AWS Guidance for HIPAA Technical Safeguards
AWS has released a new implementation and readiness guide for configuring and evidencing compliance with HIPAA Security Rule Technical Safeguards when building healthcare workloads on AWS. The guidance covers current HIPAA regulations and proposed 2025 NPRM changes, including mandatory encryption, multi-factor authentication, and network segmentation. It is intended for cloud architects, security engineers, CISOs, and compliance teams, providing a practical reference for covered entities and business associates.
- →New HIPAA Security Rule Technical Safeguards Guidance Released
- →Guidance Details Key Implementation Areas
- →Addressing Proposed HIPAA Rule Changes
Notes (3) ›
- New HIPAA Security Rule Technical Safeguards Guidance Released
AWS has published a guide to help covered entities and business associates implement and demonstrate compliance with the HIPAA Security Rule Technical Safeguards when operating healthcare workloads on AWS. The document addresses current regulations and proposed changes from the January 2025 NPRM, such as mandatory encryption, multi-factor authentication, and network segmentation.
- Guidance Details Key Implementation Areas
The guide includes a shared responsibility matrix, ePHI boundary architecture, ePHI data flow and encryption reference architecture, and a foundation checklist. It assumes familiarity with AWS services and serves as a practical implementation reference, not a legal interpretation.
- Addressing Proposed HIPAA Rule Changes
The guidance incorporates proposed updates from the 2025 NPRM, which includes making encryption at rest and in transit, and multi-factor authentication for ePHI access, mandatory. It recommends treating all specifications as required for new workloads, even though the final rule has not yet been published (as of June 2026).
https://aws.amazon.com/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance/
Related releases
- Terraform AWS Provider v6.60.0 Adds New Resources and Fixes Bugs Terraform AWS Provider Releases ·
- Amazon S3 enhances access denied errors with specific policy ARNs AWS What's New ·
- OpenAI Daybreak Red and Blue Cyber Defense Models Now on Amazon Bedrock AWS What's New ·
- AppFolio Transforms Data Streaming with Amazon MSK Express Brokers AWS Big Data Blog ·
- AWS IAM Role Manager Automates Service Role Setup AWS What's New ·
- Amazon Quick Integrates Microsoft Purview for Data Loss Prevention AWS What's New ·