Skip to main content

Comparison — AWS demo catalog research (2026-09-04)

Generated at build time from research/aws-demo-catalog/comparison.md in the repo — edit the source, not this page.

Comparator pass over the four scout files in sources/ (existing-reference-repos = REPO, healthcare-compliance-building-blocks = COMP, mobile-and-device-stack = MOB, education-portal-and-workshop-patterns = PORT) against brief.md and catalog-v0.md. Claims are numbered C-n and grouped by catalog item so the lead can write catalog-v1.md item by item. Gaps are G-n, contradictions X-n. "Corroborated by" lists the angles that independently support a claim; single-angle claims are marked as such. Tiers: Primary = AWS page/doc/repo/What's New; Practitioner = AWS blog case study or third party; Inference = scout or comparator reasoning from primary text.

Where a contradiction could be narrowed with a targeted check, I did one (§5, "Comparator checks", all retrieved 2026-09-04) and say what it found; where it remains open, I say so rather than pick a side.


1. Claims by catalog item

F0 — HIPAA-ready landing zone

#ClaimSources (dated)Corroborated byConfidence
C1The only AWS-official F0-level artefact is the LZA + LZA-for-Healthcare config: organisation-only (Control Tower Management/Audit/LogArchive + OU tree), "not designed for single-account deployments", ~US$400–500/month idle. Healthcare config v1.9.0-e 2025-11-29, repo pushed 2026-06-18, MIT-0; LZA Solution v1.16.2 released 9/2026, cost page US$430.22/month sample.https://github.com/aws-samples/landing-zone-accelerator-on-aws-for-healthcare (README fetched 2026-09-04); https://docs.aws.amazon.com/solutions/landing-zone-accelerator-on-aws/ ; https://docs.aws.amazon.com/solutions/latest/landing-zone-accelerator-on-aws/cost.html (2026-09-04)REPO Table A, PORT C3/C4/C-mapHigh
C2No public "empty single account → HIPAA baseline" example exists in any AWS org, Guidance or workshop. Closest: deploy-conformance-pack-for-aws-startup-security-baseline (CDK, pushed 2025-03-28, not the HIPAA pack). The 2017 HIPAA Quick Start is gone.REPO Table B; PORT B7 (Workshop Studio/Builder Center searched 2026-09-04)REPO, PORT (independent absence searches)High (absence)
C3Control Tower is the current, active landing-zone path: CfCT pushed 2026-07-01; What's New 2026-07-16 (AFT); v4.0 "controls-dedicated experience" 2025-11-21 lets you use 750+ managed controls in an existing Organization without a full landing zone; LZA Solution released 9/2026. An Organization is still required for any of it.https://github.com/aws-solutions/aws-control-tower-customizations ; https://aws.amazon.com/about-aws/whats-new/2026/07/aws-control-tower-account/ ; https://aws.amazon.com/about-aws/whats-new/2025/11/aws-control-tower-controls-dedicated-experience/REPO, COMP 4.6, PORT C3High
C4The Config conformance pack is still named "Operational Best Practices for HIPAA Security"; template last commit 2025-01-07 (130-rule cap); validated by AWS SAS; disclaimer "not designed to fully ensure compliance".https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-hipaa_security.html ; https://github.com/awslabs/aws-config-rules/commits/master/aws-config-conformance-packs/Operational-Best-Practices-for-HIPAA-Security.yamlREPO, COMP 4.1High
C5Security Hub split in Oct–Dec 2025: standards live in AWS Security Hub CSPM (FSBP, AI Security Best Practices, CIS v5, NIST 800-53 r5, NIST 800-171 r2, PCI DSS, Resource Tagging, Control Tower service-managed); the new "AWS Security Hub" (GA 2025-12-02, OCSF risk analytics) is not on the HIPAA list under its own name; there is no HIPAA-named standard.https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.html ; https://aws.amazon.com/about-aws/whats-new/2025/12/security-hub-near-real-time-risk-analytics/COMP 4.2/4.3 onlyHigh (Primary)
C6Macie has 12 PHI managed data identifiers, all keyword-dependent, and none is in the recommended set (2023-06-27) or the automated-discovery default set (2023-08-02) — F0/U4/U5 must select them explicitly.https://docs.aws.amazon.com/macie/latest/user/mdis-reference.html ; https://docs.aws.amazon.com/macie/latest/user/discovery-asdd-settings-defaults.htmlCOMP 4.4/4.5 onlyHigh
C7BAA is self-service in AWS Artifact at account scope or, from the management account of an all-features Organization, at organization scope covering all existing and future member accounts. No catalog service needs an extra HIPAA opt-in.https://docs.aws.amazon.com/artifact/latest/ug/accept-org-agreement.html ; https://aws.amazon.com/compliance/hipaa-compliance/COMP 1.1–1.5 onlyHigh (Medium for "no other opt-in")
C8New constraint absent from catalog-v0: Bedrock and Security Hub CSPM compliance pages warn "Our new AWS sign-up experience is not designed for regulated workloads … sign up for AWS (advanced) or activate advanced features." An F0 "empty account" runbook must start from an advanced-features account.https://docs.aws.amazon.com/bedrock/latest/userguide/compliance-validation.html ; https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-compliance.htmlCOMP 1.5 onlyHigh (text)
C9AWS's older HIPAA framing documents are stale: the "Architecting for HIPAA" whitepaper is archived (points to the eligible-services page); the Healthcare Industry Lens is dated 2022-11-17 with no revisions. Current AWS-official narrative is the eligible-services page plus 2026 blogs (C71).https://docs.aws.amazon.com/whitepapers/latest/architecting-hipaa-security-and-compliance-on-aws/document-revisions.html ; https://docs.aws.amazon.com/wellarchitected/latest/healthcare-industry-lens/document-revisions.htmlCOMP 1.6, PORT C7High
C10aws-samples/aws-security-reference-architecture-examples (pushed 2026-09-04) is CC-BY-SA-4.0 — link, do not fork (brief OQ5).LICENSE fetched 2026-09-04REPO onlyHigh
C11Every named catalog service is on the HIPAA Eligible Services Reference (page "Last Updated: September 3, 2026"), including Bedrock, Bedrock AgentCore, Connect Health, Quick, Kiro, IoT Core, Greengrass, Kinesis, Firehose, Managed Flink, Athena, Glue, Lake Formation, SageMaker AI, Amplify Console, AppSync, API Gateway, SNS, SES, "Amazon Pinpoint and End User Messaging", ECS/Fargate, Aurora, DynamoDB, ElastiCache, Cognito, CloudFront, WAF/Shield, Macie, Config, GuardDuty, Control Tower. Not named (covered only by the "GA features of listed services are eligible" rule): S3 Tables, Timestream for InfluxDB, Valkey engine, Bedrock Knowledge Bases / Guardrails / Data Automation (KB and Guardrails are named as eligible in the AWS industries blog 2025-10-13).https://aws.amazon.com/compliance/hipaa-eligible-services-reference/ ; https://aws.amazon.com/blogs/industries/hipaa-compliance-for-generative-ai-solutions-on-aws/ (2025-10-13)COMP §2 (Primary); REPO independently cites Connect Health "HIPAA-eligible" from the 2026-03-05 What's NewHigh for listed; Medium (KB/Guardrails), Medium-Low (S3 Tables, InfluxDB, BDA)
C12Presence on the eligibility list is not a lifecycle signal: Forecast, Kendra, Q Business, IoT Events and A2I are still listed. Catalog rule 4 stands.Same pageCOMP onlyHigh

U1 — Patient portal + companion mobile app

#ClaimSources (dated)Corroborated byConfidence
C13No AWS-official U1 Tier 1 exists (portal + native iOS/Android + Cognito + HealthLake). No aws-samples repo, no Guidance, no workshop, and no first-party Amplify native-mobile healthcare sample of any kind.REPO Table B; PORT B7; MOB A12REPO, PORT, MOB (three independent absence searches)High (absence)
C14Closest U1 T1 components: aws-healthlake-smart-on-fhir (CDK TS, 2024-03-16, no UI/Cognito); sample-intelligent-security-for-healthcare-apis (CloudFormation, 2026-08-14, Cognito MFA + Comprehend Medical redaction + Bedrock Guardrail, empty→running in 10–15 min); "SMART on FHIR with AWS HealthLake" workshop (content unreadable).https://github.com/aws-samples/aws-healthlake-smart-on-fhir ; https://github.com/aws-samples/sample-intelligent-security-for-healthcare-apis ; https://catalog.us-east-1.prod.workshops.aws/workshops/542c1a0f-7bd2-4f2f-8da9-699e953c7b26REPO, PORT B3Medium
C15Amplify Gen 2 (GA 2024-05-06) is the only supported path; Gen 1 in maintenance from 2026-05-01, EOL 2027-05-01. All four clients actively released (Swift 2.60.2 2026-09-01; Android 2.41.1 2026-09-02; Flutter 2.15.0 2026-08-19; JS 2026-09-01).https://github.com/aws-amplify/amplify-cli/issues/14881 (2026-05-14); release feeds 2026-09-04MOB A1–A6 only; consistent with REPO's finding that aws-healthscribe-demo (2025-04-08) is Gen 1High
C16Parity: Swift and Android have passkeys/passwordless and AppSync Events clients; Flutter has neither (issues #6094, #6106 open; WebAuthn PR #6851 unmerged draft since 2026-04-08); React Native follows JS (Expo Go unsupported). Gen 2 dropped Analytics/Push/Predictions as first-class categories.https://github.com/aws-amplify/amplify-flutter ; https://docs.amplify.aws/swift/start/migrate-to-gen2/feature-matrix/MOB A7–A9 onlyHigh
C17The classic AWS Mobile SDKs (aws-sdk-ios, aws-sdk-android) reached end of support 2026-08-01; the IoT Core "Mobile SDKs" docs page still lists them (stale).READMEs of https://github.com/aws-amplify/aws-sdk-ios and …/aws-sdk-android ; https://docs.aws.amazon.com/iot/latest/developerguide/iot-sdks.htmlMOB A10 only; bears on X6High
C18API layer: no AWS document recommends AppSync over API Gateway (or vice versa) for a mobile+web app over a container backend. Documented split: Amplify Data (AppSync GraphQL) when Amplify owns the model; API Gateway REST/HTTP to proxy an existing backend; AppSync Events for real-time. AppSync, API Gateway and their features are all HIPAA-listed.https://docs.aws.amazon.com/prescriptive-guidance/latest/modernization-integrating-microservices/appsync-api-gateway.html ; https://docs.amplify.aws/react/build-a-backend/add-aws-services/rest-api/ ; COMP §2MOB B1–B6 + COMP (eligibility)Medium (synthesis)
C19Cognito mobile: Managed Login (2024-11-22); passkeys/OTP passwordless on Essentials (default for new pools); refresh-token rotation 2025-04-22; self-service provisioned limits 2026-07. Design constraint: OTP-first-factor is incompatible with required MFA; a passkey satisfies MFA only with user verification required; passkeys cannot be a second factor to password. Mobile passkeys need a .well-known association file.https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-authentication-flow-methods.html ; https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-sign-in-feature-plans.htmlMOB C1–C8 onlyHigh
C20Amazon Pinpoint end of support 2026-10-30; no new customers since 2025-05-20. Closes catalog rule 4's VERIFY: Pinpoint goes on the retired list. serverless-patient-engagement-stack (2025-04-01) depends on it and cannot be linked as-is.https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html ; https://aws.amazon.com/pinpoint/faqs/MOB D1 (Primary); REPO (flags the dependent repo); COMP (list entry "Amazon Pinpoint and End User Messaging")High
C21AWS-named successors: push/SMS/voice/OTP → AWS End User Messaging (push still uses the Pinpoint send-messages API with an application ID; migration guide states these APIs "are not impacted by this change and are supported by AWS End User Messaging"); email → SES; engagement (segments/campaigns/journeys) → Amazon Connect Customer outbound campaigns + Customer Profiles; events/analytics → Kinesis; In-App Messaging has no successor; push is not native in Connect campaigns. SNS mobile push is documented, undeprecated and valid, but is not the named successor.Migration guide (above, re-fetched by comparator 2026-09-04); https://docs.aws.amazon.com/push-notifications/latest/userguide/reference-send-message.html ; https://docs.aws.amazon.com/sns/latest/dg/sns-mobile-application-as-subscriber.htmlMOB D2–D6 + comparator check (X2)High
C22U1 Tier 2 (patient-facing assistant over the patient's own FHIR data via AgentCore Gateway tools): no example. Scaffolding exists: HCLS Agents Toolkit (amazon-bedrock-agents-healthcare-lifesciences, AgentCore + Strands despite the name, pushed 2026-09-03, 268 stars, MIT-0, life-science skew, no provider/patient agents); sample-healthcare-agent-with-agentcore-on-aws (2026-08-03, agent calls a SageMaker endpoint — the Tier 2→3 bridge); AWS blueprint blog "Architecting HIPAA-compliant AI agents" (2026-08-14: KMS-encrypted AgentCore Memory, Cedar on Gateway, Macie/Comprehend pre-ingestion scans, Object Lock logs).https://github.com/aws-samples/amazon-bedrock-agents-healthcare-lifesciences ; https://aws.amazon.com/blogs/publicsector/architecting-hipaa-compliant-ai-agents-to-safeguard-health-data-with-aws/REPO, PORT B5, COMP 5.3.5High
C23U1 Tier 3 (no-show / adherence model): nothing public; SageMaker MLOps workshops and the generic Pipelines/Registry CDK sample (amazon-sagemaker-pipeline-deploy-manage-100x-models-python-cdk, 2026-07-28) supply mechanics only.REPO Table B; PORT GREPO, PORTHigh (absence)
C24HealthLake: GA, actively shipping (2026-03 CCDA→FHIR agent preview, 2026-05 CMS-0057-F, 2026-07 resource matching preview); us-east-1 and us-west-2; US$0.27 per data-store-hour (~US$197/month per store) is the dominant running-demo cost — relevant because most U3/U4/U5 samples require a HealthLake datastore.https://aws.amazon.com/healthlake/pricing/ ; https://aws.amazon.com/healthlake/faqs/COMP §3 (Primary); REPO (many samples list HealthLake as prerequisite)High lifecycle / Medium price
C25Amazon Location Service is active (seven 2026 What's New posts, Mar–Aug); Device Farm active (last What's New 2025-11-21) but us-west-2 only — no PHI in test data.https://docs.aws.amazon.com/general/latest/gr/devicefarm.html ; MOB E1–E3MOB onlyHigh

U2 — Remote patient monitoring at scale

#ClaimSources (dated)Corroborated byConfidence
C26No end-to-end RPM example (devices → IoT Core → Kinesis → Flink → InfluxDB/Iceberg → alerts → app) exists in any AWS org, Guidance or workshop, and AWS publishes no guidance at all for HealthKit or Health Connect ingestion. REPO ranks U2 "second-highest" demonstration value after U1; PORT ranks it "highest" — a ranking difference, not a factual one.REPO Table B; PORT B7; MOB F3REPO, PORT, MOBHigh (absence)
C27Components that exist (all MIT-0 unless noted): guidance-for-aws-iot-greengrass-foundations (CDK v2, 2026-07-23); aws-greengrass-ec2-device-farm (CDK v2, 2026-08-30, Apache-2.0, simulated fleet); flink-keyed-random-cut-forest-example (2025-12-19, per-key RCF in Flink state, no IaC); amazon-sagemaker-deepar-mlops-pipeline-cdk (2025-04-10); transactional-datalake-using-amazon-datafirehose-iceberg (Firehose→Iceberg, CDC source); aws-appsync-iot-core-realtime-dashboard (Amplify Gen 2, npx ampx sandbox, pushed 2026-09-03, 126 stars — comparator check, X7) for the portal-side real-time view.REPO U2 table; MOB F13; comparator checkREPO, MOBHigh
C28The catalog's hot path has two independent weaknesses that converge: no IoT Core → Timestream for InfluxDB sample with IaC (REPO) and InfluxDB is not on the HIPAA list by name (COMP; FAQ compliance sentence sits under LiveAnalytics only).REPO gaps; COMP §2 row + gap 3REPO, COMPHigh (no sample) / Medium-Low (eligibility)
C29Phone → IoT Core path AWS documents: Cognito identity pool + IAM role plus an IoT policy attached to the Cognito identity; MQTT over WebSocket/SigV4. iOS: AWS IoT Device SDK for Swift GA 2026-06-01 (iOS 16+, MQTT5, Shadow/Jobs/Fleet Provisioning, Apache-2.0). Android: IoT Device SDK for Java v2 (API 24+). Amplify Swift and Android have no PubSub category; Amplify PubSub is JS/RN only. No AWS guidance for X.509 per phone.https://docs.aws.amazon.com/iot/latest/developerguide/cognito-identities.html ; https://aws.amazon.com/about-aws/whats-new/2026/06/aws-iot-device-sdk-swift/ ; https://github.com/aws/aws-iot-device-sdk-java-v2/blob/main/documents/ANDROID.mdMOB F4–F9 only; REPO independently lists the SDK page and aws-sdk-ios-samples IoT-Sample/SwiftHigh
C30HealthKit and Health Connect are on-device stores only (no cloud API); Apple guideline 5.1.3 forbids storing personal health information in iCloud; Health Connect has background reads and a changes/sync API. Only AWS-adjacent code: cleverdevil/healthlake (community, archived 2022, no license).https://developer.apple.com/app-store/review/guidelines/ §5.1.3 ; https://developer.android.com/health-and-fitness/guides/health-connect ; https://github.com/cleverdevil/healthlakeMOB F1–F3, REPOHigh
C31The only AWS sample of a phone as BLE→IoT Core gateway is aws-amplify-cdk-iot-ble-swift-app: CDK migrated v1→v2 on 2026-06-09 (commits), but the iOS Podfile pins Amplify ~> 1.0, AWSIoT, AWSMobileClient — Amplify iOS v1 plus the classic Mobile SDK that reached EOS 2026-08-01 (C17); README still says "CDK version 1.105.0". Fork for the CDK/IoT-policy structure only; the iOS layer must be rewritten on Amplify Swift 2.x + IoT Device SDK for Swift. (Resolves X6.)https://api.github.com/repos/aws-samples/aws-amplify-cdk-iot-ble-swift-app/commits ; …/BLEX/Podfile ; README (all 2026-09-04)REPO, MOB F10 + comparator checkHigh
C32U2 Tier 2 (telemetry as typed MCP tools on AgentCore Gateway): no example; nearest are generic Gateway samples (AWS-ops tools, protein tools). Design correction: see X1 — the Bedrock Guardrails PII filter does not evaluate tool inputs/results.REPO U2 table; COMP 5.3.3REPO, COMPHigh
C33U2 Tier 3 edge scoring: SageMaker Edge Manager EOL 2024-04-26 (AWS recommends Greengrass v2 + ONNX); greengrass-v2-sagemaker-edge-manager-python and amazon-sagemaker-aws-greengrass-custom-timeseries-forecasting (IoT Analytics + Greengrass v1, archived) cannot be linked; the only current Greengrass-v2 ML Guidance is Strands SLM-at-edge (2025-10-27), an LLM not a scoring model.https://docs.aws.amazon.com/sagemaker/latest/dg/edge-eol.html ; https://github.com/aws-solutions-library-samples/guidance-for-deploying-ai-agents-to-device-fleets-using-aws-iot-greengrassREPO onlyHigh
C34Flink→SageMaker real-time endpoint pattern exists generically (amazon-sagemaker-feature-store-streaming-inference-msk-kda, 2024-01-04, fraud domain, pre-rename naming). Greengrass is HIPAA-listed without a version qualifier.REPO U2 table; COMP §2REPO, COMPMedium

U3 — Ambient clinical documentation

#ClaimSources (dated)Corroborated byConfidence
C35HealthScribe: GA 2023-11-27, active (2025-02 GIRPP template), HIPAA-eligible under the list entry "AWS Transcribe [Includes Healthscribe]", us-east-1 only (fails brief OQ3's us-west-2 default), US$0.10/min, en-US. Developer guide now carries a banner steering to Connect Health Ambient. REPO's sup-hcls-generate-clinical-notes-with-ai (2024-07-23) ships a Transcribe+Bedrock fallback "for regions without HealthScribe" — the constraint is old enough that AWS samples work around it.https://docs.aws.amazon.com/transcribe/latest/dg/health-scribe.html ; https://aws.amazon.com/healthscribe/pricing/COMP §3 (Primary), REPO (fallback sample)High
C36Transcribe Medical (last What's New 2021-01) and Comprehend Medical (last What's New 2020-07) are quiet, not retired: docs live, no end-of-support notice. Sample activity stopped too: medical-transcription-analysis 2023-07-18; amazon-comprehend-medical-fhir-integration archived 2024-01-22. Newer surfaces for the same jobs: HealthScribe/Connect Health (notes, coding preview) and HealthLake integrated NLP.COMP §3; REPO U3 tableCOMP, REPOHigh
C37Amazon Connect Health GA 2026-03-05, HIPAA-eligible, us-east-1 + us-west-2; GA features: patient verification, ambient documentation; preview: appointment management, patient insights, medical coding. Both scouts cite the same What's New; the AI dossier's 2026-04-28 date is the Connect rename post (X9). PORT did not surface Connect Health at all.https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/REPO, COMPHigh
C38sample-amazon-connect-health-unified-clinical-workflow (pushed 2026-08-31, CloudFormation ×3, MIT-0) is the most complete U3 artefact (capture → SOAP → coding → HealthLake DocumentReference, review in Agent Workspace) but: (a) comparator check confirms its care-manager workspace uses Bedrock Agents classic with 6 action groups — on catalog rule 4's retired list; (b) it requires a registered Amazon Connect instance and Connect Health domain (semi deploy, not empty→running); (c) medical coding is gated preview. The sibling sample-amazon-connect-health-point-of-care (2026-03-31) has the same Connect prerequisites; its Bedrock use is a pre-visit narrative, not agents (not re-checked).README fetched 2026-09-04: https://github.com/aws-samples/sample-amazon-connect-health-unified-clinical-workflowREPO + comparator check (X3)High
C39sample-healthscribe-bedrock-clinical-analysis (pushed 2026-04-07, CDK, ECS Fargate, React+Vite, Cognito, CloudFront, HealthScribe streaming + Bedrock "12 specialist agents", empty→running via deploy.sh, needs an ACM cert) is the best stack-spine match for U3; no HealthLake write-back or Comprehend Medical coding step documented.https://github.com/aws-samples/sample-healthscribe-bedrock-clinical-analysisREPO onlyHigh
C40Guidance "Identifying Diagnosis Codes from Clinical Notes on AWS" (guidance-for-identifying-diagnosis-codes-from-clinical-notes-on-aws: CDK Python, MIT-0, not archived, pushed 2026-04-13, 4 stars — comparator check) covers HealthScribe → S3 → Comprehend Medical ICD-10-CM → Bedrock Converse + OpenSearch Serverless KB → Lake Formation/Athena/QuickSight; README cost table US$495.89/month (April 2025) dominated by OpenSearch Serverless (US$350). No clinician review UI, Step Functions, or HealthLake write-back. REPO did not find this Guidance.https://docs.aws.amazon.com/solutions/identifying-diagnosis-codes-from-clinical-notes-on-aws/ ; https://api.github.com/repos/aws-solutions-library-samples/guidance-for-identifying-diagnosis-codes-from-clinical-notes-on-awsPORT C-map + comparator check (X4)High
C41aws-healthscribe-demo (2025-04-08, 60 stars) is Amplify Gen 1 (aws-amplify ^6.14, no @aws-amplify/backend) with a CodeCommit-based deploy doc; UI patterns worth borrowing, deploy path stale. MOB lists it as one of only two web-only Amplify healthcare samples.package.json and docs/deploy.md fetched 2026-09-04REPO, MOB A12High
C42U3 Tier 3 (note-quality / coding classifier on SageMaker): none; only LLM-as-judge and clinical-report evaluation notebooks (healthcare-LLM-as-a-Judge, eval-genai-techniques-clinicalreport 2024-04-15).REPO U3 table; PORT GREPO, PORTHigh (absence)
C43Comprehend Medical DetectPHI detects but does not redact and per AWS "does not meet the requirements for de-identification" — human review or additional methods required; Transcribe (Medical) PHI identification is free in all Transcribe regions.https://docs.aws.amazon.com/comprehend-medical/latest/dev/textanalysis-phi.html ; https://aws.amazon.com/comprehend/medical/faqs/COMP 5.3.1/5.3.2 onlyHigh

U4 — Intelligent document intake

#ClaimSources (dated)Corroborated byConfidence
C44GenAI IDP Accelerator (aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws, pushed 2026-09-04, v0.6.6, 302 stars, MIT-0): one-click CloudFormation/SAM (us-east-1, us-west-2, eu-central-1) with CDK/Terraform alternates; Pattern 1 = Bedrock Data Automation end-to-end, Pattern 2 = Textract OCR → Bedrock; built-in human review (not A2I); MLflow evaluation; Cognito+WAF web UI; MCP via AgentCore Gateway. Full generic U4 T1+T2; no Comprehend Medical / HealthLake / Macie.https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-awsREPO only (PORT did not surface it)High
C45Guidance for Intelligent Document Processing on AWS (docs page) is now AgentCore Runtime/Identity/Gateway + Strands multi-agent + Textract + ECS dashboard; its Security pillar text points to Comprehend Medical PHI redaction; sample aws-ai-intelligent-document-processing pushed 2026-05-04, 244 stars. REPO did not verify the repo contents match the page.https://docs.aws.amazon.com/solutions/intelligent-document-processing-on-aws/ ; https://github.com/aws-samples/aws-ai-intelligent-document-processingREPO, PORT C-mapHigh (page) / Medium (repo)
C46sample-healthcare-agents (pushed 2026-09-03, CDK TS, Amplify-hosted React + Cognito, AgentCore Runtime + Gateway, Strands, HealthLake FHIR R4, Comprehend Medical, B2B Data Interchange EDI 837P, CDS Hooks; cdk deploy --all) is full for U4 Tier 2 (prior-auth packet, eligibility, coding, claims, appeals); no PDF intake.https://github.com/aws-samples/sample-healthcare-agentsREPO onlyHigh
C47Textract vs BDA (brief sub-question): in AWS's own code both are first-class and BDA is the default pattern (C44); Textract is on the HIPAA list by name, BDA only via the general-feature rule (Medium); two official workshops exist, one per path ("Intelligent Document Processing with AWS AI Services", "Document Processing with Amazon Bedrock Data Automation"). Consequence: BDA is the 2026 default, but the portal must state its eligibility rests on the feature rule.REPO U4 table; COMP §2; PORT B6REPO, COMP, PORTHigh (default) / Medium (BDA eligibility)
C48sample-scalable-intelligent-document-processing-with-amazon-bedrock-data-automation (2026-07-28) uses A2I + Ground Truth (retired list) → cannot link; superseded by C44. amazon-textract-idp-cdk-constructs stale (2024-04-29).REPO U4 tableREPO onlyHigh
C49De-identification: aws-ai-phi-deidentification (2025-04-23, CDK single command, Textract → Comprehend Medical → redaction UI) is the only deployable de-id pipeline; Bedrock-based PHI detection in DICOM/PDF is a practitioner pattern (Clario, 2026-08-19, F1 0.975–0.995, human-in-the-loop). Combined with C43: automated de-id is an assist, not a Safe Harbor guarantee.https://github.com/aws-samples/aws-ai-phi-deidentification ; https://aws.amazon.com/blogs/architecture/how-clario-automates-phi-pii-detection-in-dicom-images-using-amazon-bedrock/REPO, COMP 5.3.7/5.3.8High (repo) / Medium (Bedrock pattern)
C50U4 Tier 3 (document-type classifier / denial-risk on SageMaker): none; the Accelerator classifies with Bedrock.REPO Table B; PORT GREPO, PORTHigh (absence)
C51U4 is the best-covered catalog item and has the lowest new-build value (Tier 1–2).REPO summary/notes; PORT GREPO, PORTHigh
C52"Guidance for Ingesting PDF and Image Files to AWS HealthLake" is architecture-only (no sample-code link); the "Intelligent Healthcare Systems: FHIR, AI, and AWS HealthLake" workshop (CMS-1500 / SOAP notes → FHIR) is the nearest healthcare IDP tutorial (module list unreadable, G1).https://aws.amazon.com/solutions/guidance/ingesting-pdf-and-image-files-to-aws-healthlake/ ; https://catalog.us-east-1.prod.workshops.aws/workshops/da0cf4f5-63d4-4e4b-bf98-6a48b748d914/en-USREPO, PORT B2Medium

U5 — Population health analytics and risk models

#ClaimSources (dated)Corroborated byConfidence
C53"Guidance for Multi-Modal Data Analysis with AWS Health and ML Services" (guidance-for-multi-modal-data-analysis-…, pushed 2024-12-17, MIT-0; one-click CloudFormation SageMaker domain + sequential notebooks; HealthOmics/HealthLake/HealthImaging → Lake Formation → Athena → QuickSight; Feature Store → AutoGluon → real-time endpoint; Synthea) is the closest U5 T1+T3 artefact — but notebook-driven, QuickSight-era, no S3 Tables/Iceberg, no de-identification, README has no cost table.https://docs.aws.amazon.com/solutions/multi-modal-data-analysis-with-aws-health-and-ml-services/ ; https://github.com/aws-solutions-library-samples/guidance-for-multi-modal-data-analysis-with-aws-health-and-ml-servicesREPO, PORT C-mapHigh
C54Patient Entity Resolution Guidance (2025-09-11) + "Patient Matching with AWS Entity Resolution" workshop = one U5 T1 component (EMPI).https://github.com/aws-solutions-library-samples/guidance-for-patient-entity-resolution-with-aws-healthlakeREPO, PORTHigh
C55S3 Tables is not on the HIPAA list by name (re:Post thread unresolved, 403 to fetch) and no healthcare sample lands data in S3 Tables; the Iceberg landing exists only as a CDC sample (C27). Converging gap on the catalog's U5/U2 cold path (see G2).COMP §2 + gap 3; REPOCOMP, REPOMedium-Low (eligibility) / High (no sample)
C56Amazon Quick is HIPAA-listed, but every U5 sample, Guidance page and workshop still says QuickSight — any fork needs a rename pass and re-validation of the BI step. healthlake-workshop repo is archived (pushed 2026-01-29; archived 2026-02-04).COMP §2; REPO; PORT B1COMP, REPO, PORTHigh
C57U5 Tier 3 healthcare models: all readmission/outcome samples are 2021–2022 (aws-ml-readmission-prediction 2022-04-18; amazon-healthlake-patient-outcome-prediction archived 2022-09-06; Data Wrangler 2021-10-25); newest healthcare ML samples are Clean Rooms ML ADR prediction (2026-05/07), outside the spine; generic MLOps CDK spine is current (2026-07-28). PORT's "Fork the Multi-Modal Guidance for T3" and REPO's "stale only → build" differ (X5).REPO U5 table + Table B; PORT GREPO, PORT (disagree on verdict)High (facts)
C58U5 Tier 2 (NL analytics over the lake): only extract-medical-insights-from-amazon-healthlake-with-bedrock (2024-11-05, Apache-2.0, Streamlit, no IaC, text-to-SQL) — a snippet, predates Quick.https://github.com/aws-samples/extract-medical-insights-from-amazon-healthlake-with-bedrockREPO, PORT D5High
C59Clarify successor for bias (catalog-v0 U5 T3 VERIFY): no scout answered it (see G5).

U6 — Contact center with AI agents (optional)

#ClaimSources (dated)Corroborated byConfidence
C60Connect Health makes U6 Tier 1's identity verification and (preview) scheduling first-party product features rather than Lex + Lambda code; sample-healthcare-realtime-eligibility (2026-03-03) plugs eligibility into it. PORT, unaware of Connect Health, recommended linking only the generic "Getting started with Amazon Connect" workshop.https://aws.amazon.com/products/connect/health/ ; https://github.com/aws-samples/sample-healthcare-realtime-eligibilityREPO, COMP (product); PORT disagrees on link target (X3)High
C61Amazon Connect (renamed Connect Customer 2026-04-28 per dossier) and Lex are HIPAA-listed.COMP §2COMP onlyHigh
C62sample-amazon-connect-bedrock-agent-voice-integration (2025-11-18, CDK TS) uses Bedrock Agents classic action groups → cannot link; Connect+Lex+CDK structure reusable. voice-enabled-patient-diary (2024-08-27) Lex version unverified.REPO U6 tableREPO onlyHigh
C63sample-Nova-Sonic-AgentCore-Healthcare-Call-Center (2026-05-21, CDK Python, MIT not MIT-0, AgentCore + Nova 2 Sonic, no Amazon Connect) is the modern-agent-stack U6 T2 sample, empty→running.https://github.com/aws-samples/sample-Nova-Sonic-AgentCore-Healthcare-Call-CenterREPO onlyHigh
C64No healthcare-specific Connect workshop or Guidance exists; U6 T3 demand forecasting is a Connect product feature ("forecasting, capacity planning, and scheduling" workshop), not a SageMaker build.REPO U6 table; PORT B7/GREPO, PORTHigh
C65Pinpoint's engagement successor is Connect Customer outbound campaigns + Customer Profiles (C21), so U1 reminders/journeys and U6 share a service — serverless-patient-engagement-stack (Pinpoint + Connect) maps naturally onto it after replacing Pinpoint.MOB D2; REPO U1 tableMOB, REPOMedium (inference)

P0 — Education portal

#ClaimSources (dated)Corroborated byConfidence
C66Workshop Studio content = git repo with contentspec.yaml (v2.0: accountSources: [WorkshopStudio, CustomerProvided], participant IAM policy, region config, cloudformationTemplates[]), content/, static/, optional infrastructure/ (CDK synthesised into static/). Two provisioning modes (event account via access code; own account). Discovery moved to Builder Center 2025-11-18; workshops.aws/categories/* 301s there.https://github.com/aws-samples/rancher-on-aws-workshop/blob/main/contentspec.yaml ; https://github.com/aws-samples/sample-agent-jailbreak-to-cloud-takeover ; https://aws.amazon.com/about-aws/whats-new/2025/11/workshops-available-aws-builder-centerPORT A1–A7 (Primary); REPO (What's New + redirect observed)High
C67Every Workshop Studio and Builder Center page is client-rendered and unreadable by the fetch tool; all workshop coverage judgements (B1–B6; the HealthLake, SMART-on-FHIR, Intelligent Healthcare Systems, Patient Matching, HCLS Agents workshops) rest on titles, AWS descriptions and backing repos.REPO gaps; PORT method caveat + gapsREPO, PORTHigh (that it is a gap — G1)
C68Solutions Library pages moved to docs.aws.amazon.com/solutions/<slug>/ (301 from aws.amazon.com/solutions/guidance/…). Guidance page anatomy: overview → architecture PNG/PDF + numbered steps → "Go to sample code" → six Well-Architected pillar paragraphs → related content → usage disclaimer; cost table and deploy steps live in the repo README, not the page. Solution header (version, released, deploy time, estimated cost) is the best "is it maintained?" signal. Guidance code is "not for production accounts" — forked chapters must carry that disclaimer.https://docs.aws.amazon.com/solutions/guidance-disclaimers/ ; PORT C1–C5PORT (Primary); REPO independently cites the docs-domain URLsHigh
C69aws-samples conventions: MIT-0 default; README tail ## Security / ## License; Guidance README contract Overview → Cost → Prerequisites → Deployment → Validation → Running → Next Steps → Cleanup (adherence varies; no public template repo found); serverless-patterns' example-pattern.json is the smallest proven docs-from-metadata contract.https://github.com/aws-samples/serverless-patterns ; https://github.com/aws/mit-0PORT D1–D7 only; REPO's license census (MIT-0 default, Apache-2.0 minority, one MIT, one CC-BY-SA, one unlicensed) is consistentHigh
C70AWS's own examples of a portal generated from repos: the HCLS Agents Toolkit GitHub-Pages site (Astro, agent catalog, developer guide) and eks-workshop-v2 (Docusaurus + Terraform, off Workshop Studio). No public "education portal" repo for this purpose exists — P0 is build-new. Recommended pattern: repo-owned README (Guidance contract) + MADR 4 ADRs in docs/decisions/ + contentspec.yaml per use case, aggregated at build time (Backstage TechDocs / Antora model).https://aws-samples.github.io/amazon-bedrock-agents-healthcare-lifesciences/ ; https://github.com/aws-samples/eks-workshop-v2 ; https://adr.github.io/madr/ ; https://backstage.io/docs/features/techdocs/REPO, PORTHigh
C71Comparators: Serverless Land (one machine-generated contract, thousands of two-service patterns); Google Jump Start Solutions (cost estimate before deploy, delete after; now behind console sign-in); Azure Architecture Center (dated, git-backed, pillar structure, no deploy button). Health AI Hub and healthcare.awsaccelerators.com demos are partner/demo showcases without deploy links.PORT F1–F5; REPO P0 tablePORT, REPOHigh

Cross-cutting (compliance evidence, Tier 2 design, regions, licences)

#ClaimSources (dated)Corroborated byConfidence
C72Dossier item F-15 closes as confirmed: Bedrock FAQ and security page state content is not used to improve base models and not shared with providers (per-region model deployment accounts); compliance list = HIPAA eligible, SOC 1/2/3, ISO 9001/27001/27017/27018/27701/22301/20000, CSA STAR L2, GDPR, FedRAMP Moderate (commercial), FedRAMP High (GovCloud US-West). IL4/IL5 not seen (stays Medium).https://aws.amazon.com/bedrock/faqs/ ; https://aws.amazon.com/bedrock/security-compliance/ ; https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.htmlCOMP 5.1 onlyHigh
C73Bedrock retention is a per-account/per-project mode (none < default < aws_review < legacy provider_data_share). Claude Fable 5 / 5.1 require aws_review (all prompts/completions retained within AWS up to 30 days; classifier-flagged traffic may be human-reviewed by AWS); Opus 4.8 allows none; Enterprise Frontier Safeguards customers get ZDR through 2026-12-31. Enforceable by SCP on bedrock:DataRetentionMode / bedrock-mantle:DataRetentionMode. Retained data lands in the cross-region destination region. Design consequence (inference): an SCP pinning none on PHI accounts makes Fable 5.1 unavailable there by construction; route PHI prompts to ZDR-capable models or use Fable 5.1 only on de-identified inputs with the decision logged; use a US-only inference profile.https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html ; https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.htmlCOMP 5.2 only (builds on dossier §2.E.4)High (facts) / Medium (design inference)
C74Bedrock Guardrails sensitive-information filters evaluate text sent to and returned from the model only. Verbatim (comparator re-fetch 2026-09-04): "In tool use (function calling) workloads, it does not evaluate the following, so PII in these fields is neither blocked nor masked: PII the model generates into tool call arguments (toolUse.input …) … PII in tool results your application returns to the model (toolResult) … PII in the tool definitions you supply". Also: model invocation logs "always contain the original, unmodified request regardless of guardrail intervention"; the trace match field carries the raw PII; built-in health types are only CA_HEALTH_NUMBER and UK_NATIONAL_HEALTH_SERVICE_NUMBER (US MRN/Medicare/NPI need regex).https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-sensitive-filters.htmlCOMP 5.3.3 + comparator check (X1)High
C75AgentCore Gateway interceptors and Policy (AWS ML blog 2026-06-01): Policy = Cedar-based deterministic access control at the Gateway; Lambda REQUEST interceptors have full read/write access to headers and body; RESPONSE interceptors filter/modify what the agent sees after a tool responds and "can also integrate with services such as Amazon Bedrock Guardrails for use cases like personally identifiable information (PII) redaction"; work for Lambda, OpenAPI and MCP targets. This is the mechanism that makes "Guardrails at the tool boundary" achievable — via the Gateway, not the model-call guardrail. No healthcare sample of it exists.https://aws.amazon.com/blogs/machine-learning/secure-ai-agents-with-policy-and-lambda-interceptors-in-amazon-bedrock-agentcore-gateway/ (2026-06-01)Comparator check (X1); consistent with COMP 5.3.5 (Cedar on Gateway)High (Primary AWS blog)
C76Security Hub CSPM's new AI Security Best Practices standard (network isolation, encryption, VPC placement, KMS for deployed AI resources) is directly usable as Tier 2/3 compliance evidence; practical HIPAA pairing = FSBP + NIST 800-53 r5 + Config HIPAA pack.https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.htmlCOMP 4.3 onlyHigh
C77Retired-service dependents (cannot be linked as-is): serverless-patient-engagement-stack (Pinpoint), sample-amazon-connect-bedrock-agent-voice-integration (Bedrock Agents classic), sample-scalable-intelligent-document-processing-with-amazon-bedrock-data-automation (A2I/Ground Truth), greengrass-v2-sagemaker-edge-manager-python (Edge Manager), amazon-sagemaker-aws-greengrass-custom-timeseries-forecasting (IoT Analytics, Greengrass v1), sample-amazon-connect-health-unified-clinical-workflow (Bedrock Agents classic — confirmed by comparator, C38), amazon-archives/medical-mobile-iot-with-aws (Kinesis Data Analytics), the last-mile BLE Guidance (Timestream, likely LiveAnalytics — MOB F11), and aws-amplify-cdk-iot-ble-swift-app's iOS layer (EOS Mobile SDK — C31). Safe despite its name: amazon-bedrock-agents-healthcare-lifesciences (AgentCore + Strands).REPO retired table; MOB F11/F12; comparator checksREPO, MOB + comparatorHigh
C78Region constraints converge on us-east-1 as the primary demo region: HealthScribe us-east-1 only (C35); Connect Health, HealthLake, Comprehend Medical, Transcribe Medical in both defaults; Device Farm us-west-2 only (C25); Fable 5.1 retained data lands in the inference destination region (C73); IDP Accelerator one-click in us-east-1/us-west-2/eu-central-1.COMP §6; MOB E2; REPO C44COMP, MOB, REPOHigh (facts) / Medium (the "pin us-east-1" inference)
C79Licences (brief OQ5): MIT-0 default; Apache-2.0 on landing-zone-accelerator-on-aws, aws-greengrass-ec2-device-farm, extract-medical-insights-…, eks-workshop-v2, IoT Device SDK for Swift; MIT on sample-Nova-Sonic-…; CC-BY-SA-4.0 on aws-security-reference-architecture-examples and on medical-mobile-iot-with-aws docs; no licence on cleverdevil/healthlake and one Clean Rooms sibling. All permissive except the CC-BY-SA and unlicensed ones.REPO notes; PORT D1; MOB F12REPO, PORT, MOBHigh

2. Agreements (multi-angle corroboration, strongest dossier claims)

#AgreementClaimsAngles
A1F0 must be split: LZA/Control Tower is the authoritative organisation layer (link), and a single-account HIPAA baseline has no public example (build). Control Tower is current.C1, C2, C3REPO, COMP, PORT
A2U1 Tier 1 (portal + native mobile) has no AWS-official example on any current stack; it is the highest-value new build.C13, C14, C15REPO, PORT, MOB
A3U2 has no end-to-end example, no HealthKit/Health Connect guidance, and no current phone→IoT Core sample; every U2 tier is new work.C26, C28, C30, C31, C32, C33REPO, PORT, MOB
A4Pinpoint is retired (EOS 2026-10-30) and belongs on rule 4's list; End User Messaging is the named push successor; SNS mobile push is a supported alternative.C20, C21MOB, REPO, COMP + comparator
A5Amazon Connect Health (GA 2026-03-05, HIPAA-eligible, both default regions) reshapes U3 (ambient documentation as a product) and U6 (patient verification as a product).C37, C38, C60REPO, COMP
A6Transcribe Medical and Comprehend Medical are quiet-not-retired; HealthScribe/Connect Health and HealthLake NLP are AWS's newer surfaces for the same jobs; HealthScribe is us-east-1 only.C35, C36COMP, REPO
A7U4 is the best-covered item (IDP Accelerator, IDP Guidance on AgentCore, sample-healthcare-agents); BDA is the 2026 default with Textract retained for OCR-first; BDA's eligibility rests on the feature rule.C44–C47, C51REPO, COMP, PORT
A8Automated de-identification (Comprehend Medical DetectPHI, the de-id sample, Bedrock detectors) assists but does not satisfy Safe Harbor on its own; human review is part of the demo.C43, C49COMP, REPO
A9U5's closest artefact is the 2024-12 Multi-Modal Guidance; S3 Tables, Quick and de-identification are all new work on top of it; U5 T2 has only a snippet.C53–C56, C58REPO, PORT, COMP
A10All Tier 3 healthcare-specific models (U1 no-show, U3 note quality, U4 denial risk, U5 risk newer than 2022) are absent publicly; the generic SageMaker Pipelines/Registry CDK spine is current.C23, C42, C50, C57REPO, PORT
A11P0 is build-new; AWS's three content surfaces (Workshop Studio, Solutions Library, aws-samples) have stable, copyable contracts; the repo-generated docs site (HCLS toolkit, eks-workshop-v2) is the pattern.C66, C68–C71PORT, REPO
A12Workshop Studio module content is unreadable to all scouts; every "link this workshop" judgement is provisional.C67REPO, PORT
A13The retired-service list is longer than catalog-v0's: add Pinpoint, SageMaker Edge Manager, Kinesis Data Analytics naming, the classic AWS Mobile SDKs (EOS 2026-08-01), Amplify Gen 1 (maintenance). Several otherwise-attractive repos are blocked by it.C17, C20, C33, C77REPO, MOB, COMP
A14Every catalog-named service is HIPAA-listed by name except S3 Tables, Timestream for InfluxDB, Valkey engine and Bedrock sub-features; Connect Health's eligibility is corroborated by two angles.C11, C37COMP, REPO
A15us-east-1 is the only region where every catalog service and sample works; us-west-2 fails on HealthScribe.C35, C78COMP, MOB, REPO

3. Gaps (brief questions no scout could close)

#GapWho lookedComparator re-check
G1Workshop Studio module lists for every healthcare workshop (HealthLake, SMART on FHIR, Intelligent Healthcare Systems, Patient Matching, HCLS Agents) and the generic component workshops; the HealthScribe workshop's URL was never located. All pages are client-rendered.REPO, PORTNot re-tried (same tool). Needs a browser session before any chapter links a workshop.
G2S3 Tables HIPAA eligibility by name. Not on the list; re:Post thread unresolved.COMPre:Post still 403 on 2026-09-04; web results are third-party only. Open. Treat as feature-rule-only; confirm with the account team before PHI lands in S3 Tables, or keep the Iceberg landing de-identified.
G3Timestream for InfluxDB HIPAA eligibility by name. List says "Amazon Timestream"; FAQ compliance sentence is under LiveAnalytics.COMPTimestream developer-guide compliance page returned no readable HIPAA sentence; search summaries asserting "includes InfluxDB" are third-party synthesis, not AWS text. Open. Same handling as G2.
G4IoT Core → Timestream for InfluxDB sample with IaC — none exists (distinct from G3: even if eligible, the hot path has no public example).REPONot re-tried.
G5SageMaker Clarify successor for bias/explainability (catalog-v0 U5 T3 VERIFY). No scout addressed it.noneNot checked — outside the targeted-check remit; flag to validator/lead.
G6Comprehend Medical: DetectPHI, ICD-10-CM and RxNorm per-unit prices (page shows worked examples only); region list from a primary page (General Reference unreadable; third-party mirror used).COMPNot re-tried.
G7Whether HIPAA is among Control Catalog's "seven new compliance frameworks" (2025-06/2025-11 posts).COMPNot re-tried.
G8Amplify compliance documentation page (returned only a title); Gen 2 backend eligibility rests on the per-service list + "AWS Amplify Console". Also the Android feature-matrix ambiguity on the REST frontend category.COMP, MOBNot re-tried.
G9"Guidance for Patient Outcome Prediction on AWS" — docs URL 404; the related amazon-healthlake-patient-outcome-prediction repo was archived 2022-09-06. Two signals that it is retired, no AWS statement.PORT, REPONot re-tried.
G10Bedrock IL4/IL5 and the Anthropic third-party model terms page (not fetched); dossier sub-claim stays Medium.COMPNot re-tried.
G11An AWS-published pattern for HealthKit / Health Connect / BLE ingestion — brief question 3 asked for "the supported ways"; the answer is "generic Cognito+MQTT or REST, no AWS guidance, one stale BLE sample". The supported paths are documented; an AWS recommendation is not.MOB, REPONot re-tried.
G12Exact wording of Amplify's "Migrate from Pinpoint-backed features" page (push device registration → Connect Customer Profiles was captured by a summariser only).MOBNot re-tried.
G13Whether aws-ai-intelligent-document-processing (pushed 2026-05-04) actually contains the AgentCore/Strands architecture shown on the Guidance page.REPONot re-tried.
G14Amazon Connect Health pricing — not on the announcement or product page pointer.COMPNot re-tried.
G15The community "Apple Watch → IoT Core → Flutter dashboard" repo described by search summaries — never located; treat as non-existent.REPONot re-tried.
G16Whether sample-amazon-connect-health-point-of-care shares the unified-workflow sibling's Bedrock Agents classic dependency (REPO describes its Bedrock use as a pre-visit narrative).Not checked; only the unified-workflow README was.

4. Contradictions

Stated as found; resolved only where a targeted primary check settled it.

X1 — "Guardrails at the tool boundary" (catalog-v0 U2 Tier 2) vs Bedrock Guardrails scope

  • catalog-v0 U2 Tier 2 assumes Guardrails sit "at the tool boundary" of AgentCore Gateway MCP tools.
  • COMP 5.3.3 (Primary, High): the Guardrails sensitive-information filter "does not evaluate" toolUse.input, toolResult or tool definitions; "the tool layer must do its own masking".
  • Comparator check: (1) the doc note is confirmed verbatim (C74). (2) AWS ML blog 2026-06-01 (C75) shows AgentCore Gateway RESPONSE interceptors can "integrate with … Amazon Bedrock Guardrails for … PII redaction" and REQUEST interceptors have full read/write on the tool request body; Policy (Cedar) governs which tools may be called.
  • Resolution: Partly resolved. catalog-v0's wording is wrong as written — attaching a guardrail to the model call does not cover tool arguments or results. The intent is achievable, but via a different mechanism: Gateway interceptors that call Guardrails (ApplyGuardrail) on tool I/O, plus Cedar Policy on tool access, plus CloudWatch Logs data protection because invocation logs keep the raw prompt. What remains open: no healthcare sample of interceptor-based PHI masking exists, and whether the interceptor Lambda (which handles raw PHI) is itself an acceptable PHI processor is a risk-analysis question, not a sourcing one. catalog-v1 should rewrite U2 T2 (and every Tier 2 line that says "Guardrails") accordingly.

X2 — Pinpoint successor: SNS/EventBridge (catalog-v0) vs End User Messaging (MOB)

  • catalog-v0 U1 Tier 1: "SNS push notifications (VERIFY Pinpoint end of support; SNS/EventBridge successor)".
  • MOB D1–D4 (Primary, High): Pinpoint EOS 2026-10-30; the AWS-named successor for push/SMS/voice/OTP is AWS End User Messaging; SNS mobile push is supported but "not the successor AWS names"; Amplify's own migration banner names EUM/SES/Connect/Kinesis. EventBridge is not named by AWS as a successor for anything.
  • COMP §2: list entry is "Amazon Pinpoint and End User Messaging" (one row), consistent with EUM being the continuation.
  • Comparator check: migration guide banner verbatim: "APIs related to SMS, voice, mobile push, OTP, and phone number validate are not impacted by this change and are supported by AWS End User Messaging." What becomes inaccessible is "endpoints, segments, campaigns, journeys, and analytics".
  • Resolution: Resolved. Catalog-v0's "SNS/EventBridge successor" should read: push = EUM Push (named successor, same send-messages API) or SNS mobile push (supported, simpler for EventBridge→SNS fan-out in U2 alerts); email = SES; SMS = EUM; engagement = Connect Customer campaigns; client analytics = Kinesis. Residual caveat for build time (not a contradiction): confirm that a "Pinpoint application" resource used as the EUM push application ID is not among the resources removed on 2026-10-30 — AWS's text says push APIs are unaffected, but it does not name the application resource explicitly.

X3 — Amazon Connect Health reshaping U3/U6: REPO/COMP vs PORT, and the "near-full" U3 sample

  • REPO (Primary, High): sample-amazon-connect-health-unified-clinical-workflow is "near-full" for U3 T1+T2; Connect Health "changes the U6 build decision" — link the product rather than build Lex+Lambda identity checks.
  • COMP §3 (Primary, High): U3 T1 should prefer HealthScribe or Connect Health Ambient over Transcribe Medical + Comprehend Medical; Connect Health is HIPAA-eligible in both default regions (HealthScribe direct is us-east-1 only).
  • PORT G (Primary for what it saw): never surfaced Connect Health; recommends U3 = fork the diagnosis-codes Guidance, U6 = link the generic "Getting started with Amazon Connect" workshop, "keep as a link-only chapter unless angle 1 finds a Guidance".
  • Comparator check: the unified-workflow README states "Amazon Bedrock Agents reason over the question, call action groups (one Lambda per domain task)" and "Amazon Bedrock Agent with 6 action groups" — Bedrock Agents classic, on catalog rule 4's retired list; prerequisites include a registered Amazon Connect instance, Connect Health domain, HealthLake datastore and Bedrock access (three sequential stacks: shared, guardrail, provider).
  • Resolution: Partly resolved, and the picture is worse than REPO's "near-full". Connect Health the product is current and eligible (A5), but the best sample built on it (a) has a retired-service dependency in its Tier 2 half and (b) is not empty→running. PORT's U6 recommendation is simply incomplete (it did not see the product). What remains open and is a lead decision: whether U3 Tier 1 is built on HealthScribe direct (CDK TS sample fits the spine; us-east-1 only) or on Connect Health Ambient (both regions; requires a Connect instance, which makes every U3 deploy semi-manual and couples U3 to U6). The sources do not settle this; they only show the trade-off.

X4 — U3 fork target: REPO vs PORT name different repos, neither saw the other's

  • REPO: fork sample-healthscribe-bedrock-clinical-analysis (CDK TS, Fargate, React/Vite, Cognito, CloudFront; pushed 2026-04-07; empty→running; no HealthLake write-back, no coding step).
  • PORT: fork Guidance "Identifying Diagnosis Codes from Clinical Notes on AWS" (CDK Python; HealthScribe → Comprehend Medical ICD-10 → Bedrock + OpenSearch Serverless KB → QuickSight; README cost US$495.89/month; no review UI, no Step Functions, no write-back).
  • Comparator check: the Guidance repo is live — MIT-0, not archived, pushed 2026-04-13 — so both candidates are current and permissive.
  • Resolution: Open; not resolvable by sourcing. Both are valid fork bases with complementary gaps: the REPO candidate matches the stack spine (CDK TS) and has a clinician UI; the PORT candidate has the coding step and a Guidance page with pillars and a cost table but is CDK Python and carries a US$350/month OpenSearch Serverless line. A reasonable catalog-v1 outcome is "fork the HealthScribe CDK-TS sample for structure, port the Comprehend Medical coding step from the Guidance, build the Step Functions review + HealthLake write-back" — but that is a lead composition decision, not a finding.

X5 — U5 Tier 3: "stale only → build" (REPO Table B) vs "fork the Multi-Modal Guidance" (PORT)

  • REPO Table B: "All healthcare readmission samples are 2021–2022; generic MLOps CDK is current — stale only." (REPO's own Table A rates the same Guidance "partial→full" for T1+T3, so the scout is internally inconsistent.)
  • PORT G: "Fork — Multi-Modal Guidance already shows Feature Store → AutoGluon → endpoint; re-target to readmission risk."
  • Both agree on the facts: the Guidance is 2024-12-17, notebook-driven, CloudFormation-launched SageMaker domain, QuickSight-era, no cost table.
  • Resolution: Open. The disagreement is about whether a 2024-12 notebook Guidance counts as a fork base for a CDK-spine Tier 3. Practical synthesis for the lead: fork the modelling logic (Feature Store schema, AutoGluon training, endpoint) from the Guidance into the current Pipelines/Registry CDK spine (amazon-sagemaker-pipeline-deploy-manage-100x-models-python-cdk, 2026-07-28) — i.e. "fork content, build infrastructure".

X6 — Freshness of aws-amplify-cdk-iot-ble-swift-app: "stale, CDK v1, pre-Gen-2" (REPO) vs "migrated to CDK v2 2026-06-09, best fork candidate" (MOB)

  • REPO: README references CDK v1.105 and CocoaPods → pre-Gen-2 Amplify, CDK v1; "stack is stale".
  • MOB F10: commits 2026-06-09 "migrate CDK v1 to v2, resolve all 93 security vulnerabilities" and "scope IoT policy … least-privilege"; "verify it is Amplify Swift v2, not v1/aws-sdk-ios, before forking".
  • Comparator check: commit log confirms the 2026-06-09 CDK v1→v2 migration (four commits, then nothing since 2021). README is unchanged ("CDK version 1.105.0", "AWS Mobile SDK for iOS" via CocoaPods). BLEX/Podfile: pod 'Amplify', '~> 1.0', pod 'AmplifyPlugins/AWSCognitoAuthPlugin', '~> 1.0', pod 'AWSIoT', pod 'AWSMobileClient' — Amplify iOS v1 plus the classic aws-sdk-ios IoT/MobileClient pods that reached end of support 2026-08-01 (C17).
  • Resolution: Resolved — each scout was half right. The CDK/IoT side is current (v2, least-privilege policy) and forkable; the iOS side is on an end-of-support SDK and must be rewritten on Amplify Swift 2.x + AWS IoT Device SDK for Swift (GA 2026-06-01). It is a fork-for-structure candidate for the U2 device-pairing chapter, not a link.

X7 — "Zero AWS-official Amplify Gen 2 samples" (REPO) vs an AWS Gen 2 IoT sample (MOB F13)

  • REPO: aws-samples org search for "amplify gen2" in name/description returned zero repos; "no AWS-official Gen 2 healthcare or mobile sample exists".
  • MOB F13: aws-samples/aws-appsync-iot-core-realtime-dashboard uses "AppSync + Amplify Gen 2 + Location Service".
  • Comparator check: README opens "this project has been updated to use Amplify Gen2"; deploy is npx ampx sandbox; pushed 2026-09-03; MIT-0; 126 stars; topics amplify-js, aws-iot-core, location-services.
  • Resolution: Resolved. REPO's absence claim was too broad because its search keyed on name/description. Correct statement: no AWS-official Gen 2 sample with a healthcare framing or a native-mobile client exists; at least one AWS-official Gen 2 web + IoT Core sample does, and it is a fork candidate for U2's portal-side real-time view.

X8 — U4 primary artefact: IDP Accelerator + sample-healthcare-agents (REPO) vs Guidance for IDP on AWS + workshops (PORT)

  • REPO: link the GenAI IDP Accelerator (one-click, pushed 2026-09-04, BDA default) for T1+T2 generic; fork sample-healthcare-agents (2026-09-03, CDK TS) for T2 healthcare; the IDP Guidance repo "not verified".
  • PORT: link the two official IDP workshops; fork the Guidance for IDP on AWS sample (AgentCore-based per page) for healthcare specifics; did not surface the Accelerator or sample-healthcare-agents.
  • Resolution: Open but complementary, not conflicting on the verdict (both say link + fork). The objects differ because each scout searched a different surface. No check performed. Lead choice: the Accelerator is the stronger link (deployable, current, has evaluation and review built in); sample-healthcare-agents is the stronger fork for T2 (spine-matching CDK TS, HealthLake, prior-auth); the Guidance page is the better architecture explainer to embed in the chapter. G13 (Guidance repo contents) should be closed before the Guidance repo is forked.

X9 — Amazon Connect Health GA date: 2026-04-28 (AI dossier, line 35) vs 2026-03-05 (REPO, COMP)

  • Dossier (2026-09-03): dates "Connect Health GA" to the 2026-04-28 Connect rename post.
  • REPO and COMP: both cite the What's New at …/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/, dated 2026-03-05.
  • Resolution: Resolved in favour of 2026-03-05 — two independent scouts cite the dated primary announcement; the dossier's date is a re-mention in the rename post. Dossier line 35 should be corrected downstream.

5. Comparator checks performed (2026-09-04)

CheckURLFindingUsed in
Guardrails tool-use scopehttps://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-sensitive-filters.htmlNote confirmed verbatim: toolUse.input, toolResult, toolSpec.* not evaluated; logs keep unmodified input; trace match holds raw PII.C74, X1
AgentCore Gateway interceptorshttps://aws.amazon.com/blogs/machine-learning/secure-ai-agents-with-policy-and-lambda-interceptors-in-amazon-bedrock-agentcore-gateway/ (2026-06-01)Policy = Cedar at Gateway; REQUEST interceptors r/w on body; RESPONSE interceptors "can also integrate with … Amazon Bedrock Guardrails for … PII redaction".C75, X1
Pinpoint migration guidehttps://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.htmlPush/SMS/voice/OTP APIs "not impacted … supported by AWS End User Messaging"; endpoints/segments/campaigns/journeys/analytics become inaccessible; In-App Messaging no successor.C21, X2
BLE Swift sample commits / README / Podfilehttps://api.github.com/repos/aws-samples/aws-amplify-cdk-iot-ble-swift-app/commits ; raw README; BLEX/PodfileCDK v2 since 2026-06-09; README still "CDK 1.105.0"; Podfile pins Amplify ~>1.0 + AWSIoT + AWSMobileClient (EOS 2026-08-01).C31, X6
Connect Health unified workflow READMEhttps://github.com/aws-samples/sample-amazon-connect-health-unified-clinical-workflow"Amazon Bedrock Agent with 6 action groups" = Bedrock Agents classic; needs registered Connect instance + Connect Health domain; 3 stacks.C38, C77, X3
Diagnosis-codes Guidance repo metadatahttps://api.github.com/repos/aws-solutions-library-samples/guidance-for-identifying-diagnosis-codes-from-clinical-notes-on-awspushed 2026-04-13; MIT-0; not archived; 4 stars.C40, X4
AppSync IoT dashboardhttps://api.github.com/repos/aws-samples/aws-appsync-iot-core-realtime-dashboard ; raw README (master)"updated to use Amplify Gen2"; npx ampx sandbox; pushed 2026-09-03; MIT-0; 126 stars.C27, X7
Timestream compliance pagehttps://docs.aws.amazon.com/timestream/latest/developerguide/compliance.htmlNo readable HIPAA sentence; no InfluxDB/LiveAnalytics distinction retrievable.G3
S3 Tables re:Posthttps://repost.aws/questions/QU7NkMC1dNQlaC9WzOwA-aEw/s3-tables-hipaa-eligibilityHTTP 403 (same as COMP).G2
Web searches"Timestream for InfluxDB" HIPAA; "S3 Tables" HIPAA; AgentCore Gateway guardrailsOnly third-party syntheses for the two eligibility questions (not usable as claims); the AgentCore search surfaced the 2026-06-01 AWS blog above.G2, G3, C75

"REPO view" = repo-coverage angle; "PORT view" = content-structure angle; "Reconciled" = comparator's reading of the evidence, with the open decision named where the sources do not settle it.

Item / tierREPO viewPORT viewReconciledOpen decision
F0 org layerLink LZA-for-HealthcareLink LZA Solution + healthcare configLink (C1, C3). Copy the Solution cost-table shape.
F0 single accountBuild (no example)Build (no workshop)Build: CDK stack — KMS, CloudTrail, Config HIPAA pack (C4), Security Hub CSPM FSBP + NIST 800-53 r5 + AI Security BP (C5, C76), GuardDuty, Macie with PHI identifiers explicitly selected (C6), VPC endpoints, WAF; BAA step (C7); advanced-features account prerequisite (C8). Link SRA examples (CC-BY-SA, C10) and the Healthcare Lens with its 2022 date (C9).Whether the F0 chapter also demonstrates the Bedrock DataRetentionMode SCP (C73) or leaves it to the compliance-evidence chapter.
U1 T1Build (no example)BuildBuild on Amplify Gen 2 (C15); native Swift + Kotlin have full parity, Flutter does not (C16); API Gateway HTTP → FastAPI + AppSync Events for real-time (C18); Cognito Essentials with passkey-with-user-verification or password+MFA, no OTP-first-factor (C19); push via EUM Push or SNS (X2); HealthLake datastore cost ~US$197/month (C24). Fork sample-intelligent-security-for-healthcare-apis for the API boundary (C14).Native vs cross-platform (brief OQ6): evidence favours native Swift/Kotlin or React Native; Flutter is excluded by C16. Lead decision.
U1 T2Build (no example)Fork scaffolding (HCLS toolkit, AgentCore workshops)Fork scaffolding, build the assistant (C22); implement Tier 2 PHI controls per X1 (Gateway interceptors + Guardrails, Cedar Policy, logs data protection) and C73 (model choice / retention mode).Which model family carries PHI prompts (ZDR-capable vs Fable 5.1 aws_review) — C73.
U1 T3BuildLink mechanics, build modelBuild on the generic Pipelines/Registry CDK spine (C23).
U2 T1BuildBuildBuild (C26–C31). Fork guidance-for-aws-iot-greengrass-foundations and aws-greengrass-ec2-device-farm for gateway/fleet; fork aws-appsync-iot-core-realtime-dashboard (Gen 2) for the portal view (X7); fork the BLE sample's CDK only and rewrite iOS on Amplify Swift 2 + IoT Device SDK for Swift (X6); Android via IoT Device SDK for Java v2 (C29). HealthKit/Health Connect via app read + Path A/B (C30).Whether PHI-bearing vitals may land in Timestream for InfluxDB and S3 Tables at all (G2, G3) — or the hot/cold stores hold device-keyed de-identified data.
U2 T2Build (no example)BuildBuild, with the U2 T2 line rewritten per X1.
U2 T3Build (Edge Manager gone)BuildBuild: fork flink-keyed-random-cut-forest-example logic (add IaC) and the DeepAR MLOps CDK sample; edge scoring = Greengrass v2 + ONNX (C33).
U3 T1–T2Fork sample-healthscribe-bedrock-clinical-analysis; link Connect HealthFork diagnosis-codes GuidanceFork — candidates differ (X4); Connect Health sample is retired-dependent and semi-deploy (X3). Prefer HealthScribe (COMP judgement, C35) with Comprehend Medical for ontology linking (C36); build Step Functions review + HealthLake write-back. us-east-1 only.HealthScribe direct vs Connect Health Ambient (X3); which repo is the fork base (X4).
U3 T3BuildBuildBuild (C42); reuse LLM-as-judge notebooks for the evaluation harness.
U4 T1–T2Link Accelerator; fork sample-healthcare-agentsLink workshops + IDP Guidance; fork Guidance sampleLink + fork — objects differ (X8). BDA default, Textract retained (C47). Add Comprehend Medical PHI step, Macie on intake bucket, de-id sample (C49). Drop the A2I-based BDA sample (C48).Which artefact is the chapter's primary link (X8); close G13 before forking the Guidance repo.
U4 T3BuildBuildBuild (C50).
U5 T1Fork Multi-Modal GuidanceFork Multi-Modal + Entity Resolution + HealthLake workshopFork the Guidance (C53) and Entity Resolution (C54); build S3 Tables/Iceberg landing, Quick rename (C56), de-id pipeline (C49). HealthLake workshop is archived — link for concepts only.S3 Tables eligibility (G2).
U5 T2Build (snippet only)BuildBuild (C58).
U5 T3Build (stale only)Fork Multi-Modal GuidanceFork modelling content, build infrastructure (X5).Clarify successor for bias (G5).
U6 T1–T2Link Connect Health + samplesLink generic Connect workshopLink Connect Health as product (C60) and, if a repo is wanted, fork sample-Nova-Sonic-AgentCore-Healthcare-Call-Center (C63); do not link the classic-Agents voice sample (C62). Brief default 7 (light coverage) holds.Whether U6 stays optional given that Connect Health also serves U3 (X3).
U6 T3Link Connect forecasting workshopLink (C64); not a SageMaker build.
P0Build (no portal repo)Build on existing contractsBuild (C70): Guidance page anatomy + Solution header + serverless-patterns README contract; MADR 4 ADRs; contentspec.yaml per use case; TechDocs/Antora-style aggregation; Guidance disclaimer on forked chapters (C68). Link official workshops only after G1 is closed.Docusaurus vs Backstage TechDocs vs Antora — tooling choice (PORT E4–E6).
Cross-cutting: compliance evidencesample-hipaa-assistant as an evidence-generation demoAdd chapters for: Bedrock retention modes + SCP (C73), Guardrails scope and logging caveats (C74–C75), Security Hub CSPM AI standard (C76), Macie PHI selection (C6), F-15 closure text (C72).