HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance
July 31, 2026 · AWS Security · Severity: MEDIUM
AWS has released the "HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance" to assist covered entities and business associates in configuring, implementing, and demonstrating compliance with HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) for healthcare workloads on AWS. The guidance addresses five standards and nine implementation specifications, including access control, audit controls, integrity, authentication, and transmission security. It also incorporates proposed changes from the 2025 Notice of Proposed Rulemaking (NPRM), such as mandatory encryption at rest and in transit, multi-factor authentication (MFA) for accessing electronic Personal Health Information (ePHI), and new requirements for network segmentation, patch management, and incident response. The document outlines the shared responsibility model between AWS and customers, providing a detailed matrix of responsibilities and practical recommendations for establishing ePHI boundaries, data flow, and encryption. The guidance is tailored for cloud architects, security engineers, CISOs, and compliance teams at covered entities and business associates leveraging AWS for healthcare workloads. It emphasizes treating all Technical Safeguard specifications as required for new workloads, even though the final rule for the 2025 NPRM has not yet been published as of June 2026. AWS Security Assurance Services, LLC, a HITRUST External Assessor Firm and PCI-QSAC, developed the guidance in collaboration with AWS Health & Life Sciences (HCLS) and AWS Compliance teams. While the document serves as a practical implementation reference, it does not provide legal or regulatory advice, and users are responsible for ensuring compliance with their specific obligations. For further assistance, AWS encourages contacting their Security Assurance Services team or account representatives.
Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS.
The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and nine implementation specifications covering access control, audit controls, integrity, authentication, and transmission security.
The guidance also covers the 2025 NPRM proposed changes, including encryption at rest and in transit becoming required, multi-factor authentication (MFA) becoming mandatory for all electronic Personal Health Information (ePHI) access, and new specifications for network segmentation, configuration management, anti-malware protection, patch management, software removal, incident response and breach notification.
Key topics included
- Shared responsibility for HIPAA on AWS – A responsibility matrix mapping each §164.312 specification to what AWS manages nd what the customer must configure and operate.
- ePHI boundary architecture – Guidance on establishing a defined ePHI boundary
- ePHI data flow and encryption – A reference architecture tracing ePHI with the applicable §164.312 specification
- Foundation checklist – Prerequisite recommendation before configuring individual Technical Safeguard controls.
This guidance is written for cloud architects, security engineers, CISOs, and compliance teams at covered entities and business associates building or operating AWS healthcare workloads. It assumes familiarity with AWS services and is intended as a practical implementation reference, not a legal or regulatory interpretation. This guidance focuses exclusively on Technical Safeguards.
HHS published a Notice of Proposed Rulemaking in January 2025, proposing significant updates to the HIPAA Security Rule—including eliminating the Addressable designation, making encryption, MFA, and asset inventory mandatory, and introducing new technical requirements not present in the current rule. As of June 2026, the final rule has not been published. This guidance covers both the current rule and the proposed changes and recommends treating all specifications as Required for new workloads.
Download HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance.
For questions about HIPAA readiness on AWS, including Administrative Safeguards, Physical Safeguards, risk analysis, and assessment preparation, contact the AWS Security Assurance Services team or your AWS account representative.
This guidance is provided by AWS Security Assurance Services, LLC, a HITRUST External Assessor Firm and PCI-QSAC along with contribution from AWS HCLS, AWS Compliance teams. It is for informational and guidance purposes only and does not constitute legal, regulatory, or compliance advice. Recipients are solely responsible for determining applicability to their specific environments and legal obligations.
If you have feedback about this post, submit comments in the Comments section below.
Key Takeaways
- AWS publishes guidance on implementing HIPAA Security Rule technical safeguards on the AWS cloud platform.
- The guide covers access controls audit controls integrity controls and transmission security for healthcare workloads.
- Healthcare organizations using AWS can leverage this guidance to achieve and maintain HIPAA compliance in the cloud.