aws AWS Security Blog ·

AWS Guidance for HIPAA Technical Safeguards

blogcomplianceawsengineerhealthcare
announcement

AWS has released a new implementation and readiness guide for configuring and evidencing compliance with HIPAA Security Rule Technical Safeguards when building healthcare workloads on AWS. The guidance covers current HIPAA regulations and proposed 2025 NPRM changes, including mandatory encryption, multi-factor authentication, and network segmentation. It is intended for cloud architects, security engineers, CISOs, and compliance teams, providing a practical reference for covered entities and business associates.

  • New HIPAA Security Rule Technical Safeguards Guidance Released
  • Guidance Details Key Implementation Areas
  • Addressing Proposed HIPAA Rule Changes
Notes (3)
  • New HIPAA Security Rule Technical Safeguards Guidance Released

    AWS has published a guide to help covered entities and business associates implement and demonstrate compliance with the HIPAA Security Rule Technical Safeguards when operating healthcare workloads on AWS. The document addresses current regulations and proposed changes from the January 2025 NPRM, such as mandatory encryption, multi-factor authentication, and network segmentation.

  • Guidance Details Key Implementation Areas

    The guide includes a shared responsibility matrix, ePHI boundary architecture, ePHI data flow and encryption reference architecture, and a foundation checklist. It assumes familiarity with AWS services and serves as a practical implementation reference, not a legal interpretation.

  • Addressing Proposed HIPAA Rule Changes

    The guidance incorporates proposed updates from the 2025 NPRM, which includes making encryption at rest and in transit, and multi-factor authentication for ePHI access, mandatory. It recommends treating all specifications as required for new workloads, even though the final rule has not yet been published (as of June 2026).

Read the original announcement →

https://aws.amazon.com/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance/

Related releases