Build applications that store, process, and transmit sensitive health-related information, consistent with your privacy and security obligations.
At AWS, security and privacy is the top priority
Specifically for the healthcare industry, we provide a number of global certifications and accreditations (HIPAA, HITRUST, GDPR, and others) that allow you to store, process, or transmit your most sensitive data in the cloud and improve your security and compliance posture.
Roles and Responsibilities
Your data, stored in AWS, is your data. Our shared security model ensures ownership and control of your data remains with you at all times. We offer a robust set of solutions to keep healthcare data protected and readily available. AWS provides access to more than 130 HIPAA eligible services as well as numerous certifications for industry-relevant global IT and compliance standards, including support for GDPR, HITRUST, ENS High, HDS, and C5. And, with twice as many Availability Zones as any other cloud provider, health organizations can benefit from the scale, security, and reliability of AWS.
AWS & Data Privacy
AWS takes data privacy very seriously, and maintaining customer trust is an ongoing commitment. Customers always manage access to their services and content. We do not access or use customer content for any purpose without the customer’s consent. Customers choose the region(s) in which their customer content will be stored. We will not move or replicate customer content outside of the customer’s chosen region(s) without the customer’s consent.
Shared Responsibility
Understanding how to build healthcare applications on AWS means understanding the shared responsibility model. In the AWS Cloud, security is shared between AWS and the customer. This means that certain elements of security (such as physical security of the underlying infrastructure) are now the responsibility of AWS. Customers are still responsible for other aspects of security (such as the security measures used to protect your applications), which is no different than if your application was running in a traditional data center.
AWS Healthcare Compliance Alignments / Frameworks
- The AWS compliance certifications demonstrate the “security of the cloud” and the operating effectiveness of AWS controls. Customers are responsible for the security in the cloud.
- Customers inherit these compliance certifications and can use them to demonstrate part of their compliance to auditor and regulators.
Compliance certifications and attestations are assessed by a third-party, independent auditor and result in a certification, audit report, or attestation of compliance.
AWS customers remain responsible for complying with applicable compliance laws and regulations. In some cases, AWS offers functionality (such as security features), enablers, and legal agreements (such as the AWS Data Processing Agreement and Business Associate Addendum) to support customer compliance.
No formal certification is available to (or distributable by) a cloud service provider within these law and regulatory domains.
Compliance alignments and frameworks include published security or compliance requirements for a specific purpose, such as a specific industry or function. AWS provides functionality (such as security features) and enablers (including compliance playbooks, mapping documents, and whitepapers) for these types of programs.
It is important to mention the shared responsibility model while discussing regulatory compliance. AWS bring in state of the art technologies, goes through the industry standard certifications and attestations both globally and regionally where possible and align to industry frameworks to help facilitate the compliant implementation of AWS services for healthcare compliance. Under the aegis of shared responsibility model, customers can inherit the compliant controls and capabilities to meet the needs of healthcare compliance in that region.
The information below provides representative certifications, healthcare laws and relevant frameworks.
Key Certifications & Attestations
ISO 9001
ISO 27001, 27017, 27018
SOC 1, 2, 3
PCI DSS Level 1
FedRAMP
Cyber Essentials Plus
DoD SRG
Healthcare Laws - Regulations & Privacy
GDPR
HIPAA
HITECH
PDPA-2012 (Singapore)
PIPEDA (Canada)
Privacy Act (Australia)
PDPA -2010 (Malaysia)
Key Alignment & Frameworks
CSA (Cloud Security Alliance)
EU-US Privacy Shield
NIST
BioPhorum IT Controls
United States
AWS & FedRAMP
The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide program that delivers a standard approach to the security assessment, authorization and continuous monitoring for cloud products and services. FedRAMP is mandatory for all US federal agencies and all cloud services, including the U.S. Department of Health and Human Services.
Two separate FedRAMP Agency authorizations have been issued; one encompassing the AWS GovCloud (US) Region, and the other covering the AWS US East/West regions.
AWS & HITRUST Compliance
The HITRUST CSF (Cloud Security Framework) serves to unify security controls based on aspects of US federal law (such as HIPAA and HITECH), state law (such as Massachusetts’s Standards for the Protection of Personal Information of Residents of the Commonwealth), and recognized non-governmental compliance standards (such as PCI DSS) into a single framework that is tailored for healthcare needs.
Certain AWS services have been assessed under the HITRUST CSF Assurance Program by an approved HITRUST CSF Assessor as meeting the HITRUST CSF v9.3 Certification Criteria.
Customers may use any AWS service in an account designated as a HIPAA account, but they should only process, store, and transmit protected health information (PHI) in the HIPAA-eligible services.
AWS, HIPAA, and HITECH Compliance
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is legislation that is designed to make it easier for US workers to retain health insurance coverage when they change or lose their jobs. The legislation also seeks to encourage electronic health records to improve the efficiency and quality of the US healthcare system through improved information sharing.
Health Information Technology for Economic and Clinical Health Act (HITECH) expanded the HIPAA rules in 2009. HIPAA and HITECH together establish a set of federal standards intended to protect the security and privacy of PHI. These provisions are included in what are known as the "Administrative Simplification" rules. HIPAA and HITECH impose requirements related to the use and disclosure of PHI, appropriate safeguards to protect PHI, individual rights, and administrative responsibilities.
Canada
Personal Information Protection and Electronic Documents Act (PIPEDA)
Personal Information Protection and Electronic Documents Act (PIPEDA) is a Canadian federal law that applies to the collection, use, and disclosure of personal information in the course of commercial activities in all Canadian provinces.
The Health Information Act (HIA) is the privacy law in Alberta that applies to the collection, use, disclosure and protection of health information that is in the custody or under the control of a custodian.
The AWS Canada (Central) Region is currently available for multiple services, such as: Amazon Elastic Compute Cloud (Amazon EC2), Amazon Simple Storage Service (Amazon S3), and Amazon Relational Database Service (Amazon RDS).
Personal Health Information Protection Act (Ontario)
The Personal Health Information Protection Act (PHIPA) is privacy legislation in Ontario that applies to the collection, use, and disclosure of personal health information (PHI) in the course of providing or facilitating healthcare services.
United Kingdom
Health and Social Care Cloud Security – Good Practice Guide
Health and Social Care Cloud Security – Good Practice Guide has been written jointly by NHS Digital, NHS England, the Department of Health and Social Care and NHS Improvement.
This guidance explains the safeguards that must be put in place so health and social care organisations can safely locate health and social care data, including confidential patient information in the public cloud including solutions that make use of data off-shoring.
AWS enables the compliance through classifying the workloads that are being deployed to AWS and supports by implementing the class-appropriate controls. The white paper, “Using AWS in the context of NHS Cloud Security Guidance” includes detailed risk management activities for organizations to undertake, comprising mostly technical measures appropriate to the level of security required.
France
Hébergeur de Données de Santé (HDS)
Hébergeur de Données de Santé (HDS) - Introduced by the French governmental agency for health, “Agence du Numérique en Santé” (ANS), the HDS (Hébergeur de Données de Santé) certification aims to strengthen the security and protection of personal health data.
To be HDS certified, an IT provider must be ISO 27001 certified. This means that the services covered by our ISO 27001 certification are included in the scope of HDS. The AWS services that are in scope for the ISO/IEC 27001:2013 certification can be found on the ISO Certified webpage.
Germany
DiGAV compliance
DiGAV was introduced in April 2020 to support the digitization of the German health system. DiGAV enables certain healthcare applications to be recognized as refundable under the German statutory health insurance system. However, for organizations to comply with and enable eligibility for reimbursement through DiGAV, they must demonstrate that their applications meet DiGAV data protection requirements, including that personal data is processed exclusively within the European Economic Area (EEA) or a country with an adequacy decision by the European Commission based on Article 45 of the EU General Data Protection Regulation (GDPR).
AWS provides a number of industry-leading tools to support customers address local regulatory and legislative requirements, including the German Digital Supply Act (DVG) and associated Digital Health Applications Ordinance (DiGAV), as they move healthcare workloads to the cloud.
Japan
Act on the Protection of Personal Information (APPI)
The Act on the Protection of Personal Information (APPI) is the primary legislation dealing with personal data in Japan.
The APPI applies to all business operators (individuals and entities) that handle personal information. The APPI also distinguishes between personal information and personal data (which the APPI defines as personal information that constitutes part of a personal information database). Obligations on business operators vary depending on whether the business operators acquire, use, or provide, personal information or personal data.
AWS implements and maintains technical and organizational security measures applicable to AWS cloud infrastructure services under globally recognized security assurance frameworks and certifications, including ISO 27001, ISO 27017, ISO 27018, PCI DSS Level 1, and SOC 1, 2, and 3. These technical and organizational security measures are validated by independent third-party assessors, and are designed to prevent unauthorized access to or disclosure of customer content.
Singapore
Personal Data Protection Act 2012 (PDPA)
The Personal Data Protection Act 2012 (PDPA) is the law that applies to the protection of personal data in Singapore, including when the personal data is transferred internationally for processing. The PDPA governs the collection, use, disclosure and protection of personal data.
AWS implements and maintains technical and organizational security measures applicable to AWS cloud infrastructure services under globally recognized security assurance frameworks and certifications, including ISO 27001, ISO 27017, ISO 27018, PCI DSS Level 1, and SOC 1, 2, and 3. These technical and organizational security measures are validated by independent third-party assessors, and are designed to prevent unauthorized access to or disclosure of customer content.
AWS supports many healthcare organizations globally by providing the technology needed to move at the speed necessary to have an impact—from using medical data-sharing to diagnose previously unknown diseases, to identifying new viruses to prevent another pandemic, and many other critical functions—all while enabling customers to meet the highest security and compliance requirements. As one example, the Integrated Health Information Systems (IHiS) in Singapore, the agency responsible for supplying the enabling technologies that power Singapore public healthcare, turned to AWS to securely scale its vaccination operations IT systems to sustain significantly higher loads at very short notice, from an initial load of 8,000 daily vaccinations to a peak of 80,000 daily vaccinations within
four weeks.