud-based analytics tool. The vendor gets access to a data set that includes PHI. No Business Associate Agreement is signed before access is granted.
If a breach occurs, or if the OCR conducts a compliance audit, the absence of that BAA is itself a violation, entirely separate from whether data was exposed.
HHS guidance on business associates is clear: where a vendor qualifies as a business associate, a Business Associate Agreement should be in place before that vendor creates, receives, maintains, or transmits PHI on behalf of the covered entity.

The HIPAA Security Rule applies specifically to electronic PHI and sets three categories of safeguards: administrative, physical and technical.
In a cloud environment, the technical safeguards carry the most immediate operational weight.
The HIPAA Security Rule requires several key technical safeguards in cloud environments. Access controls help ensure that only authorised users can access ePHI. Audit controls require systems to record and examine activity involving ePHI. Integrity controls protect ePHI from improper alteration or destruction. Transmission security protects ePHI when it moves across open networks.
None of these are optional, and none are automatically satisfied by using a HIPAA-eligible cloud service.
A cloud provider can sign a BAA and offer HIPAA-eligible services while the customer’s own application layer has open access controls, no logging and unencrypted data transfers.
The provider’s compliance does not substitute for the customer’s.

A BAA is not a standard contract addendum. It has specific required elements under HIPAA.
It must establish the permitted uses and disclosures of PHI by the business associate, require the business associate to implement appropriate safeguards, require reporting of breaches and security incidents, and address what happens to PHI when the relationship ends.
Major cloud providers, including AWS, Google Cloud and Microsoft Azure, offer standard BAA templates for their HIPAA-eligible services.
These usually cover the infrastructure layer. They do not extend to every service those providers offer, and they do not cover the applications built on top of the infrastructure.
Cloud teams need to understand exactly which services fall under the BAA, which services do not, and how to prevent PHI from flowing into services outside that scope.
Cloud providers operate on a shared responsibility model. The provider secures the underlying infrastructure, including physical data centres, network hardware and hypervisors.
The customer is responsible for everything built on top, including operating systems, applications, data, access controls and configurations.
For HIPAA, this division has direct consequences. A healthcare organisation using a cloud provider’s HIPAA-eligible storage service relies on the provider to secure the physical infrastructure and storage layer.
However, the organisation remains responsible for configuring access permissions correctly, encrypting data at rest and in transit where required, logging access to PHI and training its workforce on proper handling procedures.
When the OCR investigates a breach or conducts a compliance review, it evaluates the covered entity’s controls, not the provider’s.
A cloud provider’s security attestations do not transfer to the covered entity. The organisation must demonstrate its own compliance independently.
Understanding the shared responsibility model is a useful first step, but applying HIPAA requirements across cloud infrastructure, vendors, access controls and audit evidence requires structured learning.
The Cloud Compliance Basics HIPAA PCI SOC2 In The Cloud course helps cloud and security teams understand how HIPAA obligations apply in real cloud environments.
Explore the Course → Cloud Compliance Basics HIPAA PCI SOC2 In The Cloud
The Security Rule requires covered entities and business associates to conduct a thorough risk analysis of all PHI, including ePHI stored, processed, or transmitted in cloud systems.
The HHS guidance on risk analysis specifies that this assessment must identify where PHI exists across all systems, evaluate the threats and vulnerabilities relevant to that data, and document the controls in place to address identified risks.
In a cloud environment, that means mapping every data flow involving PHI.
This includes the primary application database, backup systems, logging pipelines, analytics exports, communication tools and any integration that pulls or pushes patient data.
Many organisations complete a risk assessment for their core systems and overlook the data flows created by secondary tools and third-party integrations. Those gaps are exactly where auditors look.
Risk assessments are not a one-time activity. Any significant change to the cloud environment, such as a new integration, a migrated workload, or a change in vendor, should trigger a reassessment of the affected scope.
Preparation for a HIPAA audit in a cloud environment is less about last-minute documentation and more about whether controls have been operating consistently.
The OCR does not only evaluate whether policies exist. It evaluates whether those policies are followed in practice and whether the organisation can demonstrate that through records.
The starting point is a complete inventory of every system that touches PHI, including third-party tools, integrations and data exports.
From that inventory, every vendor relationship should be checked for a signed BAA. Any vendor without one should be addressed before the audit, not during it.
Access logs should be reviewed to confirm that PHI access is restricted to authorised users and that any anomalous access has been investigated and documented.
Workforce training records should confirm that staff with access to PHI have completed role-specific HIPAA training within the required timeframe.
Incident response records should show that any security incidents, regardless of whether they resulted in a reportable breach, were identified, investigated and documented.
If you are building or managing cloud infrastructure that handles PHI, the gap between knowing what HIPAA requires and applying it correctly under operational conditions is where many compliance failures happen.
The Cloud Compliance Basics HIPAA PCI SOC2 In The Cloud course covers HIPAA cloud requirements in practical detail, including risk assessment, BAA management and Security Rule implementation across AWS, Azure and GCP environments.
Explore the Course → Cloud Compliance Basics HIPAA PCI SOC2 In The Cloud
