Skip to main content

Angle 2 — healthcare-compliance-building-blocks

Generated at build time from research/aws-demo-catalog/sources/healthcare-compliance-building-blocks.md in the repo — edit the source, not this page.

Date: 2026-09-04 (all retrievals this date unless a source date is given). Scout: angle 2 of the aws-demo-catalog research pass. Brief: research/aws-demo-catalog/brief.md; hypothesis: catalog-v0.md.

Summary

Every service on the catalog's stack spine and in F0–U6 is on the AWS HIPAA Eligible Services Reference (page stamped "Last Updated: September 3, 2026"), including Amazon Bedrock, Amazon Bedrock AgentCore, all six health-specific services, Amazon Quick, Kiro and the whole IoT → Kinesis → Managed Flink → Timestream → S3 → Athena/Glue/Lake Formation → SageMaker AI path. Three names the catalog uses do not appear by name — S3 Tables, Timestream for InfluxDB and ElastiCache for Valkey — and are covered only by the page's general rule that "generally available features of each of the HIPAA eligible services listed are also considered HIPAA eligible"; Bedrock Knowledge Bases, Guardrails and Data Automation are in the same position (features of Bedrock), and the AWS industries blog of 2025-10-13 names Knowledge Bases and Guardrails as eligible explicitly. The BAA is self-service in AWS Artifact, at account level or — from the Organizations management account with "all features" enabled — at organization level, covering all existing and future member accounts. The six health services are all GA and all HIPAA-eligible; HealthLake, HealthImaging and HealthOmics are actively shipping (multiple 2026 What's New posts), HealthScribe is active but us-east-1 only and is now being surfaced through the new Amazon Connect Health (GA 2026-03-05, HIPAA-eligible, us-east-1/us-west-2), while Transcribe Medical and Comprehend Medical are quiet, not retired (no What's New since 2021-01 and 2020-07 respectively; docs live, no end-of-support notice). Controls: the Config pack is still "Operational Best Practices for HIPAA Security" (template last touched 2025-01-07); Security Hub was split in Oct–Dec 2025 into "AWS Security Hub CSPM" (which runs the standards: FSBP, AI Security Best Practices, CIS, NIST 800-53 r5, NIST 800-171 r2, PCI DSS, Resource Tagging, Control Tower service-managed) and a new "AWS Security Hub" (OCSF, risk analytics) — only CSPM is on the eligible list; there is no HIPAA-named Security Hub standard. Macie has twelve PHI managed data identifiers but none of them are in the recommended or default sets, so PHI discovery must be configured explicitly. Dossier item F-15 closes as CONFIRMED with one important nuance: Bedrock's FAQ no-training / no-provider-sharing statements and the HIPAA / SOC / ISO / CSA STAR L2 / FedRAMP Moderate (commercial) and FedRAMP High (GovCloud US-West) list are all on the primary pages, but the Bedrock data-retention user guide now defines a per-account/per-project retention mode (none < default < aws_review < legacy provider_data_share), and Claude Fable 5 / 5.1 require aws_review, under which all prompts and completions are retained by AWS for up to 30 days and classifier-flagged traffic may be human-reviewed by AWS. For PHI that means model choice and an SCP on bedrock:DataRetentionMode are compliance-evidence items in their own right (catalog cross-cutting "Compliance evidence" chapter).


1. Business Associate Addendum (F0)

#FindingSourceTierConfidence
1.1The BAA is accepted self-service in the AWS Artifact console ("To review, accept, and manage the status of the BAA for your account, sign in to AWS Artifact in the AWS Management Console"). PHI may only be processed in HIPAA-eligible services.AWS HIPAA Compliance page, https://aws.amazon.com/compliance/hipaa-compliance/ (retrieved 2026-09-04)PrimaryHigh
1.2Artifact supports two scopes: account agreements and organization agreements. "If you use AWS Organizations, you can accept agreements, such as a BAA with AWS, on behalf of all AWS accounts in your organization. All existing and subsequent member accounts are automatically covered by the agreement and can legally process PHI."AWS Artifact User Guide, "Managing agreements", https://docs.aws.amazon.com/artifact/latest/ug/managing-agreements.html (retrieved 2026-09-04)PrimaryHigh
1.3Organization-level acceptance prerequisites: must be signed in to the management account with Artifact permissions; the organization must be enabled for all features (consolidated-billing-only orgs cannot use it); the Artifact NDA must be accepted to download the agreement PDF before accepting. Member-account users with organizations:DescribeOrganization can view the accepted org agreement.AWS Artifact User Guide, "Accepting agreements for your organization", https://docs.aws.amazon.com/artifact/latest/ug/accept-org-agreement.html (retrieved 2026-09-04)PrimaryHigh
1.4The eligible-services page carries the operative contractual sentence: a Covered Entity or Business Associate agrees "not to use these HIPAA Eligible Services for any purpose or in any manner involving Protected Health Information ... without first entering into an AWS business associate agreement", and "Customers still must configure these services consistent with HIPAA requirements."https://aws.amazon.com/compliance/hipaa-eligible-services-reference/ (page stamped Last Updated: September 3, 2026; retrieved 2026-09-04)PrimaryHigh
1.5No catalog service requires a separate HIPAA opt-in beyond the BAA. Two configuration points are however PHI-relevant and belong in F0: (a) Bedrock's per-account/per-project data_retention mode (see §5), and (b) the Bedrock and Security Hub CSPM compliance pages both warn: "Our new AWS sign-up experience is not designed for regulated workloads. If you're using our new AWS sign-up experience, but you want to use AWS for regulated workloads, you can sign up for AWS (advanced) or activate advanced features." An F0 "empty account" runbook must therefore start from an advanced-features account.Bedrock compliance validation, https://docs.aws.amazon.com/bedrock/latest/userguide/compliance-validation.html ; Security Hub CSPM compliance validation, https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-compliance.html (both retrieved 2026-09-04)PrimaryHigh for the warning text; Medium for "no other opt-in" (absence of evidence across the pages read)
1.6The whitepaper "Architecting for HIPAA Security and Compliance on Amazon Web Services" is archived: "Notice: This whitepaper has been archived. For the latest technical information on HIPAA Compliance and AWS, see the HIPAA Eligible Services Reference." The portal's F0 chapter should not link it as current guidance.https://docs.aws.amazon.com/whitepapers/latest/architecting-hipaa-security-and-compliance-on-aws/document-revisions.html (retrieved 2026-09-04)PrimaryHigh

2. HIPAA-eligible services list, per catalog service

Source for every row: AWS HIPAA Eligible Services Reference, https://aws.amazon.com/compliance/hipaa-eligible-services-reference/ — page shows "Last Updated: September 3, 2026"; retrieved 2026-09-04 (two fetches, verbatim list of 174 entries). The Services-in-Scope page's "HIPAA BAA" tab links to this same page, so it is the authoritative list. General rule on the page: "Unless specifically excluded, generally available features of each of the HIPAA eligible services listed are also considered HIPAA eligible." No exclusions were shown for any service below.

Status key: Listed = named on the list; Feature of listed service = not named, covered by the general-feature rule; Not found = not on the list under that name.

Catalog serviceCatalog item / tierStatus (2026-09-04)Exact list entry / noteConfidence
Amazon Bedrock (model inference, Converse, cross-region inference)U1–U6 Tier 2Listed"Amazon Bedrock". Also confirmed on Bedrock FAQ ("HIPAA eligible") and Bedrock security page.High
Amazon Bedrock AgentCore (Runtime, Gateway, Memory, Identity, Observability)U1 T2, U2 T2, U4 T2Listed"Amazon Bedrock AgentCore". AgentCore docs: "Amazon Bedrock AgentCore is HIPAA eligible and FedRAMP (Class C and Class D), SOC 2 and ISO (27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018, 9001:2015) and CSA STAR compliant"; HITRUST, PCI and others by AWS internal assessment pending third-party audit. Docs do not exclude any AgentCore component. https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/compliance-validation.htmlHigh
Bedrock Knowledge Bases (Managed KB)U1 T2, U5 T2, U6 T2Feature of listed serviceNot named separately. AWS industries blog 2025-10-13 explicitly names "Amazon Bedrock Knowledge Bases" and "Amazon Bedrock Guardrails" as HIPAA eligible. https://aws.amazon.com/blogs/industries/hipaa-compliance-for-generative-ai-solutions-on-aws/High
Bedrock Guardrailsall Tier 2Feature of listed serviceAs above.High
Bedrock Data AutomationU4 T1Feature of listed serviceNot named separately; GA feature of Bedrock. AWS Architecture Blog "Automate medical record digitization with Amazon Bedrock Data Automation and AWS HealthLake" (lead for angle 1) treats it as usable for medical records. No AWS page naming BDA as HIPAA eligible was found.Medium
AWS HealthLakeU1 T1, U3 T1, U5 T1Listed"AWS HealthLake"; FAQ: "AWS HealthLake is a HIPAA Eligible Service".High
AWS HealthImaging(not in catalog; reference)Listed"AWS HealthImaging"; FAQ: "HealthImaging is a HIPAA-eligible service."High
AWS HealthOmics(not in catalog; reference)Listed"AWS HealthOmics"; product page: "HIPAA-eligible service".High
AWS HealthScribeU3 T1Listed (as part of Transcribe)Entry reads "AWS Transcribe [Includes Healthscribe]". Transcribe developer guide: "AWS HealthScribe is a HIPAA-eligible machine learning (ML) capability". https://docs.aws.amazon.com/transcribe/latest/dg/health-scribe.htmlHigh
Amazon Transcribe MedicalU3 T1Listed (as part of Transcribe)"AWS Transcribe"; developer guide: "Amazon Transcribe is covered under AWS's HIPAA eligibility and BAA which requires BAA customers to encrypt all PHI at rest and in transit when in use. Automatic PHI identification is available at no additional charge and in all regions where Amazon Transcribe operates." https://docs.aws.amazon.com/transcribe/latest/dg/what-is.htmlHigh
Amazon Comprehend MedicalU3 T1, U4 T1, U5 T1Listed"Amazon Comprehend Medical"; FAQ: "HIPAA eligible".High
Amazon TextractU4 T1Listed"Amazon Textract".High
Amazon Connect (renamed Amazon Connect Customer 2026-04-28 per dossier)U6 T1–T2Listed"Amazon Connect" (link target /products/connect/customer/).High
Amazon Connect HealthU3 T1, U6 T1 (new)Listed"Amazon Connect Health". What's New 2026-03-05: GA; patient verification and ambient documentation GA; appointment management, patient insights, medical coding in preview; us-east-1 and us-west-2; "All the features ... are HIPAA-eligible". https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/High
Amazon Lex (V2)U6 T1Listed"Amazon Lex".High
AWS Amplify — HostingU1 T1Listed"AWS Amplify Console" (i.e. Amplify Hosting).High
AWS Amplify — Gen 2 backend / client librariesU1 T1Feature of listed services (backend) / n/a (libraries)Not named. Gen 2 backends are CloudFormation-deployed Cognito, AppSync, Lambda, S3, DynamoDB in the customer account — each listed individually. Client libraries execute on the device and are not an AWS service. Amplify docs compliance page could not be fetched (see gaps).Medium
AWS AppSyncU1 T1Listed"AWS AppSync".High
Amazon API GatewayU1 T1, cross-cuttingListed"Amazon API Gateway".High
AWS IoT CoreU2 T1Listed"AWS IoT Core".High
AWS IoT Greengrass (v2)U2 T1, U2 T3Listed"AWS IoT Greengrass" (no version qualifier).High
Amazon Kinesis Data StreamsU2 T1Listed"Amazon Kinesis Data Streams".High
Amazon Data FirehoseU2 T1, U5 T1Listed"Amazon Kinesis Data Firehose" (old name on the list).High
Amazon Managed Service for Apache FlinkU2 T1, U2 T3Listed"Amazon Managed Service for Apache Flink".High
Amazon Timestream for InfluxDBU2 T1Feature of listed service / not found by nameList says only "Amazon Timestream". Timestream FAQ's compliance sentence ("HIPAA eligible and in scope for AWS SOC 1, SOC 2, and SOC 3") sits under the LiveAnalytics section only; the developer-guide compliance page was unreadable. No AWS page naming InfluxDB as HIPAA eligible was found. Recommend confirming with the AWS account team before PHI lands in InfluxDB, or storing only device-keyed, de-identified vitals there. https://aws.amazon.com/timestream/faqs/Medium-Low
Amazon S3U1–U5Listed"Amazon Simple Storage Service (S3)".High
Amazon S3 TablesU5 T1, U2 T1Feature of listed service / not found by nameNot named; an unresolved re:Post thread "S3 Tables HIPAA Eligibility" exists (fetch returned 403). Same recommendation as InfluxDB. https://repost.aws/questions/QU7NkMC1dNQlaC9WzOwA-aEw/s3-tables-hipaa-eligibilityMedium-Low
Amazon AthenaU2 T1, U5 T1Listed"Amazon Athena".High
AWS Glue (Data Catalog)U5 T1Listed"AWS Glue" (also "AWS Glue DataBrew").High
AWS Lake FormationU5 T1Listed"AWS Lake Formation".High
Amazon SageMaker AI (Feature Store, Pipelines, Model Registry, endpoints)all Tier 3Listed"Amazon SageMaker AI"; features covered by the general rule.High
Amazon QuickU5 T1–T2Listed"Amazon Quick".High
KiroP0 / toolingListed"Kiro".High
AWS Step FunctionsU3 T1, U4 T1Listed"AWS Step Functions".High
Amazon EventBridgeU2 T1Listed"Amazon EventBridge".High
Amazon SNSU1 T1, U2 T1Listed"Amazon Simple Notification Service (SNS)".High
Amazon SES / Pinpoint / End User MessagingU1 T1 (angle 3 owns lifecycle)Listed"Amazon Simple Email Service (Amazon SES)"; "Amazon Pinpoint and End User Messaging".High
Amazon SQSU4 T1Listed"Amazon Simple Queue Service (SQS)".High
Amazon ECS / AWS Fargate (Express Mode)spineListed"Amazon Elastic Container Service (ECS)"; "AWS Fargate".High
Amazon Aurora (PostgreSQL Serverless v2)spineListed"Amazon Aurora".High
Amazon DynamoDBspineListed"Amazon DynamoDB".High
Amazon ElastiCache (for Valkey)cross-cuttingListed (engine not named)"Amazon ElastiCache"; Valkey engine is a GA feature → general rule.High
Amazon CognitospineListed"Amazon Cognito".High
Amazon CloudFrontspineListed"Amazon CloudFront".High
AWS WAF / AWS ShieldF0Listed"AWS Web Application Firewall (WAF)"; "AWS Shield".High
Amazon MacieF0, U4 T1, U5 T1Listed"Amazon Macie".High
AWS Security HubF0Listed as CSPM only"AWS Security Hub CSPM". The new "AWS Security Hub" (GA 2025-12-02) is not on the list under its own name.High
AWS ConfigF0Listed"AWS Config".High
Amazon GuardDutyF0Listed"Amazon GuardDuty".High
AWS Control Tower / AWS OrganizationsF0Listed"AWS Control Tower"; "AWS Organizations".High
AWS KMS, CloudTrail, CloudWatch (+Logs), Secrets Manager, IAM Identity Center, VPC, Lambda, CloudFormation, CodeBuild/CodePipeline, X-RayF0 / spineListedAll named on the list.High
Lifecycle caveatrule 4The list still carries retired services (Amazon Forecast, Amazon Kendra, Amazon Q Business, AWS IoT Events, Amazon Augmented AI). Presence on the eligibility list is not a lifecycle signal; catalog rule 4 stands.High

3. Health-specific services: lifecycle, regions, pricing

Pricing figures below were extracted from the AWS pricing pages on 2026-09-04 by an automated reader; units are reliable, exact numbers should be re-checked in the AWS Pricing Calculator before they go into a portal chapter. Region default per brief Open Question 3 is us-east-1 + us-west-2.

ServiceLifecycle (2026-09-04)Regions (us-east-1 / us-west-2?)Headline pricing unitsSourcesConfidence
AWS HealthLake (U1 T1, U3 T1, U5 T1)GA, actively shipping. What's New: 2026-03 data transformation agent (CCDA→FHIR R4, preview); 2026-05 CMS-0057-F prior-auth API support; 2026-07 resource matching / duplicate linking (preview); 2025-06 Ireland region.FAQ: US East (N. Virginia), US East (Ohio), US West (Oregon), Asia Pacific (Mumbai), Europe (London), Europe (Ireland), Asia Pacific (Sydney). Both defaults yes.Data store $0.27 per data-store-hour (~$197/month per store, first 10 GB included) — the dominant demo cost; storage $0.37/GB-mo Advanced or $0.25/GB-mo Standard; 3,500 queries/hour included then $0.048 (Adv) / $0.015 (Std) per 10,000; integrated medical NLP $0.0010 per 100 characters; export $0.19/GB; FHIR subscriptions $2.00 (EventBridge) / $0.90 (REST-hook) per 1M events, 100k free/month.https://aws.amazon.com/healthlake/pricing/ ; https://aws.amazon.com/healthlake/faqs/ ; https://aws.amazon.com/about-aws/whats-new/2026/07/aws-healthlake/ ; https://aws.amazon.com/about-aws/whats-new/2026/05/aws-healthlake-cms-cms-0057-f/ ; https://aws.amazon.com/about-aws/whats-new/2026/03/aws-healthlake-data-transformation-agent/Lifecycle High; regions High; prices Medium
AWS HealthImaging (reference only; not in catalog)GA (2023-07), actively shipping. 2026-01 JPEG XL; 2026-02 CloudWatch storage metrics; 2026-03 study-level fine-grained access control; 2026-03 London region.General Reference: us-east-1, us-west-2, ap-southeast-2, eu-west-1, eu-west-2. Both defaults yes.Storage $0.105/GB-mo Frequent Access, $0.006/GB-mo Archive Instant Access; imports free; $0.005 per 1,000 API calls; 30-day minimum, 5 MB minimum per image set; 10 GB structured metadata included per data store.https://docs.aws.amazon.com/general/latest/gr/healthimaging.html ; https://aws.amazon.com/healthimaging/pricing/ ; https://aws.amazon.com/about-aws/whats-new/2026/03/aws-healthimaging-study-level-access-control/ ; https://aws.amazon.com/about-aws/whats-new/2026/02/aws-healthimaging-additional-metrics/ ; https://aws.amazon.com/about-aws/whats-new/2026/01/aws-healthimaging-adds-jpeg-xl/High / High / Medium
AWS HealthOmics (reference only; not in catalog)GA, most active of the six. 2026-03 batch runs (100k runs/request) and VPC-connected workflows; 2026-06 Nextflow 26.04, version pinning, profiles, ephemeral storage; 2026-07-20 Tokyo + Ohio for private workflows; 2025-09 Seoul.Private workflows (2026-07-20): us-east-1, us-east-2, us-west-2, eu-central-1, eu-west-1, eu-west-2, il-central-1, ap-northeast-2, ap-southeast-1, ap-northeast-1. Both defaults yes. Sequence/variant store region list not separately confirmed.Workflows: per omics instance-hour (e.g. omics.c.4xlarge $0.9180/hr), 60-s minimum per task; run storage $0.000411/GB-hr dynamic, $0.000192/GB-hr static; Ready2Run fixed fee per run; sequence store $0.005769 per gigabase-month active, $0.001154 archive; variant store $0.035/GB-mo; 2-month free tier.https://aws.amazon.com/healthomics/pricing/ ; https://aws.amazon.com/about-aws/whats-new/2026/07/healthomics-tokyo-ohio/ ; https://aws.amazon.com/about-aws/whats-new/2026/03/aws-healthomics-vpc-connected-workflows/ ; https://aws.amazon.com/about-aws/whats-new/2026/06/healthomics-scratch-storage/High / High / Medium
AWS HealthScribe (U3 T1)GA (2023-11-27), active but slower. 2025-02 GIRPP behavioral-health note template. Developer guide now carries a banner "Introducing Amazon Connect Health Ambient agent — you can now use the ambient agent to power your healthcare workflow", i.e. the capability is being surfaced through Connect Health; no retirement notice.Developer guide: "AWS HealthScribe is available in the US East (N. Virginia) region." us-east-1 only — us-west-2 NO. Flag for Open Question 3.$0.001667 per audio second (= $0.10/min), 15-second minimum per request; batch (StartMedicalScribeJob) and streaming (StartMedicalScribeStream) both supported, single price; free tier 300 audio minutes/month for first 2 months. en-US only; 22 specialties.https://docs.aws.amazon.com/transcribe/latest/dg/health-scribe.html ; https://aws.amazon.com/healthscribe/pricing/ ; https://aws.amazon.com/about-aws/whats-new/2023/11/aws-healthscribe-generally-available/ ; https://aws.amazon.com/about-aws/whats-new/2025/02/aws-healthscribe-girpp-note-template-behavioral-healthHigh / High / Medium
Amazon Transcribe Medical (U3 T1)GA (2019-12); quiet, not retired. Last What's New found: 2021-01 automatic PHI identification (searches for 2022–2026 returned nothing). Developer guide live on 2026-09-04 with no deprecation, end-of-support or migration notice. en-US only; primary-care specialties batch+streaming, others streaming only.Developer guide table: us-east-1 (batch, streaming), us-west-2 (batch, streaming), plus us-east-2, us-west-1 (batch), ca-central-1, eu-west-1/2/3, eu-central-1, eu-north-1, ap-*, sa-east-1, af-south-1, me-south-1, GovCloud. Both defaults yes.Extracted as $0.075/min batch and $0.15/min streaming (about 12–15x standard Transcribe's $0.006 / $0.01); free tier 60 min/month for 12 months. Re-verify — the extraction did not show a per-second table.https://docs.aws.amazon.com/transcribe/latest/dg/transcribe-medical.html ; https://aws.amazon.com/transcribe/pricing/ ; https://aws.amazon.com/about-aws/whats-new/2021/01/amazon-transcribe-medical-now-provides-automatic-protected-health-information-phi-identification/Lifecycle High; regions High; prices Medium-Low
Amazon Comprehend Medical (U3 T1, U4 T1, U5 T1)GA (2018-11); quiet, not retired. Last What's New found: 2020-07 relationship extraction; 2020-05 GovCloud (US-West). Docs and FAQ live, no end-of-support notice. Newer surfaces for the same job: HealthLake integrated NLP ($0.0010/100 chars) and Connect Health medical coding (preview, 2026-03).Third-party mirror dated 2026-09-03 (General Reference page unreadable): us-east-1, us-east-2, us-west-2, ca-central-1, eu-west-1, eu-west-2, ap-southeast-2, us-gov-west-1. Both defaults yes (Medium — non-primary source).100-character units, 1-unit minimum per request. NERe (DetectEntitiesV2) tiered $0.01 / $0.005 / $0.001 per unit (first 1M / next 1M / beyond); SNOMED CT $0.0075 / $0.00375 / $0.00075. DetectPHI, ICD-10-CM and RxNorm rows could not be extracted (page presents worked examples, not a table). Free tier 85,000 units (8.5M chars) in the first month.https://aws.amazon.com/comprehend/medical/pricing/ ; https://aws.amazon.com/comprehend/medical/faqs/ ; https://www.aws-services.info/comprehendmedical.html (third-party, 2026-09-03) ; https://aws.amazon.com/about-aws/whats-new/2020/07/amazon-comprehend-medical-adds-relationship-extraction-to-medical-condition/Lifecycle High; regions Medium; prices Medium (PHI price: gap)
Amazon Connect Health (new; overlaps U3 T1 and U6 T1)GA 2026-03-05. GA: patient verification, ambient documentation. Preview: appointment management, patient insights, medical coding (ICD-10/CPT from notes). Dossier line 35 dates "Connect Health GA" to the 2026-04-28 Connect rename post — the What's New is 2026-03-05; comparator should reconcile (likely re-mention).us-east-1 and us-west-2. Both defaults yes.Not on the announcement; product page pointer only.https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/High

Judgement for the catalog. Nothing in the six is retired or de-emphasised by AWS notice. Transcribe Medical and Comprehend Medical are the two "no What's New in 12+ months" services (last posts 2021-01 and 2020-07); AWS is investing in HealthScribe/Connect Health (ambient documentation + coding) and HealthLake NLP as the newer surfaces for the same U3/U4 jobs. U3 Tier 1 should therefore prefer HealthScribe (or Connect Health Ambient) over Transcribe Medical + Comprehend Medical as the primary path, keeping Comprehend Medical for ontology linking (ICD-10-CM/RxNorm/SNOMED) where HealthScribe does not code — with the us-east-1-only constraint recorded.


4. Controls and evidence (F0)

#FindingSourceTierConfidence
4.1AWS Config conformance pack name is unchanged: "Operational Best Practices for HIPAA Security". Template Operational-Best-Practices-for-HIPAA-Security.yaml in awslabs/aws-config-rules/aws-config-conformance-packs. Latest commits: 2025-01-07 "Removing S3_BUCKET_LEVEL_PUBLIC_ACCESS_PROHIBITED which is redundant to limit rules to 130"; 2024-12-17 RDS Multi-AZ cluster rules; 2023-10 parameter fixes. The doc page says the pack "was validated by AWS Security Assurance Services LLC (AWS SAS)" and disclaims that packs "are not designed to fully ensure compliance". Sibling packs relevant to a health portal: FDA 21 CFR Part 11, GxP EU Annex 11, NIST 800-53 rev 5, NIST 800-171, NIST CSF, NIST Privacy Framework.https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-hipaa_security.html ; https://github.com/awslabs/aws-config-rules/tree/master/aws-config-conformance-packs ; commit history https://github.com/awslabs/aws-config-rules/commits/master/aws-config-conformance-packs/Operational-Best-Practices-for-HIPAA-Security.yaml (all retrieved 2026-09-04)PrimaryHigh
4.2Security Hub split. The pre-2025 service was renamed AWS Security Hub CSPM (Oct 2025) and a new AWS Security Hub went GA 2025-12-02 ("detects critical risks by correlating and enriching security signals from Amazon GuardDuty, Amazon Inspector, and AWS Security Hub CSPM"; OCSF schema; automation-rule migration blog exists). Security standards and controls remain in CSPM. Only "AWS Security Hub CSPM" is on the HIPAA list.https://aws.amazon.com/about-aws/whats-new/2025/12/security-hub-near-real-time-risk-analytics/ ; https://aws.amazon.com/blogs/security/security-hub-cspm-automation-rule-migration-to-security-hub/ ; https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.html (retrieved 2026-09-04)PrimaryHigh
4.3Security Hub CSPM standards available (exact names): AWS Foundational Security Best Practices; AI Security Best Practices (new — "controls that detect when deployed AI resources do not align with security best practices ... network isolation, encryption, VPC placement, and AWS KMS key usage"; directly relevant to Bedrock/SageMaker in Tier 2/3); AWS Resource Tagging; CIS AWS Foundations Benchmark (v5.0 support added 2025-10); NIST SP 800-53 Revision 5; NIST SP 800-171 Revision 2; PCI DSS; Service-managed standard, AWS Control Tower. There is no HIPAA-named standard; the doc states standards "don't guarantee compliance with any regulatory frameworks". For HIPAA evidence the practical pairing is FSBP + NIST 800-53 r5 in CSPM plus the Config HIPAA pack.https://docs.aws.amazon.com/securityhub/latest/userguide/standards-reference.html ; https://aws.amazon.com/about-aws/whats-new/2025/10/aws-security-hub-cspm-cis-foundations-benchmark-v5 (retrieved 2026-09-04)PrimaryHigh
4.4Macie PHI managed data identifiers (category "Personal information: PHI"): US_DRUG_ENFORCEMENT_AGENCY_NUMBER, USA_HEALTH_INSURANCE_CLAIM_NUMBER, USA_MEDICARE_BENEFICIARY_IDENTIFIER, CANADA_HEALTH_NUMBER, EUROPEAN_HEALTH_INSURANCE_CARD_NUMBER, FINLAND_EUROPEAN_HEALTH_INSURANCE_NUMBER, FRANCE_HEALTH_INSURANCE_NUMBER, UK_NHS_NUMBER, USA_HEALTHCARE_PROCEDURE_CODE (HCPCS), USA_NATIONAL_DRUG_CODE, USA_NATIONAL_PROVIDER_IDENTIFIER, MEDICAL_DEVICE_UDI. All require a nearby keyword. Also relevant: NAME, DATE_OF_BIRTH, ADDRESS, PHONE_NUMBER, USA_SOCIAL_SECURITY_NUMBER.https://docs.aws.amazon.com/macie/latest/user/mdis-reference.html (retrieved 2026-09-04)PrimaryHigh
4.5None of the PHI identifiers are in Macie's "recommended" set for discovery jobs (GA 2023-06-27) or the dynamic default set for automated sensitive data discovery (since 2023-08-02) — both sets contain credentials, credit cards and PII only. Accounts that enabled automated discovery before 2023-08-02 use an older static set that did include the PHI identifiers. F0/U4/U5 must therefore explicitly select the PHI identifiers (and NAME, DATE_OF_BIRTH, ADDRESS) in job and automated-discovery settings; the portal chapter should show this as a deliberate step.https://docs.aws.amazon.com/macie/latest/user/discovery-jobs-mdis-recommended.html ; https://docs.aws.amazon.com/macie/latest/user/discovery-asdd-settings-defaults.html (retrieved 2026-09-04)PrimaryHigh
4.6Control Tower is current and active as the landing-zone path. 2026-07-16 AFT re-applies customizations on OU moves; 2025-11-21 Control Tower v4.0 "controls-dedicated experience": "customers can have direct access to these AWS managed controls without requiring a full Control Tower deployment" (750+ managed controls, deployed into an existing AWS Organization); 2025-12 176 more Security Hub controls; 2025-11 279 more Config rules and seven new compliance frameworks in Control Catalog; 2025-11 automatic enrollment. Relevance to Open Question 2: an Organization is still required, but a full landing zone is no longer required to use the managed controls — F0 can present "single account + org-level controls later" honestly. Whether HIPAA is among the Control Catalog frameworks was not verified.https://aws.amazon.com/about-aws/whats-new/2026/07/aws-control-tower-account/ ; https://aws.amazon.com/about-aws/whats-new/2025/11/aws-control-tower-controls-dedicated-experience/ ; https://aws.amazon.com/about-aws/whats-new/2025/12/176-security-hub-controls-control-tower/ ; https://aws.amazon.com/about-aws/whats-new/2025/11/aws-control-tower-new-compliance-frameworks-additional-aws-config-rules/ (retrieved 2026-09-04)PrimaryHigh

5. PHI handling patterns and Bedrock data retention (closes dossier F-15; brief Open Question 8)

5.1 F-15 closure — Bedrock FAQ / compliance claims

Sub-claim in dossier §2.E.4VerdictEvidence (retrieved 2026-09-04)
"Bedrock does not use customer content to improve models"ConfirmedFAQ: "With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers." and "AWS and the third-party model providers will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models." https://aws.amazon.com/bedrock/faqs/ ; security page: "your data is not shared with model providers, and is not used to improve the base models" https://aws.amazon.com/bedrock/security-compliance/
"does not share it with providers (per-region Model Deployment Accounts)"ConfirmedData-protection guide: "in each AWS Region where Amazon Bedrock is available, there is one such deployment account per model provider ... Model providers don't have any access to those accounts ... they don't have access to Amazon Bedrock logs or to customer prompts and completions." Data-retention guide: "Sharing content with model providers is not supported today"; legacy provider_data_share "does not cause your inputs or outputs to be shared". https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html ; https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html
"HIPAA-eligible, SOC 1/2/3, ISO, FedRAMP Moderate commercial"Confirmed (ISO list is 9001, 27001, 27017, 27018, 27701, 22301, 20000; CSA STAR Level 2; GDPR)FAQ and https://aws.amazon.com/bedrock/security-compliance/ ; HIPAA list entry "Amazon Bedrock".
"FedRAMP High / IL4-5 in GovCloud"FedRAMP High confirmed ("a FedRAMP High authorized service in the AWS GovCloud (US-West) Region"); IL4/IL5 not seen on any page fetched — leave at Medium.https://aws.amazon.com/bedrock/security-compliance/
Nuance the dossier did not have"No retention" is model-dependent, see 5.2.data-retention.html, abuse-detection.html

5.2 Bedrock data-retention modes as they apply to PHI

#FindingSourceTierConfidence
5.2.1Retention is a mode, set at project or account scope, ordered none < default < aws_review < provider_data_share (legacy), with inherit deferring to the broader scope; effective mode = first non-inherit of project → account → model default. none = "Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider." default = the model's own policy; "AWS may retain the data for safety and abuse-prevention purposes. The model provider does not receive it." aws_review = "allows your inputs and outputs to be retained for human review by AWS ... within the AWS boundary — the model provider does not review your content". Set via PUT /v1/data_retention (Mantle) or PUT /data-retention (control plane); "At launch, there is no console UI".https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html (retrieved 2026-09-04)PrimaryHigh
5.2.2Claude Fable 5 and Fable 5.1 require aws_review (allowed_modes: ["aws_review","provider_data_share"]); with none or default they show status: "unavailable". For these models "user prompts and completions are retained within the AWS boundary for up to 30 days and may be reviewed by AWS". Abuse-detection page: "all traffic will be retained for up to 30 days for automated offline abuse detection. Classifier-flagged traffic will be subject to potential human review performed by AWS." Customers in the Enterprise Frontier Safeguards program get ZDR through 2026-12-31; that program "plans to enable customer-managed encryption keys and bring your own bucket" for the abuse-detection store. "There is no data retention change to Claude models released before Claude Fable 5." Example in the doc: Claude Opus 4.8 allows none. ZDR on a retention-requiring model is per-account, per-model via the AWS account manager; "ZDR eligibility for Claude models is managed by Anthropic."data-retention.html ; https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html (retrieved 2026-09-04)PrimaryHigh
5.2.3Bedrock's baseline model is "zero operator access (ZOA)" and "zero data retention (ZDR) ... by default"; exceptions listed are the OpenAI GPT-5.4/5.5/5.6 family (classifier-flagged traffic retained up to 30 days) and Fable 5/5.1 (all traffic). "Retained inputs and outputs are stored and processed by AWS and are not shared with third-party model providers. If cross-region inference is enabled for these models, retained inputs and outputs are stored in destination regions."abuse-detection.html (retrieved 2026-09-04)PrimaryHigh
5.2.4Enforcement is possible by SCP/IAM using condition keys bedrock:DataRetentionMode (control plane) and bedrock-mantle:DataRetentionMode (Mantle) on PutAccountDataRetention / CreateProject / UpdateProject; the doc gives two worked SCPs: "require zero data retention across the organization" and "permit AWS retention but not human review".data-retention.htmlPrimaryHigh
5.2.5Design consequence for PHI (catalog "Compliance evidence" chapter, and every Tier 2). Under the BAA, AWS is the business associate, so retention inside the AWS boundary is not a disclosure to a third party — but for a aws_review model it is a 30-day retention of PHI-bearing prompts with possible human review by AWS staff, which the covered entity's risk analysis and minimum-necessary policy must address. The clean demonstrable patterns are: (a) an org SCP pinning DataRetentionMode to none for PHI accounts, which makes Fable 5.1 unavailable there by construction; (b) routing PHI-bearing prompts to ZDR-capable models (Opus 5 per dossier §2.E.4; Opus 4.8 per the doc example) and using Fable 5.1 only on de-identified inputs or in a project explicitly set to aws_review with that decision logged; (c) a US-only cross-region inference profile so retained data stays in-country. This is a scout inference from the primary text, not an AWS statement.Inference from 5.2.1–5.2.4Scout inferenceMedium

5.3 De-identification and PHI-detection building blocks

#FindingCatalog itemSourceTierConfidence
5.3.1Comprehend Medical DetectPHI returns entities with offsets and confidence, types AGE, DATE, NAME, PHONE_OR_FAX, EMAIL, ID, URL, ADDRESS, PROFESSION, mapped to the 18 Safe Harbor identifiers ("these entities don't map 1:1 to the list specified by the Safe Harbor method"). It detects, it does not redact; the FAQ states it "may not accurately identify protected health information in all circumstances, and does not meet the requirements for de-identification"; docs recommend "additional human review or other methods" for compliance use.U3 T1, U4 T1, U5 T1https://docs.aws.amazon.com/comprehend-medical/latest/dev/textanalysis-phi.html ; https://aws.amazon.com/comprehend/medical/faqs/ (retrieved 2026-09-04)PrimaryHigh
5.3.2Transcribe / Transcribe Medical automatic PHI identification is "available at no additional charge and in all regions where Amazon Transcribe operates"; PII redaction is a chargeable feature on standard Transcribe.U3 T1https://docs.aws.amazon.com/transcribe/latest/dg/what-is.htmlPrimaryHigh
5.3.3Bedrock Guardrails sensitive-information filters: per-PII-type BLOCK / ANONYMIZE (mask as {NAME} etc.) / NONE (detect only), separately for input and output; custom regex (no lookaround). Built-in health-related types are only CA_HEALTH_NUMBER and UK_NATIONAL_HEALTH_SERVICE_NUMBERno US MRN, Medicare ID, NPI or generic health-plan-ID type, so US PHI identifiers need regex patterns. Three caveats that matter for the catalog: (i) "In tool use (function calling) workloads, it does not evaluate ... PII the model generates into tool call arguments (toolUse.input) ... PII in tool results your application returns to the model (toolResult) ... PII in the tool definitions" — so catalog U2 Tier 2's "Guardrails at the tool boundary" cannot rely on the PII filter for AgentCore Gateway tool inputs/outputs; the tool layer must do its own masking; (ii) model invocation logs "always contain the original, unmodified request regardless of guardrail intervention" — use CloudWatch Logs data protection; (iii) the guardrail trace match field carries the raw PII value.all Tier 2; U2 T2 specificallyhttps://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-sensitive-filters.html (retrieved 2026-09-04)PrimaryHigh
5.3.4AWS reference pattern (2026-06-16), "Building a HIPAA-ready generative AI architecture for healthcare on AWS": seven layers — IAM, KMS customer-managed keys ("a second authorization gate beyond IAM"), Guardrails to "detect and redact ePHI before it reaches the foundation model", PrivateLink endpoints, CloudTrail with log-file integrity validation, immutable log storage; explicit warning that model invocation logging persists any ePHI in prompts. Does not cover retention modes.F0, all Tier 2https://aws.amazon.com/blogs/industries/building-a-hipaa-ready-generative-ai-architecture-for-healthcare-on-aws/ (published 2026-06-16)Primary (AWS official blog)High
5.3.5AWS reference pattern for agents (2026-08-14), "Architecting HIPAA-compliant AI agents to safeguard health data with AWS": AgentCore Memory encrypted with customer-managed KMS keys and per-session namespace isolation; Cedar policies on AgentCore Gateway restricting tool invocation; "Amazon Comprehend and Amazon Macie scan every document before ingestion to keep stray PHI out of Retrieval Augmented Generation retrieval"; Guardrails with stricter filters for member-facing agents; CloudWatch Logs data protection masking PHI at ingestion; logs to S3 Object Lock compliance mode with 6-year retention; human-approval decisions logged. This is the closest AWS-published blueprint to U1/U2 Tier 2 and U4 Tier 2.U1 T2, U2 T2, U4 T2, F0https://aws.amazon.com/blogs/publicsector/architecting-hipaa-compliant-ai-agents-to-safeguard-health-data-with-aws/ (published 2026-08-14)Primary (AWS official blog)High
5.3.6AWS "HIPAA compliance for generative AI solutions on AWS" (2025-10-13) names SageMaker AI, Bedrock, Bedrock Knowledge Bases, Bedrock Guardrails, Bedrock Agents and Q Business as HIPAA eligible and stresses "Customers do not automatically inherit HIPAA compliance by using HIPAA eligible services."F0, Tier 2https://aws.amazon.com/blogs/industries/hipaa-compliance-for-generative-ai-solutions-on-aws/ (published 2025-10-13)Primary (AWS official blog)High
5.3.7Bedrock-based PHI detection in images/documents — practitioner case (2026-08-19): Clario uses Bedrock (Claude Sonnet 4.5) + Textract to find PHI in DICOM burned-in pixels, headers and private tags and in PDFs; reported F1 0.975–0.995; human-in-the-loop before redaction. Evidence that an LLM-based detector is a viable Tier 2 add-on to Comprehend Medical for U4, not a replacement for review.U4 T2https://aws.amazon.com/blogs/architecture/how-clario-automates-phi-pii-detection-in-dicom-images-using-amazon-bedrock/ (published 2026-08-19)Practitioner (customer case on AWS blog)Medium
5.3.8Older AWS de-identification catalogue (2022-12-19) "Common techniques to detect PHI and PII data using AWS services": Macie (S3), Comprehend PII redaction, Comprehend Medical + Step Functions de-id workflow, S3 Object Lambda redaction on read, Glue DataBrew masking, Redshift dynamic data masking, CloudWatch Logs data protection, DMS masking. No Bedrock. Still valid as the "classic" U5 de-id pipeline. Related sample repos (angle 1 territory, leads only): aws-samples/aws-ai-phi-deidentification (Comprehend Medical + Textract UI), aws-samples/amazon-comprehend-medical-image-deidentification.U5 T1https://aws.amazon.com/blogs/industries/common-techniques-to-detect-phi-and-pii-data-using-aws-services/ (published 2022-12-19)Primary (AWS blog), datedHigh for content; Medium for currency

6. Region flags for Open Question 3 (default us-east-1 + us-west-2)

Serviceus-east-1us-west-2Note
HealthScribeyesnous-east-1 only (docs, 2026-09-04). U3 must run in us-east-1 or use Connect Health Ambient.
Amazon Connect Healthyesyes2026-03-05 announcement.
HealthLakeyesyesFAQ list.
HealthImagingyesyesGeneral Reference.
HealthOmics (private workflows)yesyes2026-07-20 post.
Comprehend MedicalyesyesThird-party mirror 2026-09-03 (primary page unreadable).
Transcribe MedicalyesyesDeveloper guide table.
Bedrock retention for Fable 5.1Retained in the destination region of cross-region inference; choose a US-only inference profile.

7. Gaps — searched for and not found

  1. Comprehend Medical per-API pricing for DetectPHI, ICD-10-CM and RxNorm — the pricing page presents worked examples; only NERe and SNOMED CT tiers were extractable. Verify in the Pricing Calculator.
  2. Comprehend Medical region list from a primary page — both General Reference slugs tried returned empty; the row uses a third-party mirror dated 2026-09-03.
  3. S3 Tables and Timestream for InfluxDB by-name HIPAA statements — neither is on the eligible list by name; no AWS page names either as eligible; the re:Post thread on S3 Tables returned HTTP 403. Only the general-feature rule covers them.
  4. Amplify compliance documentation page — two docs URLs returned only a title; eligibility rests on the list entry "AWS Amplify Console" plus the per-service eligibility of Gen 2 backend resources.
  5. Services-in-Scope table is rendered client-side and unreadable; the HIPAA tab links to the eligible-services reference, which was read in full instead.
  6. HealthOmics sequence-store / variant-store region list — only the private-workflows list (2026-07-20) was found.
  7. Whether HIPAA is one of Control Catalog's "seven new compliance frameworks" (2025-06 and 2025-11 posts) — not verified.
  8. Bedrock IL4/IL5 — not on any page fetched; dossier sub-claim stays Medium.
  9. Anthropic third-party model terms on Bedrock (https://aws.amazon.com/legal/bedrock/third-party-models/) — not fetched; the retention doc points there for model-specific handling.
  10. Timestream developer-guide compliance page — unreadable; FAQ compliance sentence covers LiveAnalytics only.
  11. No AWS notice retiring or de-emphasising Transcribe Medical or Comprehend Medical was found; the "quiet" judgement is based on What's New silence since 2021-01 / 2020-07 only.

8. Source list (with dates)

Primary — AWS compliance / legal pages

Primary — Bedrock / AgentCore

Primary — health services

Primary — controls

Primary — AWS official blogs (dated)

Practitioner / case study

Internal (cited, not re-researched)

  • research/aws-ai-services-landscape/dossier.md §2.E.4 and F-15 (2026-09-03) — Opus 5 ZDR vs Fable 5.1 aws_review; Connect rename 2026-04-28 (line 35).