AWS has published "HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance." This document assists covered entities and business associates in configuring, implementing, and demonstrating compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) for healthcare workloads on AWS.
The guidance details the five standards and nine implementation specifications of the HIPAA Security Rule’s Technical Safeguards, which include access control, audit controls, integrity, authentication, and transmission security. It also incorporates proposed changes from the 2025 Notice of Proposed Rulemaking (NPRM), such as mandatory encryption at rest and in transit, multi-factor authentication for all ePHI access, and new specifications for network segmentation, configuration management, anti-malware protection, and incident response.
The guidance includes a shared responsibility matrix that maps each §164.312 specification to responsibilities managed by AWS and those requiring customer configuration. It also provides recommendations for establishing a defined ePHI boundary, a reference architecture for tracing ePHI data flow with applicable specifications, and a foundational checklist of prerequisites before configuring individual Technical Safeguard controls.
This resource is intended for cloud architects, security engineers, CISOs, and compliance teams working with AWS healthcare workloads. It assumes familiarity with AWS services and serves as a practical implementation reference, not a legal or regulatory interpretation. The guidance focuses exclusively on Technical Safeguards and recommends treating all specifications as required for new workloads, anticipating future regulatory updates.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
AWS has released new guidance to help healthcare entities configure and implement HIPAA Security Rule Technical Safeguards when using AWS services. This guidance covers current regulations and proposed 2025 NPRM changes, including mandatory encryption and multi-factor authentication, providing a practical reference for compliance.