Comparison — AWS demo catalog research (2026-09-04)
Generated at build time from
research/aws-demo-catalog/comparison.mdin the repo — edit the source, not this page.
Comparator pass over the four scout files in sources/ (existing-reference-repos = REPO, healthcare-compliance-building-blocks = COMP, mobile-and-device-stack = MOB, education-portal-and-workshop-patterns = PORT) against brief.md and catalog-v0.md. Claims are numbered C-n and grouped by catalog item so the lead can write catalog-v1.md item by item. Gaps are G-n, contradictions X-n. "Corroborated by" lists the angles that independently support a claim; single-angle claims are marked as such. Tiers: Primary = AWS page/doc/repo/What's New; Practitioner = AWS blog case study or third party; Inference = scout or comparator reasoning from primary text.
Where a contradiction could be narrowed with a targeted check, I did one (§5, "Comparator checks", all retrieved 2026-09-04) and say what it found; where it remains open, I say so rather than pick a side.
1. Claims by catalog item
F0 — HIPAA-ready landing zone
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C1 | The only AWS-official F0-level artefact is the LZA + LZA-for-Healthcare config: organisation-only (Control Tower Management/Audit/LogArchive + OU tree), "not designed for single-account deployments", ~US$400–500/month idle. Healthcare config v1.9.0-e 2025-11-29, repo pushed 2026-06-18, MIT-0; LZA Solution v1.16.2 released 9/2026, cost page US$430.22/month sample. | https://github.com/aws-samples/landing-zone-accelerator-on-aws-for-healthcare (README fetched 2026-09-04); https://docs.aws.amazon.com/solutions/landing-zone-accelerator-on-aws/ ; https://docs.aws.amazon.com/solutions/latest/landing-zone-accelerator-on-aws/cost.html (2026-09-04) | REPO Table A, PORT C3/C4/C-map | High |
| C2 | No public "empty single account → HIPAA baseline" example exists in any AWS org, Guidance or workshop. Closest: deploy-conformance-pack-for-aws-startup-security-baseline (CDK, pushed 2025-03-28, not the HIPAA pack). The 2017 HIPAA Quick Start is gone. | REPO Table B; PORT B7 (Workshop Studio/Builder Center searched 2026-09-04) | REPO, PORT (independent absence searches) | High (absence) |
| C3 | Control Tower is the current, active landing-zone path: CfCT pushed 2026-07-01; What's New 2026-07-16 (AFT); v4.0 "controls-dedicated experience" 2025-11-21 lets you use 750+ managed controls in an existing Organization without a full landing zone; LZA Solution released 9/2026. An Organization is still required for any of it. | https://github.com/aws-solutions/aws-control-tower-customizations ; https://aws.amazon.com/about-aws/whats-new/2026/07/aws-control-tower-account/ ; https://aws.amazon.com/about-aws/whats-new/2025/11/aws-control-tower-controls-dedicated-experience/ | REPO, COMP 4.6, PORT C3 | High |
| C4 | The Config conformance pack is still named "Operational Best Practices for HIPAA Security"; template last commit 2025-01-07 (130-rule cap); validated by AWS SAS; disclaimer "not designed to fully ensure compliance". | https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-hipaa_security.html ; https://github.com/awslabs/aws-config-rules/commits/master/aws-config-conformance-packs/Operational-Best-Practices-for-HIPAA-Security.yaml | REPO, COMP 4.1 | High |
| C5 | Security Hub split in Oct–Dec 2025: standards live in AWS Security Hub CSPM (FSBP, AI Security Best Practices, CIS v5, NIST 800-53 r5, NIST 800-171 r2, PCI DSS, Resource Tagging, Control Tower service-managed); the new "AWS Security Hub" (GA 2025-12-02, OCSF risk analytics) is not on the HIPAA list under its own name; there is no HIPAA-named standard. | https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.html ; https://aws.amazon.com/about-aws/whats-new/2025/12/security-hub-near-real-time-risk-analytics/ | COMP 4.2/4.3 only | High (Primary) |
| C6 | Macie has 12 PHI managed data identifiers, all keyword-dependent, and none is in the recommended set (2023-06-27) or the automated-discovery default set (2023-08-02) — F0/U4/U5 must select them explicitly. | https://docs.aws.amazon.com/macie/latest/user/mdis-reference.html ; https://docs.aws.amazon.com/macie/latest/user/discovery-asdd-settings-defaults.html | COMP 4.4/4.5 only | High |
| C7 | BAA is self-service in AWS Artifact at account scope or, from the management account of an all-features Organization, at organization scope covering all existing and future member accounts. No catalog service needs an extra HIPAA opt-in. | https://docs.aws.amazon.com/artifact/latest/ug/accept-org-agreement.html ; https://aws.amazon.com/compliance/hipaa-compliance/ | COMP 1.1–1.5 only | High (Medium for "no other opt-in") |
| C8 | New constraint absent from catalog-v0: Bedrock and Security Hub CSPM compliance pages warn "Our new AWS sign-up experience is not designed for regulated workloads … sign up for AWS (advanced) or activate advanced features." An F0 "empty account" runbook must start from an advanced-features account. | https://docs.aws.amazon.com/bedrock/latest/userguide/compliance-validation.html ; https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-compliance.html | COMP 1.5 only | High (text) |
| C9 | AWS's older HIPAA framing documents are stale: the "Architecting for HIPAA" whitepaper is archived (points to the eligible-services page); the Healthcare Industry Lens is dated 2022-11-17 with no revisions. Current AWS-official narrative is the eligible-services page plus 2026 blogs (C71). | https://docs.aws.amazon.com/whitepapers/latest/architecting-hipaa-security-and-compliance-on-aws/document-revisions.html ; https://docs.aws.amazon.com/wellarchitected/latest/healthcare-industry-lens/document-revisions.html | COMP 1.6, PORT C7 | High |
| C10 | aws-samples/aws-security-reference-architecture-examples (pushed 2026-09-04) is CC-BY-SA-4.0 — link, do not fork (brief OQ5). | LICENSE fetched 2026-09-04 | REPO only | High |
| C11 | Every named catalog service is on the HIPAA Eligible Services Reference (page "Last Updated: September 3, 2026"), including Bedrock, Bedrock AgentCore, Connect Health, Quick, Kiro, IoT Core, Greengrass, Kinesis, Firehose, Managed Flink, Athena, Glue, Lake Formation, SageMaker AI, Amplify Console, AppSync, API Gateway, SNS, SES, "Amazon Pinpoint and End User Messaging", ECS/Fargate, Aurora, DynamoDB, ElastiCache, Cognito, CloudFront, WAF/Shield, Macie, Config, GuardDuty, Control Tower. Not named (covered only by the "GA features of listed services are eligible" rule): S3 Tables, Timestream for InfluxDB, Valkey engine, Bedrock Knowledge Bases / Guardrails / Data Automation (KB and Guardrails are named as eligible in the AWS industries blog 2025-10-13). | https://aws.amazon.com/compliance/hipaa-eligible-services-reference/ ; https://aws.amazon.com/blogs/industries/hipaa-compliance-for-generative-ai-solutions-on-aws/ (2025-10-13) | COMP §2 (Primary); REPO independently cites Connect Health "HIPAA-eligible" from the 2026-03-05 What's New | High for listed; Medium (KB/Guardrails), Medium-Low (S3 Tables, InfluxDB, BDA) |
| C12 | Presence on the eligibility list is not a lifecycle signal: Forecast, Kendra, Q Business, IoT Events and A2I are still listed. Catalog rule 4 stands. | Same page | COMP only | High |
U1 — Patient portal + companion mobile app
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C13 | No AWS-official U1 Tier 1 exists (portal + native iOS/Android + Cognito + HealthLake). No aws-samples repo, no Guidance, no workshop, and no first-party Amplify native-mobile healthcare sample of any kind. | REPO Table B; PORT B7; MOB A12 | REPO, PORT, MOB (three independent absence searches) | High (absence) |
| C14 | Closest U1 T1 components: aws-healthlake-smart-on-fhir (CDK TS, 2024-03-16, no UI/Cognito); sample-intelligent-security-for-healthcare-apis (CloudFormation, 2026-08-14, Cognito MFA + Comprehend Medical redaction + Bedrock Guardrail, empty→running in 10–15 min); "SMART on FHIR with AWS HealthLake" workshop (content unreadable). | https://github.com/aws-samples/aws-healthlake-smart-on-fhir ; https://github.com/aws-samples/sample-intelligent-security-for-healthcare-apis ; https://catalog.us-east-1.prod.workshops.aws/workshops/542c1a0f-7bd2-4f2f-8da9-699e953c7b26 | REPO, PORT B3 | Medium |
| C15 | Amplify Gen 2 (GA 2024-05-06) is the only supported path; Gen 1 in maintenance from 2026-05-01, EOL 2027-05-01. All four clients actively released (Swift 2.60.2 2026-09-01; Android 2.41.1 2026-09-02; Flutter 2.15.0 2026-08-19; JS 2026-09-01). | https://github.com/aws-amplify/amplify-cli/issues/14881 (2026-05-14); release feeds 2026-09-04 | MOB A1–A6 only; consistent with REPO's finding that aws-healthscribe-demo (2025-04-08) is Gen 1 | High |
| C16 | Parity: Swift and Android have passkeys/passwordless and AppSync Events clients; Flutter has neither (issues #6094, #6106 open; WebAuthn PR #6851 unmerged draft since 2026-04-08); React Native follows JS (Expo Go unsupported). Gen 2 dropped Analytics/Push/Predictions as first-class categories. | https://github.com/aws-amplify/amplify-flutter ; https://docs.amplify.aws/swift/start/migrate-to-gen2/feature-matrix/ | MOB A7–A9 only | High |
| C17 | The classic AWS Mobile SDKs (aws-sdk-ios, aws-sdk-android) reached end of support 2026-08-01; the IoT Core "Mobile SDKs" docs page still lists them (stale). | READMEs of https://github.com/aws-amplify/aws-sdk-ios and …/aws-sdk-android ; https://docs.aws.amazon.com/iot/latest/developerguide/iot-sdks.html | MOB A10 only; bears on X6 | High |
| C18 | API layer: no AWS document recommends AppSync over API Gateway (or vice versa) for a mobile+web app over a container backend. Documented split: Amplify Data (AppSync GraphQL) when Amplify owns the model; API Gateway REST/HTTP to proxy an existing backend; AppSync Events for real-time. AppSync, API Gateway and their features are all HIPAA-listed. | https://docs.aws.amazon.com/prescriptive-guidance/latest/modernization-integrating-microservices/appsync-api-gateway.html ; https://docs.amplify.aws/react/build-a-backend/add-aws-services/rest-api/ ; COMP §2 | MOB B1–B6 + COMP (eligibility) | Medium (synthesis) |
| C19 | Cognito mobile: Managed Login (2024-11-22); passkeys/OTP passwordless on Essentials (default for new pools); refresh-token rotation 2025-04-22; self-service provisioned limits 2026-07. Design constraint: OTP-first-factor is incompatible with required MFA; a passkey satisfies MFA only with user verification required; passkeys cannot be a second factor to password. Mobile passkeys need a .well-known association file. | https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-authentication-flow-methods.html ; https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-sign-in-feature-plans.html | MOB C1–C8 only | High |
| C20 | Amazon Pinpoint end of support 2026-10-30; no new customers since 2025-05-20. Closes catalog rule 4's VERIFY: Pinpoint goes on the retired list. serverless-patient-engagement-stack (2025-04-01) depends on it and cannot be linked as-is. | https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html ; https://aws.amazon.com/pinpoint/faqs/ | MOB D1 (Primary); REPO (flags the dependent repo); COMP (list entry "Amazon Pinpoint and End User Messaging") | High |
| C21 | AWS-named successors: push/SMS/voice/OTP → AWS End User Messaging (push still uses the Pinpoint send-messages API with an application ID; migration guide states these APIs "are not impacted by this change and are supported by AWS End User Messaging"); email → SES; engagement (segments/campaigns/journeys) → Amazon Connect Customer outbound campaigns + Customer Profiles; events/analytics → Kinesis; In-App Messaging has no successor; push is not native in Connect campaigns. SNS mobile push is documented, undeprecated and valid, but is not the named successor. | Migration guide (above, re-fetched by comparator 2026-09-04); https://docs.aws.amazon.com/push-notifications/latest/userguide/reference-send-message.html ; https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-application-as-subscriber.html | MOB D2–D6 + comparator check (X2) | High |
| C22 | U1 Tier 2 (patient-facing assistant over the patient's own FHIR data via AgentCore Gateway tools): no example. Scaffolding exists: HCLS Agents Toolkit (amazon-bedrock-agents-healthcare-lifesciences, AgentCore + Strands despite the name, pushed 2026-09-03, 268 stars, MIT-0, life-science skew, no provider/patient agents); sample-healthcare-agent-with-agentcore-on-aws (2026-08-03, agent calls a SageMaker endpoint — the Tier 2→3 bridge); AWS blueprint blog "Architecting HIPAA-compliant AI agents" (2026-08-14: KMS-encrypted AgentCore Memory, Cedar on Gateway, Macie/Comprehend pre-ingestion scans, Object Lock logs). | https://github.com/aws-samples/amazon-bedrock-agents-healthcare-lifesciences ; https://aws.amazon.com/blogs/publicsector/architecting-hipaa-compliant-ai-agents-to-safeguard-health-data-with-aws/ | REPO, PORT B5, COMP 5.3.5 | High |
| C23 | U1 Tier 3 (no-show / adherence model): nothing public; SageMaker MLOps workshops and the generic Pipelines/Registry CDK sample (amazon-sagemaker-pipeline-deploy-manage-100x-models-python-cdk, 2026-07-28) supply mechanics only. | REPO Table B; PORT G | REPO, PORT | High (absence) |
| C24 | HealthLake: GA, actively shipping (2026-03 CCDA→FHIR agent preview, 2026-05 CMS-0057-F, 2026-07 resource matching preview); us-east-1 and us-west-2; US$0.27 per data-store-hour (~US$197/month per store) is the dominant running-demo cost — relevant because most U3/U4/U5 samples require a HealthLake datastore. | https://aws.amazon.com/healthlake/pricing/ ; https://aws.amazon.com/healthlake/faqs/ | COMP §3 (Primary); REPO (many samples list HealthLake as prerequisite) | High lifecycle / Medium price |
| C25 | Amazon Location Service is active (seven 2026 What's New posts, Mar–Aug); Device Farm active (last What's New 2025-11-21) but us-west-2 only — no PHI in test data. | https://docs.aws.amazon.com/general/latest/gr/devicefarm.html ; MOB E1–E3 | MOB only | High |
U2 — Remote patient monitoring at scale
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C26 | No end-to-end RPM example (devices → IoT Core → Kinesis → Flink → InfluxDB/Iceberg → alerts → app) exists in any AWS org, Guidance or workshop, and AWS publishes no guidance at all for HealthKit or Health Connect ingestion. REPO ranks U2 "second-highest" demonstration value after U1; PORT ranks it "highest" — a ranking difference, not a factual one. | REPO Table B; PORT B7; MOB F3 | REPO, PORT, MOB | High (absence) |
| C27 | Components that exist (all MIT-0 unless noted): guidance-for-aws-iot-greengrass-foundations (CDK v2, 2026-07-23); aws-greengrass-ec2-device-farm (CDK v2, 2026-08-30, Apache-2.0, simulated fleet); flink-keyed-random-cut-forest-example (2025-12-19, per-key RCF in Flink state, no IaC); amazon-sagemaker-deepar-mlops-pipeline-cdk (2025-04-10); transactional-datalake-using-amazon-datafirehose-iceberg (Firehose→Iceberg, CDC source); aws-appsync-iot-core-realtime-dashboard (Amplify Gen 2, npx ampx sandbox, pushed 2026-09-03, 126 stars — comparator check, X7) for the portal-side real-time view. | REPO U2 table; MOB F13; comparator check | REPO, MOB | High |
| C28 | The catalog's hot path has two independent weaknesses that converge: no IoT Core → Timestream for InfluxDB sample with IaC (REPO) and InfluxDB is not on the HIPAA list by name (COMP; FAQ compliance sentence sits under LiveAnalytics only). | REPO gaps; COMP §2 row + gap 3 | REPO, COMP | High (no sample) / Medium-Low (eligibility) |
| C29 | Phone → IoT Core path AWS documents: Cognito identity pool + IAM role plus an IoT policy attached to the Cognito identity; MQTT over WebSocket/SigV4. iOS: AWS IoT Device SDK for Swift GA 2026-06-01 (iOS 16+, MQTT5, Shadow/Jobs/Fleet Provisioning, Apache-2.0). Android: IoT Device SDK for Java v2 (API 24+). Amplify Swift and Android have no PubSub category; Amplify PubSub is JS/RN only. No AWS guidance for X.509 per phone. | https://docs.aws.amazon.com/iot/latest/developerguide/cognito-identities.html ; https://aws.amazon.com/about-aws/whats-new/2026/06/aws-iot-device-sdk-swift/ ; https://github.com/aws/aws-iot-device-sdk-java-v2/blob/main/documents/ANDROID.md | MOB F4–F9 only; REPO independently lists the SDK page and aws-sdk-ios-samples IoT-Sample/Swift | High |
| C30 | HealthKit and Health Connect are on-device stores only (no cloud API); Apple guideline 5.1.3 forbids storing personal health information in iCloud; Health Connect has background reads and a changes/sync API. Only AWS-adjacent code: cleverdevil/healthlake (community, archived 2022, no license). | https://developer.apple.com/app-store/review/guidelines/ §5.1.3 ; https://developer.android.com/health-and-fitness/guides/health-connect ; https://github.com/cleverdevil/healthlake | MOB F1–F3, REPO | High |
| C31 | The only AWS sample of a phone as BLE→IoT Core gateway is aws-amplify-cdk-iot-ble-swift-app: CDK migrated v1→v2 on 2026-06-09 (commits), but the iOS Podfile pins Amplify ~> 1.0, AWSIoT, AWSMobileClient — Amplify iOS v1 plus the classic Mobile SDK that reached EOS 2026-08-01 (C17); README still says "CDK version 1.105.0". Fork for the CDK/IoT-policy structure only; the iOS layer must be rewritten on Amplify Swift 2.x + IoT Device SDK for Swift. (Resolves X6.) | https://api.github.com/repos/aws-samples/aws-amplify-cdk-iot-ble-swift-app/commits ; …/BLEX/Podfile ; README (all 2026-09-04) | REPO, MOB F10 + comparator check | High |
| C32 | U2 Tier 2 (telemetry as typed MCP tools on AgentCore Gateway): no example; nearest are generic Gateway samples (AWS-ops tools, protein tools). Design correction: see X1 — the Bedrock Guardrails PII filter does not evaluate tool inputs/results. | REPO U2 table; COMP 5.3.3 | REPO, COMP | High |
| C33 | U2 Tier 3 edge scoring: SageMaker Edge Manager EOL 2024-04-26 (AWS recommends Greengrass v2 + ONNX); greengrass-v2-sagemaker-edge-manager-python and amazon-sagemaker-aws-greengrass-custom-timeseries-forecasting (IoT Analytics + Greengrass v1, archived) cannot be linked; the only current Greengrass-v2 ML Guidance is Strands SLM-at-edge (2025-10-27), an LLM not a scoring model. | https://docs.aws.amazon.com/sagemaker/latest/dg/edge-eol.html ; https://github.com/aws-solutions-library-samples/guidance-for-deploying-ai-agents-to-device-fleets-using-aws-iot-greengrass | REPO only | High |
| C34 | Flink→SageMaker real-time endpoint pattern exists generically (amazon-sagemaker-feature-store-streaming-inference-msk-kda, 2024-01-04, fraud domain, pre-rename naming). Greengrass is HIPAA-listed without a version qualifier. | REPO U2 table; COMP §2 | REPO, COMP | Medium |
U3 — Ambient clinical documentation
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C35 | HealthScribe: GA 2023-11-27, active (2025-02 GIRPP template), HIPAA-eligible under the list entry "AWS Transcribe [Includes Healthscribe]", us-east-1 only (fails brief OQ3's us-west-2 default), US$0.10/min, en-US. Developer guide now carries a banner steering to Connect Health Ambient. REPO's sup-hcls-generate-clinical-notes-with-ai (2024-07-23) ships a Transcribe+Bedrock fallback "for regions without HealthScribe" — the constraint is old enough that AWS samples work around it. | https://docs.aws.amazon.com/transcribe/latest/dg/health-scribe.html ; https://aws.amazon.com/healthscribe/pricing/ | COMP §3 (Primary), REPO (fallback sample) | High |
| C36 | Transcribe Medical (last What's New 2021-01) and Comprehend Medical (last What's New 2020-07) are quiet, not retired: docs live, no end-of-support notice. Sample activity stopped too: medical-transcription-analysis 2023-07-18; amazon-comprehend-medical-fhir-integration archived 2024-01-22. Newer surfaces for the same jobs: HealthScribe/Connect Health (notes, coding preview) and HealthLake integrated NLP. | COMP §3; REPO U3 table | COMP, REPO | High |
| C37 | Amazon Connect Health GA 2026-03-05, HIPAA-eligible, us-east-1 + us-west-2; GA features: patient verification, ambient documentation; preview: appointment management, patient insights, medical coding. Both scouts cite the same What's New; the AI dossier's 2026-04-28 date is the Connect rename post (X9). PORT did not surface Connect Health at all. | https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/ | REPO, COMP | High |
| C38 | sample-amazon-connect-health-unified-clinical-workflow (pushed 2026-08-31, CloudFormation ×3, MIT-0) is the most complete U3 artefact (capture → SOAP → coding → HealthLake DocumentReference, review in Agent Workspace) but: (a) comparator check confirms its care-manager workspace uses Bedrock Agents classic with 6 action groups — on catalog rule 4's retired list; (b) it requires a registered Amazon Connect instance and Connect Health domain (semi deploy, not empty→running); (c) medical coding is gated preview. The sibling sample-amazon-connect-health-point-of-care (2026-03-31) has the same Connect prerequisites; its Bedrock use is a pre-visit narrative, not agents (not re-checked). | README fetched 2026-09-04: https://github.com/aws-samples/sample-amazon-connect-health-unified-clinical-workflow | REPO + comparator check (X3) | High |
| C39 | sample-healthscribe-bedrock-clinical-analysis (pushed 2026-04-07, CDK, ECS Fargate, React+Vite, Cognito, CloudFront, HealthScribe streaming + Bedrock "12 specialist agents", empty→running via deploy.sh, needs an ACM cert) is the best stack-spine match for U3; no HealthLake write-back or Comprehend Medical coding step documented. | https://github.com/aws-samples/sample-healthscribe-bedrock-clinical-analysis | REPO only | High |
| C40 | Guidance "Identifying Diagnosis Codes from Clinical Notes on AWS" (guidance-for-identifying-diagnosis-codes-from-clinical-notes-on-aws: CDK Python, MIT-0, not archived, pushed 2026-04-13, 4 stars — comparator check) covers HealthScribe → S3 → Comprehend Medical ICD-10-CM → Bedrock Converse + OpenSearch Serverless KB → Lake Formation/Athena/QuickSight; README cost table US$495.89/month (April 2025) dominated by OpenSearch Serverless (US$350). No clinician review UI, Step Functions, or HealthLake write-back. REPO did not find this Guidance. | https://docs.aws.amazon.com/solutions/identifying-diagnosis-codes-from-clinical-notes-on-aws/ ; https://api.github.com/repos/aws-solutions-library-samples/guidance-for-identifying-diagnosis-codes-from-clinical-notes-on-aws | PORT C-map + comparator check (X4) | High |
| C41 | aws-healthscribe-demo (2025-04-08, 60 stars) is Amplify Gen 1 (aws-amplify ^6.14, no @aws-amplify/backend) with a CodeCommit-based deploy doc; UI patterns worth borrowing, deploy path stale. MOB lists it as one of only two web-only Amplify healthcare samples. | package.json and docs/deploy.md fetched 2026-09-04 | REPO, MOB A12 | High |
| C42 | U3 Tier 3 (note-quality / coding classifier on SageMaker): none; only LLM-as-judge and clinical-report evaluation notebooks (healthcare-LLM-as-a-Judge, eval-genai-techniques-clinicalreport 2024-04-15). | REPO U3 table; PORT G | REPO, PORT | High (absence) |
| C43 | Comprehend Medical DetectPHI detects but does not redact and per AWS "does not meet the requirements for de-identification" — human review or additional methods required; Transcribe (Medical) PHI identification is free in all Transcribe regions. | https://docs.aws.amazon.com/comprehend-medical/latest/dev/textanalysis-phi.html ; https://aws.amazon.com/comprehend/medical/faqs/ | COMP 5.3.1/5.3.2 only | High |
U4 — Intelligent document intake
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C44 | GenAI IDP Accelerator (aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws, pushed 2026-09-04, v0.6.6, 302 stars, MIT-0): one-click CloudFormation/SAM (us-east-1, us-west-2, eu-central-1) with CDK/Terraform alternates; Pattern 1 = Bedrock Data Automation end-to-end, Pattern 2 = Textract OCR → Bedrock; built-in human review (not A2I); MLflow evaluation; Cognito+WAF web UI; MCP via AgentCore Gateway. Full generic U4 T1+T2; no Comprehend Medical / HealthLake / Macie. | https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws | REPO only (PORT did not surface it) | High |
| C45 | Guidance for Intelligent Document Processing on AWS (docs page) is now AgentCore Runtime/Identity/Gateway + Strands multi-agent + Textract + ECS dashboard; its Security pillar text points to Comprehend Medical PHI redaction; sample aws-ai-intelligent-document-processing pushed 2026-05-04, 244 stars. REPO did not verify the repo contents match the page. | https://docs.aws.amazon.com/solutions/intelligent-document-processing-on-aws/ ; https://github.com/aws-samples/aws-ai-intelligent-document-processing | REPO, PORT C-map | High (page) / Medium (repo) |
| C46 | sample-healthcare-agents (pushed 2026-09-03, CDK TS, Amplify-hosted React + Cognito, AgentCore Runtime + Gateway, Strands, HealthLake FHIR R4, Comprehend Medical, B2B Data Interchange EDI 837P, CDS Hooks; cdk deploy --all) is full for U4 Tier 2 (prior-auth packet, eligibility, coding, claims, appeals); no PDF intake. | https://github.com/aws-samples/sample-healthcare-agents | REPO only | High |
| C47 | Textract vs BDA (brief sub-question): in AWS's own code both are first-class and BDA is the default pattern (C44); Textract is on the HIPAA list by name, BDA only via the general-feature rule (Medium); two official workshops exist, one per path ("Intelligent Document Processing with AWS AI Services", "Document Processing with Amazon Bedrock Data Automation"). Consequence: BDA is the 2026 default, but the portal must state its eligibility rests on the feature rule. | REPO U4 table; COMP §2; PORT B6 | REPO, COMP, PORT | High (default) / Medium (BDA eligibility) |
| C48 | sample-scalable-intelligent-document-processing-with-amazon-bedrock-data-automation (2026-07-28) uses A2I + Ground Truth (retired list) → cannot link; superseded by C44. amazon-textract-idp-cdk-constructs stale (2024-04-29). | REPO U4 table | REPO only | High |
| C49 | De-identification: aws-ai-phi-deidentification (2025-04-23, CDK single command, Textract → Comprehend Medical → redaction UI) is the only deployable de-id pipeline; Bedrock-based PHI detection in DICOM/PDF is a practitioner pattern (Clario, 2026-08-19, F1 0.975–0.995, human-in-the-loop). Combined with C43: automated de-id is an assist, not a Safe Harbor guarantee. | https://github.com/aws-samples/aws-ai-phi-deidentification ; https://aws.amazon.com/blogs/architecture/how-clario-automates-phi-pii-detection-in-dicom-images-using-amazon-bedrock/ | REPO, COMP 5.3.7/5.3.8 | High (repo) / Medium (Bedrock pattern) |
| C50 | U4 Tier 3 (document-type classifier / denial-risk on SageMaker): none; the Accelerator classifies with Bedrock. | REPO Table B; PORT G | REPO, PORT | High (absence) |
| C51 | U4 is the best-covered catalog item and has the lowest new-build value (Tier 1–2). | REPO summary/notes; PORT G | REPO, PORT | High |
| C52 | "Guidance for Ingesting PDF and Image Files to AWS HealthLake" is architecture-only (no sample-code link); the "Intelligent Healthcare Systems: FHIR, AI, and AWS HealthLake" workshop (CMS-1500 / SOAP notes → FHIR) is the nearest healthcare IDP tutorial (module list unreadable, G1). | https://aws.amazon.com/solutions/guidance/ingesting-pdf-and-image-files-to-aws-healthlake/ ; https://catalog.us-east-1.prod.workshops.aws/workshops/da0cf4f5-63d4-4e4b-bf98-6a48b748d914/en-US | REPO, PORT B2 | Medium |
U5 — Population health analytics and risk models
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C53 | "Guidance for Multi-Modal Data Analysis with AWS Health and ML Services" (guidance-for-multi-modal-data-analysis-…, pushed 2024-12-17, MIT-0; one-click CloudFormation SageMaker domain + sequential notebooks; HealthOmics/HealthLake/HealthImaging → Lake Formation → Athena → QuickSight; Feature Store → AutoGluon → real-time endpoint; Synthea) is the closest U5 T1+T3 artefact — but notebook-driven, QuickSight-era, no S3 Tables/Iceberg, no de-identification, README has no cost table. | https://docs.aws.amazon.com/solutions/multi-modal-data-analysis-with-aws-health-and-ml-services/ ; https://github.com/aws-solutions-library-samples/guidance-for-multi-modal-data-analysis-with-aws-health-and-ml-services | REPO, PORT C-map | High |
| C54 | Patient Entity Resolution Guidance (2025-09-11) + "Patient Matching with AWS Entity Resolution" workshop = one U5 T1 component (EMPI). | https://github.com/aws-solutions-library-samples/guidance-for-patient-entity-resolution-with-aws-healthlake | REPO, PORT | High |
| C55 | S3 Tables is not on the HIPAA list by name (re:Post thread unresolved, 403 to fetch) and no healthcare sample lands data in S3 Tables; the Iceberg landing exists only as a CDC sample (C27). Converging gap on the catalog's U5/U2 cold path (see G2). | COMP §2 + gap 3; REPO | COMP, REPO | Medium-Low (eligibility) / High (no sample) |
| C56 | Amazon Quick is HIPAA-listed, but every U5 sample, Guidance page and workshop still says QuickSight — any fork needs a rename pass and re-validation of the BI step. healthlake-workshop repo is archived (pushed 2026-01-29; archived 2026-02-04). | COMP §2; REPO; PORT B1 | COMP, REPO, PORT | High |
| C57 | U5 Tier 3 healthcare models: all readmission/outcome samples are 2021–2022 (aws-ml-readmission-prediction 2022-04-18; amazon-healthlake-patient-outcome-prediction archived 2022-09-06; Data Wrangler 2021-10-25); newest healthcare ML samples are Clean Rooms ML ADR prediction (2026-05/07), outside the spine; generic MLOps CDK spine is current (2026-07-28). PORT's "Fork the Multi-Modal Guidance for T3" and REPO's "stale only → build" differ (X5). | REPO U5 table + Table B; PORT G | REPO, PORT (disagree on verdict) | High (facts) |
| C58 | U5 Tier 2 (NL analytics over the lake): only extract-medical-insights-from-amazon-healthlake-with-bedrock (2024-11-05, Apache-2.0, Streamlit, no IaC, text-to-SQL) — a snippet, predates Quick. | https://github.com/aws-samples/extract-medical-insights-from-amazon-healthlake-with-bedrock | REPO, PORT D5 | High |
| C59 | Clarify successor for bias (catalog-v0 U5 T3 VERIFY): no scout answered it (see G5). | — | — | — |
U6 — Contact center with AI agents (optional)
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C60 | Connect Health makes U6 Tier 1's identity verification and (preview) scheduling first-party product features rather than Lex + Lambda code; sample-healthcare-realtime-eligibility (2026-03-03) plugs eligibility into it. PORT, unaware of Connect Health, recommended linking only the generic "Getting started with Amazon Connect" workshop. | https://aws.amazon.com/products/connect/health/ ; https://github.com/aws-samples/sample-healthcare-realtime-eligibility | REPO, COMP (product); PORT disagrees on link target (X3) | High |
| C61 | Amazon Connect (renamed Connect Customer 2026-04-28 per dossier) and Lex are HIPAA-listed. | COMP §2 | COMP only | High |
| C62 | sample-amazon-connect-bedrock-agent-voice-integration (2025-11-18, CDK TS) uses Bedrock Agents classic action groups → cannot link; Connect+Lex+CDK structure reusable. voice-enabled-patient-diary (2024-08-27) Lex version unverified. | REPO U6 table | REPO only | High |
| C63 | sample-Nova-Sonic-AgentCore-Healthcare-Call-Center (2026-05-21, CDK Python, MIT not MIT-0, AgentCore + Nova 2 Sonic, no Amazon Connect) is the modern-agent-stack U6 T2 sample, empty→running. | https://github.com/aws-samples/sample-Nova-Sonic-AgentCore-Healthcare-Call-Center | REPO only | High |
| C64 | No healthcare-specific Connect workshop or Guidance exists; U6 T3 demand forecasting is a Connect product feature ("forecasting, capacity planning, and scheduling" workshop), not a SageMaker build. | REPO U6 table; PORT B7/G | REPO, PORT | High |
| C65 | Pinpoint's engagement successor is Connect Customer outbound campaigns + Customer Profiles (C21), so U1 reminders/journeys and U6 share a service — serverless-patient-engagement-stack (Pinpoint + Connect) maps naturally onto it after replacing Pinpoint. | MOB D2; REPO U1 table | MOB, REPO | Medium (inference) |
P0 — Education portal
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C66 | Workshop Studio content = git repo with contentspec.yaml (v2.0: accountSources: [WorkshopStudio, CustomerProvided], participant IAM policy, region config, cloudformationTemplates[]), content/, static/, optional infrastructure/ (CDK synthesised into static/). Two provisioning modes (event account via access code; own account). Discovery moved to Builder Center 2025-11-18; workshops.aws/categories/* 301s there. | https://github.com/aws-samples/rancher-on-aws-workshop/blob/main/contentspec.yaml ; https://github.com/aws-samples/sample-agent-jailbreak-to-cloud-takeover ; https://aws.amazon.com/about-aws/whats-new/2025/11/workshops-available-aws-builder-center | PORT A1–A7 (Primary); REPO (What's New + redirect observed) | High |
| C67 | Every Workshop Studio and Builder Center page is client-rendered and unreadable by the fetch tool; all workshop coverage judgements (B1–B6; the HealthLake, SMART-on-FHIR, Intelligent Healthcare Systems, Patient Matching, HCLS Agents workshops) rest on titles, AWS descriptions and backing repos. | REPO gaps; PORT method caveat + gaps | REPO, PORT | High (that it is a gap — G1) |
| C68 | Solutions Library pages moved to docs.aws.amazon.com/solutions/<slug>/ (301 from aws.amazon.com/solutions/guidance/…). Guidance page anatomy: overview → architecture PNG/PDF + numbered steps → "Go to sample code" → six Well-Architected pillar paragraphs → related content → usage disclaimer; cost table and deploy steps live in the repo README, not the page. Solution header (version, released, deploy time, estimated cost) is the best "is it maintained?" signal. Guidance code is "not for production accounts" — forked chapters must carry that disclaimer. | https://docs.aws.amazon.com/solutions/guidance-disclaimers/ ; PORT C1–C5 | PORT (Primary); REPO independently cites the docs-domain URLs | High |
| C69 | aws-samples conventions: MIT-0 default; README tail ## Security / ## License; Guidance README contract Overview → Cost → Prerequisites → Deployment → Validation → Running → Next Steps → Cleanup (adherence varies; no public template repo found); serverless-patterns' example-pattern.json is the smallest proven docs-from-metadata contract. | https://github.com/aws-samples/serverless-patterns ; https://github.com/aws/mit-0 | PORT D1–D7 only; REPO's license census (MIT-0 default, Apache-2.0 minority, one MIT, one CC-BY-SA, one unlicensed) is consistent | High |
| C70 | AWS's own examples of a portal generated from repos: the HCLS Agents Toolkit GitHub-Pages site (Astro, agent catalog, developer guide) and eks-workshop-v2 (Docusaurus + Terraform, off Workshop Studio). No public "education portal" repo for this purpose exists — P0 is build-new. Recommended pattern: repo-owned README (Guidance contract) + MADR 4 ADRs in docs/decisions/ + contentspec.yaml per use case, aggregated at build time (Backstage TechDocs / Antora model). | https://aws-samples.github.io/amazon-bedrock-agents-healthcare-lifesciences/ ; https://github.com/aws-samples/eks-workshop-v2 ; https://adr.github.io/madr/ ; https://backstage.io/docs/features/techdocs/ | REPO, PORT | High |
| C71 | Comparators: Serverless Land (one machine-generated contract, thousands of two-service patterns); Google Jump Start Solutions (cost estimate before deploy, delete after; now behind console sign-in); Azure Architecture Center (dated, git-backed, pillar structure, no deploy button). Health AI Hub and healthcare.awsaccelerators.com demos are partner/demo showcases without deploy links. | PORT F1–F5; REPO P0 table | PORT, REPO | High |
Cross-cutting (compliance evidence, Tier 2 design, regions, licences)
| # | Claim | Sources (dated) | Corroborated by | Confidence |
|---|---|---|---|---|
| C72 | Dossier item F-15 closes as confirmed: Bedrock FAQ and security page state content is not used to improve base models and not shared with providers (per-region model deployment accounts); compliance list = HIPAA eligible, SOC 1/2/3, ISO 9001/27001/27017/27018/27701/22301/20000, CSA STAR L2, GDPR, FedRAMP Moderate (commercial), FedRAMP High (GovCloud US-West). IL4/IL5 not seen (stays Medium). | https://aws.amazon.com/bedrock/faqs/ ; https://aws.amazon.com/bedrock/security-compliance/ ; https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html | COMP 5.1 only | High |
| C73 | Bedrock retention is a per-account/per-project mode (none < default < aws_review < legacy provider_data_share). Claude Fable 5 / 5.1 require aws_review (all prompts/completions retained within AWS up to 30 days; classifier-flagged traffic may be human-reviewed by AWS); Opus 4.8 allows none; Enterprise Frontier Safeguards customers get ZDR through 2026-12-31. Enforceable by SCP on bedrock:DataRetentionMode / bedrock-mantle:DataRetentionMode. Retained data lands in the cross-region destination region. Design consequence (inference): an SCP pinning none on PHI accounts makes Fable 5.1 unavailable there by construction; route PHI prompts to ZDR-capable models or use Fable 5.1 only on de-identified inputs with the decision logged; use a US-only inference profile. | https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html ; https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html | COMP 5.2 only (builds on dossier §2.E.4) | High (facts) / Medium (design inference) |
| C74 | Bedrock Guardrails sensitive-information filters evaluate text sent to and returned from the model only. Verbatim (comparator re-fetch 2026-09-04): "In tool use (function calling) workloads, it does not evaluate the following, so PII in these fields is neither blocked nor masked: PII the model generates into tool call arguments (toolUse.input …) … PII in tool results your application returns to the model (toolResult) … PII in the tool definitions you supply". Also: model invocation logs "always contain the original, unmodified request regardless of guardrail intervention"; the trace match field carries the raw PII; built-in health types are only CA_HEALTH_NUMBER and UK_NATIONAL_HEALTH_SERVICE_NUMBER (US MRN/Medicare/NPI need regex). | https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-sensitive-filters.html | COMP 5.3.3 + comparator check (X1) | High |
| C75 | AgentCore Gateway interceptors and Policy (AWS ML blog 2026-06-01): Policy = Cedar-based deterministic access control at the Gateway; Lambda REQUEST interceptors have full read/write access to headers and body; RESPONSE interceptors filter/modify what the agent sees after a tool responds and "can also integrate with services such as Amazon Bedrock Guardrails for use cases like personally identifiable information (PII) redaction"; work for Lambda, OpenAPI and MCP targets. This is the mechanism that makes "Guardrails at the tool boundary" achievable — via the Gateway, not the model-call guardrail. No healthcare sample of it exists. | https://aws.amazon.com/blogs/machine-learning/secure-ai-agents-with-policy-and-lambda-interceptors-in-amazon-bedrock-agentcore-gateway/ (2026-06-01) | Comparator check (X1); consistent with COMP 5.3.5 (Cedar on Gateway) | High (Primary AWS blog) |
| C76 | Security Hub CSPM's new AI Security Best Practices standard (network isolation, encryption, VPC placement, KMS for deployed AI resources) is directly usable as Tier 2/3 compliance evidence; practical HIPAA pairing = FSBP + NIST 800-53 r5 + Config HIPAA pack. | https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.html | COMP 4.3 only | High |
| C77 | Retired-service dependents (cannot be linked as-is): serverless-patient-engagement-stack (Pinpoint), sample-amazon-connect-bedrock-agent-voice-integration (Bedrock Agents classic), sample-scalable-intelligent-document-processing-with-amazon-bedrock-data-automation (A2I/Ground Truth), greengrass-v2-sagemaker-edge-manager-python (Edge Manager), amazon-sagemaker-aws-greengrass-custom-timeseries-forecasting (IoT Analytics, Greengrass v1), sample-amazon-connect-health-unified-clinical-workflow (Bedrock Agents classic — confirmed by comparator, C38), amazon-archives/medical-mobile-iot-with-aws (Kinesis Data Analytics), the last-mile BLE Guidance (Timestream, likely LiveAnalytics — MOB F11), and aws-amplify-cdk-iot-ble-swift-app's iOS layer (EOS Mobile SDK — C31). Safe despite its name: amazon-bedrock-agents-healthcare-lifesciences (AgentCore + Strands). | REPO retired table; MOB F11/F12; comparator checks | REPO, MOB + comparator | High |
| C78 | Region constraints converge on us-east-1 as the primary demo region: HealthScribe us-east-1 only (C35); Connect Health, HealthLake, Comprehend Medical, Transcribe Medical in both defaults; Device Farm us-west-2 only (C25); Fable 5.1 retained data lands in the inference destination region (C73); IDP Accelerator one-click in us-east-1/us-west-2/eu-central-1. | COMP §6; MOB E2; REPO C44 | COMP, MOB, REPO | High (facts) / Medium (the "pin us-east-1" inference) |
| C79 | Licences (brief OQ5): MIT-0 default; Apache-2.0 on landing-zone-accelerator-on-aws, aws-greengrass-ec2-device-farm, extract-medical-insights-…, eks-workshop-v2, IoT Device SDK for Swift; MIT on sample-Nova-Sonic-…; CC-BY-SA-4.0 on aws-security-reference-architecture-examples and on medical-mobile-iot-with-aws docs; no licence on cleverdevil/healthlake and one Clean Rooms sibling. All permissive except the CC-BY-SA and unlicensed ones. | REPO notes; PORT D1; MOB F12 | REPO, PORT, MOB | High |
2. Agreements (multi-angle corroboration, strongest dossier claims)
| # | Agreement | Claims | Angles |
|---|---|---|---|
| A1 | F0 must be split: LZA/Control Tower is the authoritative organisation layer (link), and a single-account HIPAA baseline has no public example (build). Control Tower is current. | C1, C2, C3 | REPO, COMP, PORT |
| A2 | U1 Tier 1 (portal + native mobile) has no AWS-official example on any current stack; it is the highest-value new build. | C13, C14, C15 | REPO, PORT, MOB |
| A3 | U2 has no end-to-end example, no HealthKit/Health Connect guidance, and no current phone→IoT Core sample; every U2 tier is new work. | C26, C28, C30, C31, C32, C33 | REPO, PORT, MOB |
| A4 | Pinpoint is retired (EOS 2026-10-30) and belongs on rule 4's list; End User Messaging is the named push successor; SNS mobile push is a supported alternative. | C20, C21 | MOB, REPO, COMP + comparator |
| A5 | Amazon Connect Health (GA 2026-03-05, HIPAA-eligible, both default regions) reshapes U3 (ambient documentation as a product) and U6 (patient verification as a product). | C37, C38, C60 | REPO, COMP |
| A6 | Transcribe Medical and Comprehend Medical are quiet-not-retired; HealthScribe/Connect Health and HealthLake NLP are AWS's newer surfaces for the same jobs; HealthScribe is us-east-1 only. | C35, C36 | COMP, REPO |
| A7 | U4 is the best-covered item (IDP Accelerator, IDP Guidance on AgentCore, sample-healthcare-agents); BDA is the 2026 default with Textract retained for OCR-first; BDA's eligibility rests on the feature rule. | C44–C47, C51 | REPO, COMP, PORT |
| A8 | Automated de-identification (Comprehend Medical DetectPHI, the de-id sample, Bedrock detectors) assists but does not satisfy Safe Harbor on its own; human review is part of the demo. | C43, C49 | COMP, REPO |
| A9 | U5's closest artefact is the 2024-12 Multi-Modal Guidance; S3 Tables, Quick and de-identification are all new work on top of it; U5 T2 has only a snippet. | C53–C56, C58 | REPO, PORT, COMP |
| A10 | All Tier 3 healthcare-specific models (U1 no-show, U3 note quality, U4 denial risk, U5 risk newer than 2022) are absent publicly; the generic SageMaker Pipelines/Registry CDK spine is current. | C23, C42, C50, C57 | REPO, PORT |
| A11 | P0 is build-new; AWS's three content surfaces (Workshop Studio, Solutions Library, aws-samples) have stable, copyable contracts; the repo-generated docs site (HCLS toolkit, eks-workshop-v2) is the pattern. | C66, C68–C71 | PORT, REPO |
| A12 | Workshop Studio module content is unreadable to all scouts; every "link this workshop" judgement is provisional. | C67 | REPO, PORT |
| A13 | The retired-service list is longer than catalog-v0's: add Pinpoint, SageMaker Edge Manager, Kinesis Data Analytics naming, the classic AWS Mobile SDKs (EOS 2026-08-01), Amplify Gen 1 (maintenance). Several otherwise-attractive repos are blocked by it. | C17, C20, C33, C77 | REPO, MOB, COMP |
| A14 | Every catalog-named service is HIPAA-listed by name except S3 Tables, Timestream for InfluxDB, Valkey engine and Bedrock sub-features; Connect Health's eligibility is corroborated by two angles. | C11, C37 | COMP, REPO |
| A15 | us-east-1 is the only region where every catalog service and sample works; us-west-2 fails on HealthScribe. | C35, C78 | COMP, MOB, REPO |
3. Gaps (brief questions no scout could close)
| # | Gap | Who looked | Comparator re-check |
|---|---|---|---|
| G1 | Workshop Studio module lists for every healthcare workshop (HealthLake, SMART on FHIR, Intelligent Healthcare Systems, Patient Matching, HCLS Agents) and the generic component workshops; the HealthScribe workshop's URL was never located. All pages are client-rendered. | REPO, PORT | Not re-tried (same tool). Needs a browser session before any chapter links a workshop. |
| G2 | S3 Tables HIPAA eligibility by name. Not on the list; re:Post thread unresolved. | COMP | re:Post still 403 on 2026-09-04; web results are third-party only. Open. Treat as feature-rule-only; confirm with the account team before PHI lands in S3 Tables, or keep the Iceberg landing de-identified. |
| G3 | Timestream for InfluxDB HIPAA eligibility by name. List says "Amazon Timestream"; FAQ compliance sentence is under LiveAnalytics. | COMP | Timestream developer-guide compliance page returned no readable HIPAA sentence; search summaries asserting "includes InfluxDB" are third-party synthesis, not AWS text. Open. Same handling as G2. |
| G4 | IoT Core → Timestream for InfluxDB sample with IaC — none exists (distinct from G3: even if eligible, the hot path has no public example). | REPO | Not re-tried. |
| G5 | SageMaker Clarify successor for bias/explainability (catalog-v0 U5 T3 VERIFY). No scout addressed it. | none | Not checked — outside the targeted-check remit; flag to validator/lead. |
| G6 | Comprehend Medical: DetectPHI, ICD-10-CM and RxNorm per-unit prices (page shows worked examples only); region list from a primary page (General Reference unreadable; third-party mirror used). | COMP | Not re-tried. |
| G7 | Whether HIPAA is among Control Catalog's "seven new compliance frameworks" (2025-06/2025-11 posts). | COMP | Not re-tried. |
| G8 | Amplify compliance documentation page (returned only a title); Gen 2 backend eligibility rests on the per-service list + "AWS Amplify Console". Also the Android feature-matrix ambiguity on the REST frontend category. | COMP, MOB | Not re-tried. |
| G9 | "Guidance for Patient Outcome Prediction on AWS" — docs URL 404; the related amazon-healthlake-patient-outcome-prediction repo was archived 2022-09-06. Two signals that it is retired, no AWS statement. | PORT, REPO | Not re-tried. |
| G10 | Bedrock IL4/IL5 and the Anthropic third-party model terms page (not fetched); dossier sub-claim stays Medium. | COMP | Not re-tried. |
| G11 | An AWS-published pattern for HealthKit / Health Connect / BLE ingestion — brief question 3 asked for "the supported ways"; the answer is "generic Cognito+MQTT or REST, no AWS guidance, one stale BLE sample". The supported paths are documented; an AWS recommendation is not. | MOB, REPO | Not re-tried. |
| G12 | Exact wording of Amplify's "Migrate from Pinpoint-backed features" page (push device registration → Connect Customer Profiles was captured by a summariser only). | MOB | Not re-tried. |
| G13 | Whether aws-ai-intelligent-document-processing (pushed 2026-05-04) actually contains the AgentCore/Strands architecture shown on the Guidance page. | REPO | Not re-tried. |
| G14 | Amazon Connect Health pricing — not on the announcement or product page pointer. | COMP | Not re-tried. |
| G15 | The community "Apple Watch → IoT Core → Flutter dashboard" repo described by search summaries — never located; treat as non-existent. | REPO | Not re-tried. |
| G16 | Whether sample-amazon-connect-health-point-of-care shares the unified-workflow sibling's Bedrock Agents classic dependency (REPO describes its Bedrock use as a pre-visit narrative). | — | Not checked; only the unified-workflow README was. |
4. Contradictions
Stated as found; resolved only where a targeted primary check settled it.
X1 — "Guardrails at the tool boundary" (catalog-v0 U2 Tier 2) vs Bedrock Guardrails scope
- catalog-v0 U2 Tier 2 assumes Guardrails sit "at the tool boundary" of AgentCore Gateway MCP tools.
- COMP 5.3.3 (Primary, High): the Guardrails sensitive-information filter "does not evaluate"
toolUse.input,toolResultor tool definitions; "the tool layer must do its own masking". - Comparator check: (1) the doc note is confirmed verbatim (C74). (2) AWS ML blog 2026-06-01 (C75) shows AgentCore Gateway
RESPONSEinterceptors can "integrate with … Amazon Bedrock Guardrails for … PII redaction" andREQUESTinterceptors have full read/write on the tool request body; Policy (Cedar) governs which tools may be called. - Resolution: Partly resolved. catalog-v0's wording is wrong as written — attaching a guardrail to the model call does not cover tool arguments or results. The intent is achievable, but via a different mechanism: Gateway interceptors that call Guardrails (
ApplyGuardrail) on tool I/O, plus Cedar Policy on tool access, plus CloudWatch Logs data protection because invocation logs keep the raw prompt. What remains open: no healthcare sample of interceptor-based PHI masking exists, and whether the interceptor Lambda (which handles raw PHI) is itself an acceptable PHI processor is a risk-analysis question, not a sourcing one. catalog-v1 should rewrite U2 T2 (and every Tier 2 line that says "Guardrails") accordingly.
X2 — Pinpoint successor: SNS/EventBridge (catalog-v0) vs End User Messaging (MOB)
- catalog-v0 U1 Tier 1: "SNS push notifications (VERIFY Pinpoint end of support; SNS/EventBridge successor)".
- MOB D1–D4 (Primary, High): Pinpoint EOS 2026-10-30; the AWS-named successor for push/SMS/voice/OTP is AWS End User Messaging; SNS mobile push is supported but "not the successor AWS names"; Amplify's own migration banner names EUM/SES/Connect/Kinesis. EventBridge is not named by AWS as a successor for anything.
- COMP §2: list entry is "Amazon Pinpoint and End User Messaging" (one row), consistent with EUM being the continuation.
- Comparator check: migration guide banner verbatim: "APIs related to SMS, voice, mobile push, OTP, and phone number validate are not impacted by this change and are supported by AWS End User Messaging." What becomes inaccessible is "endpoints, segments, campaigns, journeys, and analytics".
- Resolution: Resolved. Catalog-v0's "SNS/EventBridge successor" should read: push = EUM Push (named successor, same
send-messagesAPI) or SNS mobile push (supported, simpler for EventBridge→SNS fan-out in U2 alerts); email = SES; SMS = EUM; engagement = Connect Customer campaigns; client analytics = Kinesis. Residual caveat for build time (not a contradiction): confirm that a "Pinpoint application" resource used as the EUM push application ID is not among the resources removed on 2026-10-30 — AWS's text says push APIs are unaffected, but it does not name the application resource explicitly.
X3 — Amazon Connect Health reshaping U3/U6: REPO/COMP vs PORT, and the "near-full" U3 sample
- REPO (Primary, High):
sample-amazon-connect-health-unified-clinical-workflowis "near-full" for U3 T1+T2; Connect Health "changes the U6 build decision" — link the product rather than build Lex+Lambda identity checks. - COMP §3 (Primary, High): U3 T1 should prefer HealthScribe or Connect Health Ambient over Transcribe Medical + Comprehend Medical; Connect Health is HIPAA-eligible in both default regions (HealthScribe direct is us-east-1 only).
- PORT G (Primary for what it saw): never surfaced Connect Health; recommends U3 = fork the diagnosis-codes Guidance, U6 = link the generic "Getting started with Amazon Connect" workshop, "keep as a link-only chapter unless angle 1 finds a Guidance".
- Comparator check: the unified-workflow README states "Amazon Bedrock Agents reason over the question, call action groups (one Lambda per domain task)" and "Amazon Bedrock Agent with 6 action groups" — Bedrock Agents classic, on catalog rule 4's retired list; prerequisites include a registered Amazon Connect instance, Connect Health domain, HealthLake datastore and Bedrock access (three sequential stacks: shared, guardrail, provider).
- Resolution: Partly resolved, and the picture is worse than REPO's "near-full". Connect Health the product is current and eligible (A5), but the best sample built on it (a) has a retired-service dependency in its Tier 2 half and (b) is not empty→running. PORT's U6 recommendation is simply incomplete (it did not see the product). What remains open and is a lead decision: whether U3 Tier 1 is built on HealthScribe direct (CDK TS sample fits the spine; us-east-1 only) or on Connect Health Ambient (both regions; requires a Connect instance, which makes every U3 deploy semi-manual and couples U3 to U6). The sources do not settle this; they only show the trade-off.
X4 — U3 fork target: REPO vs PORT name different repos, neither saw the other's
- REPO: fork
sample-healthscribe-bedrock-clinical-analysis(CDK TS, Fargate, React/Vite, Cognito, CloudFront; pushed 2026-04-07; empty→running; no HealthLake write-back, no coding step). - PORT: fork Guidance "Identifying Diagnosis Codes from Clinical Notes on AWS" (CDK Python; HealthScribe → Comprehend Medical ICD-10 → Bedrock + OpenSearch Serverless KB → QuickSight; README cost US$495.89/month; no review UI, no Step Functions, no write-back).
- Comparator check: the Guidance repo is live — MIT-0, not archived, pushed 2026-04-13 — so both candidates are current and permissive.
- Resolution: Open; not resolvable by sourcing. Both are valid fork bases with complementary gaps: the REPO candidate matches the stack spine (CDK TS) and has a clinician UI; the PORT candidate has the coding step and a Guidance page with pillars and a cost table but is CDK Python and carries a US$350/month OpenSearch Serverless line. A reasonable catalog-v1 outcome is "fork the HealthScribe CDK-TS sample for structure, port the Comprehend Medical coding step from the Guidance, build the Step Functions review + HealthLake write-back" — but that is a lead composition decision, not a finding.
X5 — U5 Tier 3: "stale only → build" (REPO Table B) vs "fork the Multi-Modal Guidance" (PORT)
- REPO Table B: "All healthcare readmission samples are 2021–2022; generic MLOps CDK is current — stale only." (REPO's own Table A rates the same Guidance "partial→full" for T1+T3, so the scout is internally inconsistent.)
- PORT G: "Fork — Multi-Modal Guidance already shows Feature Store → AutoGluon → endpoint; re-target to readmission risk."
- Both agree on the facts: the Guidance is 2024-12-17, notebook-driven, CloudFormation-launched SageMaker domain, QuickSight-era, no cost table.
- Resolution: Open. The disagreement is about whether a 2024-12 notebook Guidance counts as a fork base for a CDK-spine Tier 3. Practical synthesis for the lead: fork the modelling logic (Feature Store schema, AutoGluon training, endpoint) from the Guidance into the current Pipelines/Registry CDK spine (
amazon-sagemaker-pipeline-deploy-manage-100x-models-python-cdk, 2026-07-28) — i.e. "fork content, build infrastructure".
X6 — Freshness of aws-amplify-cdk-iot-ble-swift-app: "stale, CDK v1, pre-Gen-2" (REPO) vs "migrated to CDK v2 2026-06-09, best fork candidate" (MOB)
- REPO: README references CDK v1.105 and CocoaPods → pre-Gen-2 Amplify, CDK v1; "stack is stale".
- MOB F10: commits 2026-06-09 "migrate CDK v1 to v2, resolve all 93 security vulnerabilities" and "scope IoT policy … least-privilege"; "verify it is Amplify Swift v2, not v1/aws-sdk-ios, before forking".
- Comparator check: commit log confirms the 2026-06-09 CDK v1→v2 migration (four commits, then nothing since 2021). README is unchanged ("CDK version 1.105.0", "AWS Mobile SDK for iOS" via CocoaPods).
BLEX/Podfile:pod 'Amplify', '~> 1.0',pod 'AmplifyPlugins/AWSCognitoAuthPlugin', '~> 1.0',pod 'AWSIoT',pod 'AWSMobileClient'— Amplify iOS v1 plus the classicaws-sdk-iosIoT/MobileClient pods that reached end of support 2026-08-01 (C17). - Resolution: Resolved — each scout was half right. The CDK/IoT side is current (v2, least-privilege policy) and forkable; the iOS side is on an end-of-support SDK and must be rewritten on Amplify Swift 2.x + AWS IoT Device SDK for Swift (GA 2026-06-01). It is a fork-for-structure candidate for the U2 device-pairing chapter, not a link.
X7 — "Zero AWS-official Amplify Gen 2 samples" (REPO) vs an AWS Gen 2 IoT sample (MOB F13)
- REPO: aws-samples org search for "amplify gen2" in name/description returned zero repos; "no AWS-official Gen 2 healthcare or mobile sample exists".
- MOB F13:
aws-samples/aws-appsync-iot-core-realtime-dashboarduses "AppSync + Amplify Gen 2 + Location Service". - Comparator check: README opens "this project has been updated to use Amplify Gen2"; deploy is
npx ampx sandbox; pushed 2026-09-03; MIT-0; 126 stars; topicsamplify-js,aws-iot-core,location-services. - Resolution: Resolved. REPO's absence claim was too broad because its search keyed on name/description. Correct statement: no AWS-official Gen 2 sample with a healthcare framing or a native-mobile client exists; at least one AWS-official Gen 2 web + IoT Core sample does, and it is a fork candidate for U2's portal-side real-time view.
X8 — U4 primary artefact: IDP Accelerator + sample-healthcare-agents (REPO) vs Guidance for IDP on AWS + workshops (PORT)
- REPO: link the GenAI IDP Accelerator (one-click, pushed 2026-09-04, BDA default) for T1+T2 generic; fork
sample-healthcare-agents(2026-09-03, CDK TS) for T2 healthcare; the IDP Guidance repo "not verified". - PORT: link the two official IDP workshops; fork the Guidance for IDP on AWS sample (AgentCore-based per page) for healthcare specifics; did not surface the Accelerator or
sample-healthcare-agents. - Resolution: Open but complementary, not conflicting on the verdict (both say link + fork). The objects differ because each scout searched a different surface. No check performed. Lead choice: the Accelerator is the stronger link (deployable, current, has evaluation and review built in);
sample-healthcare-agentsis the stronger fork for T2 (spine-matching CDK TS, HealthLake, prior-auth); the Guidance page is the better architecture explainer to embed in the chapter. G13 (Guidance repo contents) should be closed before the Guidance repo is forked.
X9 — Amazon Connect Health GA date: 2026-04-28 (AI dossier, line 35) vs 2026-03-05 (REPO, COMP)
- Dossier (2026-09-03): dates "Connect Health GA" to the 2026-04-28 Connect rename post.
- REPO and COMP: both cite the What's New at
…/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/, dated 2026-03-05. - Resolution: Resolved in favour of 2026-03-05 — two independent scouts cite the dated primary announcement; the dossier's date is a re-mention in the rename post. Dossier line 35 should be corrected downstream.
5. Comparator checks performed (2026-09-04)
| Check | URL | Finding | Used in |
|---|---|---|---|
| Guardrails tool-use scope | https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-sensitive-filters.html | Note confirmed verbatim: toolUse.input, toolResult, toolSpec.* not evaluated; logs keep unmodified input; trace match holds raw PII. | C74, X1 |
| AgentCore Gateway interceptors | https://aws.amazon.com/blogs/machine-learning/secure-ai-agents-with-policy-and-lambda-interceptors-in-amazon-bedrock-agentcore-gateway/ (2026-06-01) | Policy = Cedar at Gateway; REQUEST interceptors r/w on body; RESPONSE interceptors "can also integrate with … Amazon Bedrock Guardrails for … PII redaction". | C75, X1 |
| Pinpoint migration guide | https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html | Push/SMS/voice/OTP APIs "not impacted … supported by AWS End User Messaging"; endpoints/segments/campaigns/journeys/analytics become inaccessible; In-App Messaging no successor. | C21, X2 |
| BLE Swift sample commits / README / Podfile | https://api.github.com/repos/aws-samples/aws-amplify-cdk-iot-ble-swift-app/commits ; raw README; BLEX/Podfile | CDK v2 since 2026-06-09; README still "CDK 1.105.0"; Podfile pins Amplify ~>1.0 + AWSIoT + AWSMobileClient (EOS 2026-08-01). | C31, X6 |
| Connect Health unified workflow README | https://github.com/aws-samples/sample-amazon-connect-health-unified-clinical-workflow | "Amazon Bedrock Agent with 6 action groups" = Bedrock Agents classic; needs registered Connect instance + Connect Health domain; 3 stacks. | C38, C77, X3 |
| Diagnosis-codes Guidance repo metadata | https://api.github.com/repos/aws-solutions-library-samples/guidance-for-identifying-diagnosis-codes-from-clinical-notes-on-aws | pushed 2026-04-13; MIT-0; not archived; 4 stars. | C40, X4 |
| AppSync IoT dashboard | https://api.github.com/repos/aws-samples/aws-appsync-iot-core-realtime-dashboard ; raw README (master) | "updated to use Amplify Gen2"; npx ampx sandbox; pushed 2026-09-03; MIT-0; 126 stars. | C27, X7 |
| Timestream compliance page | https://docs.aws.amazon.com/timestream/latest/developerguide/compliance.html | No readable HIPAA sentence; no InfluxDB/LiveAnalytics distinction retrievable. | G3 |
| S3 Tables re:Post | https://repost.aws/questions/QU7NkMC1dNQlaC9WzOwA-aEw/s3-tables-hipaa-eligibility | HTTP 403 (same as COMP). | G2 |
| Web searches | "Timestream for InfluxDB" HIPAA; "S3 Tables" HIPAA; AgentCore Gateway guardrails | Only third-party syntheses for the two eligibility questions (not usable as claims); the AgentCore search surfaced the 2026-06-01 AWS blog above. | G2, G3, C75 |
6. Link / fork / build reconciliation per item (input to catalog-v1)
"REPO view" = repo-coverage angle; "PORT view" = content-structure angle; "Reconciled" = comparator's reading of the evidence, with the open decision named where the sources do not settle it.
| Item / tier | REPO view | PORT view | Reconciled | Open decision |
|---|---|---|---|---|
| F0 org layer | Link LZA-for-Healthcare | Link LZA Solution + healthcare config | Link (C1, C3). Copy the Solution cost-table shape. | — |
| F0 single account | Build (no example) | Build (no workshop) | Build: CDK stack — KMS, CloudTrail, Config HIPAA pack (C4), Security Hub CSPM FSBP + NIST 800-53 r5 + AI Security BP (C5, C76), GuardDuty, Macie with PHI identifiers explicitly selected (C6), VPC endpoints, WAF; BAA step (C7); advanced-features account prerequisite (C8). Link SRA examples (CC-BY-SA, C10) and the Healthcare Lens with its 2022 date (C9). | Whether the F0 chapter also demonstrates the Bedrock DataRetentionMode SCP (C73) or leaves it to the compliance-evidence chapter. |
| U1 T1 | Build (no example) | Build | Build on Amplify Gen 2 (C15); native Swift + Kotlin have full parity, Flutter does not (C16); API Gateway HTTP → FastAPI + AppSync Events for real-time (C18); Cognito Essentials with passkey-with-user-verification or password+MFA, no OTP-first-factor (C19); push via EUM Push or SNS (X2); HealthLake datastore cost ~US$197/month (C24). Fork sample-intelligent-security-for-healthcare-apis for the API boundary (C14). | Native vs cross-platform (brief OQ6): evidence favours native Swift/Kotlin or React Native; Flutter is excluded by C16. Lead decision. |
| U1 T2 | Build (no example) | Fork scaffolding (HCLS toolkit, AgentCore workshops) | Fork scaffolding, build the assistant (C22); implement Tier 2 PHI controls per X1 (Gateway interceptors + Guardrails, Cedar Policy, logs data protection) and C73 (model choice / retention mode). | Which model family carries PHI prompts (ZDR-capable vs Fable 5.1 aws_review) — C73. |
| U1 T3 | Build | Link mechanics, build model | Build on the generic Pipelines/Registry CDK spine (C23). | — |
| U2 T1 | Build | Build | Build (C26–C31). Fork guidance-for-aws-iot-greengrass-foundations and aws-greengrass-ec2-device-farm for gateway/fleet; fork aws-appsync-iot-core-realtime-dashboard (Gen 2) for the portal view (X7); fork the BLE sample's CDK only and rewrite iOS on Amplify Swift 2 + IoT Device SDK for Swift (X6); Android via IoT Device SDK for Java v2 (C29). HealthKit/Health Connect via app read + Path A/B (C30). | Whether PHI-bearing vitals may land in Timestream for InfluxDB and S3 Tables at all (G2, G3) — or the hot/cold stores hold device-keyed de-identified data. |
| U2 T2 | Build (no example) | Build | Build, with the U2 T2 line rewritten per X1. | — |
| U2 T3 | Build (Edge Manager gone) | Build | Build: fork flink-keyed-random-cut-forest-example logic (add IaC) and the DeepAR MLOps CDK sample; edge scoring = Greengrass v2 + ONNX (C33). | — |
| U3 T1–T2 | Fork sample-healthscribe-bedrock-clinical-analysis; link Connect Health | Fork diagnosis-codes Guidance | Fork — candidates differ (X4); Connect Health sample is retired-dependent and semi-deploy (X3). Prefer HealthScribe (COMP judgement, C35) with Comprehend Medical for ontology linking (C36); build Step Functions review + HealthLake write-back. us-east-1 only. | HealthScribe direct vs Connect Health Ambient (X3); which repo is the fork base (X4). |
| U3 T3 | Build | Build | Build (C42); reuse LLM-as-judge notebooks for the evaluation harness. | — |
| U4 T1–T2 | Link Accelerator; fork sample-healthcare-agents | Link workshops + IDP Guidance; fork Guidance sample | Link + fork — objects differ (X8). BDA default, Textract retained (C47). Add Comprehend Medical PHI step, Macie on intake bucket, de-id sample (C49). Drop the A2I-based BDA sample (C48). | Which artefact is the chapter's primary link (X8); close G13 before forking the Guidance repo. |
| U4 T3 | Build | Build | Build (C50). | — |
| U5 T1 | Fork Multi-Modal Guidance | Fork Multi-Modal + Entity Resolution + HealthLake workshop | Fork the Guidance (C53) and Entity Resolution (C54); build S3 Tables/Iceberg landing, Quick rename (C56), de-id pipeline (C49). HealthLake workshop is archived — link for concepts only. | S3 Tables eligibility (G2). |
| U5 T2 | Build (snippet only) | Build | Build (C58). | — |
| U5 T3 | Build (stale only) | Fork Multi-Modal Guidance | Fork modelling content, build infrastructure (X5). | Clarify successor for bias (G5). |
| U6 T1–T2 | Link Connect Health + samples | Link generic Connect workshop | Link Connect Health as product (C60) and, if a repo is wanted, fork sample-Nova-Sonic-AgentCore-Healthcare-Call-Center (C63); do not link the classic-Agents voice sample (C62). Brief default 7 (light coverage) holds. | Whether U6 stays optional given that Connect Health also serves U3 (X3). |
| U6 T3 | Link Connect forecasting workshop | — | Link (C64); not a SageMaker build. | — |
| P0 | Build (no portal repo) | Build on existing contracts | Build (C70): Guidance page anatomy + Solution header + serverless-patterns README contract; MADR 4 ADRs; contentspec.yaml per use case; TechDocs/Antora-style aggregation; Guidance disclaimer on forked chapters (C68). Link official workshops only after G1 is closed. | Docusaurus vs Backstage TechDocs vs Antora — tooling choice (PORT E4–E6). |
| Cross-cutting: compliance evidence | sample-hipaa-assistant as an evidence-generation demo | — | Add chapters for: Bedrock retention modes + SCP (C73), Guardrails scope and logging caveats (C74–C75), Security Hub CSPM AI standard (C76), Macie PHI selection (C6), F-15 closure text (C72). | — |