Skip to main content

Validation — AWS demo catalog research (2026-09-04)

Generated at build time from research/aws-demo-catalog/validation.md in the repo — edit the source, not this page.

Independent validator pass over comparison.md (C1–C79, X1–X9). I did not read sources/*.md; every check below is my own re-fetch of the cited primary source (or a substitute primary source where the cited one was unreadable), all retrieved 2026-09-04. GitHub metadata comes from the GitHub REST API (pushed_at, license.spdx_id, archived, stargazers_count); README facts from the rendered repo page or raw file.

Verdict key: CONFIRMED = the cited source says what the claim says; UNSOURCED = I could not find the cited support; CONTESTED = I found evidence that conflicts with the claim as written. Where a claim bundles several facts, the verdict applies to the bundle and any failing sub-claim is named in the rationale and repeated in §4 (downgrade list).

Summary: 74 CONFIRMED / 0 UNSOURCED / 4 CONTESTED out of 78 verdict-bearing claims (C59 is a gap placeholder with no claim to validate). Contested: C11 (KB/Guardrails blog attribution), C24 (HealthLake region list understated), C29 (IoT Device SDK for Swift GA date), C46 (sample-healthcare-agents "no PDF intake"). Three CONFIRMED claims carry an unsourced sub-claim that must be removed or reworded: C1 (the quoted "not designed for single-account deployments"), C43 ("Transcribe PHI identification is free"), C69 (cited file path 404s; file exists elsewhere). Four gaps were incidentally closed or narrowed: G5, G13, G14, G16 (§5).


1. Per-claim verdicts

F0 — HIPAA-ready landing zone

C1 — LZA + LZA-for-Healthcare is the only AWS-official F0 artefact; organisation-only; ~US$400–500/month; v1.9.0-e 2025-11-29; pushed 2026-06-18; MIT-0; LZA v1.16.2 9/2026; US$430.22/month. Verdict: CONFIRMED (one quoted phrase UNSOURCED). Rationale: Healthcare README: "latest release v1.9.0-e from 11/29/2025"; "As of September 2022 … between $400-$500 USD per month"; "licensed under the MIT-0 License"; built on Control Tower Management, Audit, LogArchive. API: pushed 2026-06-18, MIT-0, not archived, 20 stars. LZA cost page: "$430.22 (USD) each month". awslabs/landing-zone-accelerator-on-aws release v1.16.2 published 2026-09-02. Organisation requirement confirmed by the LZA Prerequisites page (Organizations with all features; Control Tower auto-deploy or manual) and Mandatory accounts page ("requires these three accounts at minimum"). However, the quoted phrase "not designed for single-account deployments" does not appear in the healthcare README (raw-file search for "single-account", "single account", "not designed"), the LZA README, the solution overview, the prerequisites page, or the LZA FAQ. Treat it as a scout paraphrase, not a quotation; cite the Mandatory-accounts page instead.

C2 — No public "empty single account → HIPAA baseline" example; closest is the startup-security-baseline conformance-pack repo; 2017 Quick Start gone. Verdict: CONFIRMED (absence; spot-checked). Rationale: deploy-conformance-pack-for-aws-startup-security-baseline README: CDK Python, deploys the AWS Startup Security Baseline pack (16 account-level controls), explicitly not the HIPAA pack, MIT-0. GitHub search org:aws-samples patient portal and related absence searches returned 0. Pushed date 2025-03-28 not shown on the page I fetched (not disputed). Quick Start removal not re-tested.

C3 — Control Tower is current: CfCT pushed 2026-07-01; AFT What's New 2026-07-16; v4.0 controls-dedicated 2025-11-21 (750+ controls, existing Organization); LZA released 9/2026; Organization still required. Verdict: CONFIRMED. Rationale: API: aws-control-tower-customizations pushed 2026-07-01, Apache-2.0. What's New 2026-07-16 "AWS Control Tower Account Factory for Terraform now re-applies customizations when accounts move between OUs". What's New 2025-11-21 "AWS Control Tower introduces a controls-dedicated experience": deploy "into their existing AWS Organization", "over 750 managed controls". LZA v1.16.2 2026-09-02.

C4 — Config pack still "Operational Best Practices for HIPAA Security"; template last commit 2025-01-07 (130-rule cap); validated by AWS SAS; "not designed to fully ensure compliance". Verdict: CONFIRMED. Rationale: Doc page title matches; disclaimer verbatim "Conformance Packs, as sample templates, are not designed to fully ensure compliance…"; "validated by AWS Security Assurance Services LLC (AWS SAS)". Commit history for the YAML: last commit 2025-01-07 "Removing S3_BUCKET_LEVEL_PUBLIC_ACCESS_PROHIBITED which is redundant to limit rules to 130 (#433)".

C5 — Security Hub split; standards live in Security Hub CSPM (FSBP, AI Security Best Practices, CIS, NIST 800-53 r5, NIST 800-171 r2, PCI DSS, Resource Tagging, Control Tower service-managed); new Security Hub GA 2025-12-02; no HIPAA-named standard; new Security Hub not on the HIPAA list under its own name. Verdict: CONFIRMED. Rationale: "Standards reference for Security Hub CSPM" lists exactly those eight standards; no HIPAA standard. What's New 2025-12-02 "AWS Security Hub is now generally available with near real-time risk analytics". HIPAA list entry reads "AWS Security Hub CSPM (formerly AWS Security Hub)". Minor: the standards page says "CIS AWS Foundations Benchmark" without "v5"; the What's New does not mention OCSF. Neither affects the claim.

C6 — Macie: 12 PHI identifiers, all keyword-dependent, none in the recommended set (2023-06-27) or the automated-discovery default set (2023-08-02). Verdict: CONFIRMED. Rationale: mdis-reference PHI rows: US_DRUG_ENFORCEMENT_AGENCY_NUMBER, USA_HEALTH_INSURANCE_CLAIM_NUMBER, CANADA_HEALTH_NUMBER, EUROPEAN_HEALTH_INSURANCE_CARD_NUMBER, FINLAND_EUROPEAN_HEALTH_INSURANCE_NUMBER, FRANCE_HEALTH_INSURANCE_NUMBER, UK_NHS_NUMBER, USA_MEDICARE_BENEFICIARY_IDENTIFIER, USA_HEALTHCARE_PROCEDURE_CODE, USA_NATIONAL_DRUG_CODE, USA_NATIONAL_PROVIDER_IDENTIFIER, MEDICAL_DEVICE_UDI = 12, every one "Keyword required: Yes". Recommended-for-jobs page (GA 2023-06-27) and the dynamic automated-discovery default set (2023-08-02) list only Credentials/Financial/PII — no PHI. Useful nuance for F0: the static pre-2023-08-02 automated-discovery set did include all PHI identifiers, so accounts that enabled automated discovery before that date behave differently.

C7 — BAA self-service in Artifact at account or organization scope (management account, all-features org, existing and future members). No catalog service needs extra HIPAA opt-in. Verdict: CONFIRMED ("no extra opt-in" remains Medium — an absence claim I cannot positively verify). Rationale: Artifact org-agreement page: management account "can accept an agreement with AWS on behalf of all AWS accounts in your organization"; organization "must be enabled for all features"; final step "Accept … for all existing and future accounts in your organization".

C8 — Bedrock and Security Hub CSPM compliance pages warn the new sign-up experience is not for regulated workloads. Verdict: CONFIRMED. Rationale: Both pages open verbatim: "Our new AWS sign-up experience is not designed for regulated workloads. … you can sign up for AWS (advanced) or activate advanced features".

C9 — HIPAA whitepaper archived; Healthcare Industry Lens dated 2022-11-17, no revisions. Verdict: CONFIRMED. Rationale: Whitepaper page: "Notice: This whitepaper has been archived. For the latest … see the HIPAA Eligible Services Reference." Lens document-revisions table has a single row: Initial publication, November 17, 2022.

C10 — SRA examples repo is CC-BY-SA-4.0; link, don't fork. Verdict: CONFIRMED. Rationale: Raw LICENSE opens "Creative Commons Attribution-ShareAlike 4.0 International Public License". API reports NOASSERTION (GitHub can't classify CC licences), pushed 2026-09-04, 1152 stars.

C11 — Every named catalog service is on the HIPAA list (page "Last Updated: September 3, 2026"); S3 Tables, Timestream for InfluxDB, Valkey, Bedrock KB/Guardrails/BDA not named; KB and Guardrails "named as eligible in the AWS industries blog 2025-10-13". Verdict: CONTESTED (list facts confirmed; blog attribution not supported). Rationale: List page confirms "Last Updated: September 3, 2026" and every service in the claim, with exact entries worth carrying forward: "Amazon Pinpoint and End User Messaging (formerly Amazon Pinpoint) [excluding Voice Message capabilities and WhatsApp Channel]", "AWS Transcribe [Includes Healthscribe]", "Amazon Timestream", "Amazon SageMaker AI [… excludes Studio Lab, Ground Truth Plus, Public Workforce and Vendor Workforce …]", "AWS Security Hub CSPM (formerly AWS Security Hub)", "AWS Amplify Console", "Amazon ElastiCache". Absent by name: S3 Tables, Timestream for InfluxDB, Valkey, Bedrock Knowledge Bases, Guardrails, Data Automation. Feature rule verbatim: "Unless specifically excluded, generally available features of each of the HIPAA eligible services listed are also considered HIPAA eligible." But the industries blog (2025-10-13) does not state that Knowledge Bases or Guardrails are HIPAA eligible; it says ePHI "can be stored in … Amazon Bedrock Knowledge Bases" and discusses Guardrails as a control. That is a usage statement, not an eligibility statement. Downgrade KB/Guardrails from Medium to Medium-Low: they rest on the feature rule alone, same as BDA.

C12 — Eligibility list is not a lifecycle signal (Forecast, Kendra, Q Business, IoT Events, A2I still listed). Verdict: CONFIRMED. Rationale: All five present on the list page. Corroborated by the 2026-06 "AWS Service Availability Updates" post, which puts Kendra, Q Business, Bedrock Agents Classic, A2I, Clarify, Ground Truth, Model Monitor into maintenance (no new customers from 2026-07-30) while they remain HIPAA-listed.

U1 — Patient portal + companion mobile app

C13 — No AWS-official U1 Tier 1 exists. Verdict: CONFIRMED (absence; spot-checked). Rationale: GitHub search org:aws-samples patient portal → 0; org:aws-samples healthkit → 0. No contrary evidence in any page I fetched.

C14 — Closest components: aws-healthlake-smart-on-fhir (CDK TS, 2024-03-16, no UI/Cognito); sample-intelligent-security-for-healthcare-apis (CloudFormation, 2026-08-14, Cognito MFA + Comprehend Medical redaction + Guardrail, 10–15 min); SMART-on-FHIR workshop unreadable. Verdict: CONFIRMED. Rationale: smart-on-fhir: API pushed 2024-03-16, MIT-0; README: CDK TypeScript (cdk deploy --all), "No UI", external OAuth2 IdP (ORY), no Cognito. intelligent-security: API pushed 2026-08-14, MIT-0, 1 star; README: template.yaml + deploy.sh, "Cognito (MFA-enabled)", "Comprehend Medical redacts PHI before audit logging", "Bedrock Guardrail anonymizes PHI", "Estimated deployment time: 10-15 minutes"; one manual prerequisite (API Gateway CloudWatch Logs role) and optional HealthLake (~$500/month). Workshop page returns only the string "Workshop Studio".

C15 — Gen 2 only supported path; Gen 1 maintenance from 2026-05-01, EOL 2027-05-01; Swift 2.60.2 (2026-09-01), Android 2.41.1 (2026-09-02), Flutter 2.15.0 (2026-08-19), JS 2026-09-01. Verdict: CONFIRMED. Rationale: amplify-cli issue #14881 "⚠️ Amplify Gen 1 is in Maintenance Mode ⚠️", opened 2026-05-14: "Starting May 1, 2026, Gen 1 backends will receive only critical bug fixes and security patches" … "will reach end of life on May 1, 2027". Releases API: amplify-swift 2.60.2 2026-09-01; amplify-android release_v2.41.1 2026-09-02; amplify-flutter v2.15.0 2026-08-19. JS date and Gen 2 GA date (2024-05-06) not re-checked.

C16 — Swift/Android have passkeys and AppSync Events; Flutter has neither (#6094, #6106 open; PR #6851 draft since 2026-04-08); Gen 2 dropped Analytics/Push/Predictions. Verdict: CONFIRMED. Rationale: #6094 "Passwordless Support" opened 2025-03-27, open; #6106 "Appsync Events implementation for flutter SDK" opened 2025-04-04, open; PR #6851 "feat(auth): Add WebAuthn/passkey support across all platforms" opened 2026-04-08, Draft, open. Swift Gen 2 feature matrix: Analytics "No" (custom CDK only), Predictions "No"; Push Notifications and PubSub do not appear on the matrix at all — "dropped as first-class" is a fair reading for Push but is inference, not a matrix row. Swift/Android passkey and Events support not independently re-checked.

C17 — Classic Mobile SDKs EOS 2026-08-01; IoT "Mobile SDKs" docs page still lists them. Verdict: CONFIRMED. Rationale: aws-sdk-ios README: "scheduled to reach End of Support on August 1, 2026"; aws-sdk-android README same, and the repo was archived 2026-08-03. IoT SDKs page still has an "AWS Mobile SDKs" section listing both — and now also lists "AWS IoT Device SDK for Swift" under Device SDKs, which is the supported replacement for the iOS path.

C18 — No AWS doc recommends AppSync vs API Gateway for mobile+web over a container backend; documented split as stated; all HIPAA-listed. Verdict: CONFIRMED (synthesis; Medium stands). Rationale: The cited prescriptive-guidance page is specifically "AWS AppSync Events and API Gateway" (WebSocket use cases) and gives when-to-use bullets, no mobile recommendation. AppSync and API Gateway on the HIPAA list. Amplify REST-API doc not re-fetched.

C19 — Cognito: Managed Login, passkeys/OTP on Essentials (default); OTP-first-factor incompatible with required MFA; passkey counts as MFA only with user verification required; passkeys cannot be a second factor to password; mobile needs .well-known association. Verdict: CONFIRMED. Rationale: Auth-flows page verbatim: "One-time password (OTP) authentication flows aren't compatible with required multi-factor authentication (MFA)"; "Passkey authentication can satisfy multi-factor authentication (MFA) requirements when your user pool has FactorConfiguration set to MULTI_FACTOR_WITH_USER_VERIFICATION"; "Passkeys cannot be used as a second factor to password sign-in"; "for mobile apps, a passkey can only be used if the app path is present in the .well-known association files". Feature-plans page: "The default plan selection for new user pools is Essentials"; passkey and passwordless OTP are "Essentials + Plus". The three dates (2024-11-22, 2025-04-22, 2026-07) not re-checked.

C20 — Pinpoint EOS 2026-10-30; no new customers since 2025-05-20; serverless-patient-engagement-stack depends on it. Verdict: CONFIRMED. Rationale: Migration guide: "end support for Amazon Pinpoint, effective October 30, 2026. Amazon Pinpoint will no longer accept new customers beginning May 20, 2025." FAQ carries the same EOS date. Repo README: "leverages the powers of Amazon Pinpoint and Amazon Connect"; API pushed 2025-04-01, MIT-0; IaC is CDK TypeScript.

C21 — Successors: push/SMS/voice/OTP → End User Messaging (Pinpoint send-messages API); email → SES; engagement → Connect Customer campaigns + Customer Profiles; events → Kinesis; In-App has no successor; push not native in campaigns; SNS mobile push valid but not the named successor. Verdict: CONFIRMED (one nuance). Rationale: Migration guide verbatim: "APIs related to SMS, voice, mobile push, OTP, and phone number validate are not impacted by this change and are supported by AWS End User Messaging"; email → SES; engagement → "Amazon Connect Customer outbound campaigns" and "Customer Profiles"; "events collection and mobile analytics … Amazon Kinesis"; "Unavailable features … In-App Messaging". EUM Push send-message reference uses aws pinpoint send-messages --application-id …. SNS mobile push page is current with no deprecation notice. Nuance the comparator omitted: the guide says push "notifications are not natively supported in campaigns. However, you can send push notifications through journeys using a Lambda action with Amazon Connect Customer push templates" — so Connect Customer does have a push path via journeys.

C22 — U1 Tier 2: no example; scaffolding = HCLS Agents Toolkit (AgentCore + Strands, 2026-09-03, 268 stars, MIT-0, life-science skew), sample-healthcare-agent-with-agentcore-on-aws (2026-08-03, SageMaker endpoint), public-sector blueprint blog 2026-08-14. Verdict: CONFIRMED. Rationale: Toolkit API: pushed 2026-09-03, MIT-0, 268 stars; README: "building with the Strands framework and deploying to Amazon Bedrock AgentCore", no action groups; examples are genomics/drug/trials/biomarker agents. Agent sample: API pushed 2026-08-03, MIT-0, 0 stars; README: deploys to AgentCore Runtime via agentcore deploy (smolagents), model_type: "sagemaker" → "Bio-ELECTRA on SageMaker endpoint" marked manual setup; no CDK/CFN. Blog 2026-08-14 confirms KMS-encrypted AgentCore Memory, Cedar on Gateway, Comprehend + Macie pre-ingestion scans, S3 Object Lock compliance-mode logs.

C23 — U1 Tier 3: nothing public; generic Pipelines/Registry CDK sample 2026-07-28. Verdict: CONFIRMED (absence; spot-checked). Rationale: amazon-sagemaker-pipeline-deploy-manage-100x-models-python-cdk API pushed 2026-07-28, MIT-0; README: four CDK stacks, Pipelines + Model Registry + endpoints. GitHub search org:aws-samples readmission returns only the 2021/2022 repos.

C24 — HealthLake GA and shipping (2026-03 CCDA agent preview, 2026-05 CMS-0057-F, 2026-07 resource matching preview); "us-east-1 and us-west-2"; US$0.27/data-store-hour. Verdict: CONTESTED (region statement understated). Rationale: Pricing page: "You are charged $0.27 per Data Store hour" (≈US$197/month). What's New posts found: 2026-03-05 data-transformation agent (Preview), 2026-05 CMS-0057-F, 2026-07 resource matching (Preview). But the HealthLake FAQ lists seven regions: "US East (N. Virginia), US East (Ohio), US West (Oregon), Asia Pacific (Mumbai), Europe West (London), Europe (Ireland), and Asia Pacific SouthEast (Sydney)". Both brief defaults are covered, so nothing changes for the build, but the comparison should not present HealthLake as a two-region service (it is HealthScribe that is single-region).

C25 — Location Service active (seven 2026 posts); Device Farm active (last What's New 2025-11-21) but us-west-2 only. Verdict: CONFIRMED. Rationale: Web search surfaced seven Amazon Location What's New posts dated 2026-03 through 2026-08. Device Farm endpoints page lists a single row: us-west-2. Device Farm What's New 2025-11-21 (managed Appium endpoint) confirmed. Neither service appears in the 2026-06 service-availability (maintenance) post.

U2 — Remote patient monitoring at scale

C26 — No end-to-end RPM example; no AWS HealthKit/Health Connect guidance. Verdict: CONFIRMED (absence; spot-checked). Rationale: GitHub search org:aws-samples "remote patient monitoring" → 0; org:aws-samples healthkit → 0.

C27 — Component repos with dates/licences as listed; aws-appsync-iot-core-realtime-dashboard is Amplify Gen 2. Verdict: CONFIRMED. Rationale: API: greengrass-foundations pushed 2026-07-23 MIT-0 (README: CDK v2 TypeScript); ec2-device-farm pushed 2026-08-30 Apache-2.0 (README: CDK v2, simulated fleet); flink-keyed-RCF pushed 2025-12-19 MIT-0 (README: no IaC); deepar-mlops pushed 2025-04-10 MIT-0; appsync-iot dashboard pushed 2026-09-03, MIT-0, 126 stars, README: "this project has been updated to use Amplify Gen2", npx ampx sandbox. transactional-datalake-…-iceberg not re-checked.

C28 — No IoT Core → Timestream for InfluxDB sample with IaC; InfluxDB not on the HIPAA list by name. Verdict: CONFIRMED. Rationale: List page: "Amazon Timestream" only; "Timestream for InfluxDB" absent. GitHub search org:aws-samples timestream influxdb → 0.

C29 — Phone → IoT Core path (Cognito identity + IAM role + IoT policy); IoT Device SDK for Swift GA 2026-06-01 (iOS 16+, MQTT5, Shadow/Jobs/Fleet Provisioning, Apache-2.0); Android via Java v2; no Amplify PubSub on Swift/Android. Verdict: CONTESTED (date and two attributes). Rationale: IoT Cognito-identities doc verbatim: "in addition to the IAM policy attached to the identity pool, you must attach an AWS IoT policy to an Amazon Cognito Identity … use the AttachPolicy API". IoT SDKs page confirms Java v2 Android support. aws/aws-iot-device-sdk-swift is Apache-2.0. But the What's New "AWS IoT Device SDK for Swift is now generally available" is dated June 24, 2026, not 2026-06-01, and the post names macOS/iOS/tvOS/Linux, Shadow/Jobs/Fleet Provisioning and TLS 1.3 without stating "iOS 16+" or MQTT5 (MQTT 5 is stated on the IoT SDKs docs page). Fix the date; source the iOS-version floor from the SDK README if it is to be kept.

C30 — HealthKit / Health Connect on-device only; Apple 5.1.3; Health Connect background reads + sync; cleverdevil/healthlake archived 2022, no licence. Verdict: CONFIRMED. Rationale: Apple guideline 5.1.3(ii): apps "may not store personal health information in iCloud". Health Connect guide: on-device store; "Background reads … even when the app is running in the background"; sync functionality. API: cleverdevil/healthlake archived, pushed 2022-06-08, licence null.

C31 — BLE Swift app: CDK v1→v2 on 2026-06-09, but Podfile pins Amplify ~>1.0 + AWSIoT + AWSMobileClient. Verdict: CONFIRMED. Rationale: Commits API: four commits dated 2026-06-09 ("fix: migrate CDK v1 to v2, resolve all 93 security vulnerabilities", "fix: scope IoT policy and IAM role to least-privilege topics", two merges) after the 2021-08-17 initial commit. BLEX/Podfile verbatim: pod 'Amplify', '~> 1.0', pod 'Amplify/Tools', '~> 1.0', pod 'AmplifyPlugins/AWSCognitoAuthPlugin', '~> 1.0', pod 'AWSIoT', pod 'AWSMobileClient'. Note repo pushed_at is 2026-08-04 (later than the last main commit — likely a branch push); README not re-read.

C32 — U2 Tier 2 no example; Guardrails PII filter does not evaluate tool I/O. Verdict: CONFIRMED (second half via C74).

C33 — Edge Manager EOL 2024-04-26 (ONNX + Greengrass v2 recommended); the two Greengrass ML samples cannot be linked; Strands SLM-at-edge Guidance 2025-10-27. Verdict: CONFIRMED. Rationale: Edge EOL page: "Starting in April 26, 2024, you can no longer access Amazon SageMaker Edge Manager"; "For a cross-platform edge runtime, use ONNX … For edge deployments and monitoring use AWS IoT Greengrass V2". greengrass-v2-sagemaker-edge-manager-python README depends on aws.greengrass.SageMakerEdgeManager (not archived, but dead dependency). amazon-sagemaker-aws-greengrass-custom-timeseries-forecasting archived 2024-07-26, uses IoT Analytics and Greengrass v1 console. AI-agents-to-device-fleets Guidance: API pushed 2025-10-27, created 2025-09-29, MIT-0; README: Strands agents + SLM via Ollama on Greengrass.

C34 — Flink→SageMaker pattern exists generically (fraud, KDA naming); Greengrass listed without version qualifier. Verdict: CONFIRMED. Rationale: README: credit-card fraud, "Kinesis Data Analytics for Apache Flink (KDA Flink)", XGBoost "as an Amazon SageMaker endpoint", MIT-0. List entry: "AWS IoT Greengrass".

U3 — Ambient clinical documentation

C35 — HealthScribe GA 2023-11-27, GIRPP 2025-02, eligible under "AWS Transcribe [Includes Healthscribe]", us-east-1 only, US$0.10/min, en-US, banner to Connect Health Ambient; sup-hcls-… ships a Transcribe fallback. Verdict: CONFIRMED. Rationale: Developer guide: banner "Introducing Amazon Connect Health Ambient agent"; "AWS HealthScribe is available in the US East (N. Virginia) region"; "Supported Language: US English (en-US)". Pricing: "$0.10 per minute", region list shows only US East (N. Virginia). What's New 2023-11-27 GA and 2025-02 GIRPP both located. sup-hcls-generate-clinical-notes-with-ai README: "an option for the same use case with Amazon Transcribe and Transcribe Medical for regions where HealthScribe is not yet available"; API pushed 2024-07-23, MIT-0.

C36 — Transcribe Medical and Comprehend Medical quiet, not retired; sample activity stopped (medical-transcription-analysis 2023-07-18; amazon-comprehend-medical-fhir-integration archived 2024-01-22). Verdict: CONFIRMED (one date discrepancy). Rationale: Neither service appears in the 2026-06 service-availability maintenance/sunset post; docs live. API: medical-transcription-analysis pushed 2023-07-18. amazon-comprehend-medical-fhir-integration page banner: "archived by the owner on Jul 24, 2024" — not 2024-01-22 as the comparison states; immaterial to the verdict. Comprehend Medical's doc history shows ICD-10-CM model updates on 2025-02-10 and 2025-08-05, so "quiet" is right but it is still receiving ontology refreshes. Last-What's-New dates (2021-01 / 2020-07) not independently re-derived.

C37 — Amazon Connect Health GA 2026-03-05, HIPAA-eligible, us-east-1 + us-west-2; GA: verification, ambient; preview: appointment mgmt, insights, coding; dossier's 2026-04-28 is the rename post. Verdict: CONFIRMED. Rationale: What's New dated Mar 5, 2026: "now generally available", "HIPAA-eligible", "US East (N. Virginia) and US West (Oregon)"; feature split as stated. Product page today: "Patient verification (generally available)", "Ambient documentation (generally available)", "Appointment management (preview)", "Patient insights (preview)", "Medical coding (gated preview)". (A first, loosely-prompted fetch of the product page mis-summarised coding as GA; the targeted re-fetch shows the exact label "gated preview".) List page has "Amazon Connect Health". X9 resolution agreed.

C38sample-amazon-connect-health-unified-clinical-workflow: Bedrock Agents classic with 6 action groups; needs registered Connect instance + Connect Health domain; 3 stacks; coding gated preview; sibling point-of-care not agents. Verdict: CONFIRMED (and G16 closed). Rationale: README: "Amazon Bedrock Agents reason over the question, call action groups (one Lambda per domain task)"; six action groups (patient summary, recent visit, A1c trend, overdue A1c, no-show, diabetic risk); prerequisites include "A registered Amazon Connect instance"; three stacks (shared infra → guardrail → provider); "Medical Coding capability … is currently in gated preview". API pushed 2026-08-31, MIT-0, 3 stars. G16: sample-amazon-connect-health-point-of-care README uses direct Bedrock synthesis ("Amazon Bedrock synthesizes the Patient Insights output into a clinician-ready pre-visit narrative"), no Agents/action groups; CloudFormation; prerequisites "An Amazon Connect Health domain and subscription" + HealthLake datastore; pushed 2026-03-31, MIT-0.

C39sample-healthscribe-bedrock-clinical-analysis: CDK, Fargate, React+Vite, Cognito, CloudFront, HealthScribe streaming, 12 specialists, deploy.sh, ACM cert; no HealthLake/Comprehend Medical. Verdict: CONFIRMED. Rationale: README: "All infrastructure managed by AWS CDK" (TypeScript), Fargate WebSocket service behind ALB, React + Vite on S3/CloudFront, Cognito, "12 AI Domain Specialists" orchestrated by Step Functions, ./deploy.sh dev with ACM certificate ARN; no HealthLake or Comprehend Medical mentioned. API pushed 2026-04-07, MIT-0, TypeScript, 4 stars.

C40 — Diagnosis-codes Guidance (CDK Python, MIT-0, pushed 2026-04-13, 4 stars) covers HealthScribe → S3 → Comprehend Medical → Bedrock Converse + OpenSearch Serverless KB → Lake Formation/Athena/QuickSight; cost US$495.89/month dominated by OpenSearch (US$350); no review UI/Step Functions/write-back. Verdict: CONFIRMED (with a scope caveat). Rationale: API: pushed 2026-04-13, MIT-0, not archived, 4 stars (language: Jupyter Notebook). Guidance page steps name HealthLake, HealthScribe, Comprehend Medical, Bedrock Converse, OpenSearch vector DB, Lake Formation, Athena, QuickSight and link to this repo. README: CDK Python; "approximately $500 per month" as of April 2025 with OpenSearch Serverless at $350.42; no review UI, no Step Functions, no HealthLake write-back. Caveat: the README's implemented services are S3, Lambda, Comprehend Medical, Bedrock (Claude), OpenSearch Serverless — HealthScribe, Lake Formation, Athena and QuickSight are on the page's diagram, not evidently in the code. The fork base is narrower than the page suggests (bears on X4).

C41aws-healthscribe-demo is Amplify Gen 1. Verdict: CONFIRMED. Rationale: package.json: "aws-amplify": "^6.14.1", "@aws-amplify/ui-react": "^6.10.0", no @aws-amplify/backend. API pushed 2025-04-08, MIT-0, 60 stars. docs/deploy.md not re-read.

C42 — U3 Tier 3: none; only LLM-as-judge / evaluation notebooks. Verdict: CONFIRMED (absence; no contrary evidence; not exhaustively re-searched).

C43 — Comprehend Medical DetectPHI detects, does not redact, "does not meet the requirements for de-identification"; Transcribe (Medical) PHI identification is free in all regions. Verdict: CONFIRMED (second sentence UNSOURCED). Rationale: DetectPHI doc: returns entities with offsets and scores (no redaction); "we recommend that you use additional human review or other methods to confirm the accuracy of detected PHI"; entities "don't map 1:1 to the list specified by the Safe Harbor method". FAQ verbatim: "does not meet the requirements for de-identification of protected health information in accordance with HIPAA." Transcribe PHI "free": the Transcribe pricing page does not mention PHI identification at all (it lists PII redaction as a paid add-on for standard Transcribe); the PHI-identification doc page says nothing about price. Silence is not a source — drop or re-source the "free" statement.

U4 — Intelligent document intake

C44 — GenAI IDP Accelerator (pushed 2026-09-04, 302 stars, MIT-0): one-click CFN us-east-1/us-west-2/eu-central-1, CDK/Terraform alternates, Pattern 1 BDA, Pattern 2 Textract→Bedrock, built-in HITL (not A2I), MLflow, Cognito+WAF UI, MCP via AgentCore Gateway. Verdict: CONFIRMED. Rationale: API: pushed 2026-09-04T18:12Z, MIT-0, 302 stars. README: regions us-west-2/us-east-1/eu-central-1; "Pattern 1 (BDA Mode)" vs "Pattern 2 (Pipeline Mode): OCR → Bedrock Classification → …"; "Human-in-the-Loop (HITL): Built-in review system" with no A2I reference; MLflow optional; Cognito + WAF; "Model Context Protocol integration … through AWS Bedrock AgentCore Gateway"; CDK and Terraform versions linked. v0.6.6 not verified.

C45 — IDP Guidance page is AgentCore Runtime/Identity/Gateway + Strands + Textract + ECS dashboard; Security pillar points to Comprehend Medical PHI; sample repo pushed 2026-05-04, 244 stars; repo contents unverified. Verdict: CONFIRMED (and G13 narrowed). Rationale: Guidance page steps 3–11 name AgentCore Runtime, Identity (Cognito workload token), Gateway (MCP), Strands Agents, Textract, ECS chat dashboard, AgentCore Observability; Security pillar: "use Amazon Comprehend Medical PHI identification and redaction options". "Go to sample code" → aws-samples/aws-ai-intelligent-document-processing; API pushed 2026-05-04, 244 stars. G13: the repo README does describe "Agentic Intelligent Document Processing" with "Multi-agent orchestration with specialized agents (Analyzer, Matcher, Extractor, Validator, Troubleshooter)" and lists Amazon Bedrock AgentCore — so the page and repo are aligned at README level (code not inspected). Licence flag: README says "licensed under the MIT-0 License" but GitHub reports no detected licence (spdx_id: null); check the LICENSE file text before forking. Also, the page's Operational Excellence pillar still describes a Step Functions/Comprehend architecture — legacy text.

C46sample-healthcare-agents (pushed 2026-09-03, CDK TS, Amplify React + Cognito, AgentCore Runtime + Gateway, Strands, HealthLake, Comprehend Medical, B2B Data Interchange 837P, CDS Hooks; cdk deploy --all) is full for U4 Tier 2; "no PDF intake". Verdict: CONTESTED (one attribute). Rationale: API: pushed 2026-09-03, MIT-0 (repo language Python — the agents; infra is TypeScript). README: infra-cdk/ TypeScript, cdk deploy --all; Amplify-hosted React, Cognito OIDC, AgentCore Runtime + Gateway, Strands (LangGraph alternative), HealthLake FHIR R4, Comprehend Medical, B2B Data Interchange EDI 837P, CDS Hooks; six workflows (prior auth, eligibility, coding, claims assembly, claims submission, appeals). But "no PDF intake" is wrong as written: the Prior Authorization agent exposes upload_policy_document / list_policy_documents tools for uploading and searching payor-policy PDFs into a knowledge base. Correct statement: no patient/clinical document IDP intake; has policy-PDF ingestion.

C47 — BDA is the 2026 default in AWS code; Textract on the list by name, BDA only via the feature rule; two official workshops. Verdict: CONFIRMED. Rationale: List: "Amazon Textract" present; "Bedrock Data Automation" absent. Accelerator Pattern 1 = BDA (C44). Workshop "Document Processing with Amazon Bedrock Data Automation" located at catalog.us-east-1.prod.workshops.aws/workshops/c64e3606-… (search result; page itself client-rendered). The other workshop title not re-checked.

C48sample-scalable-…-bedrock-data-automation uses A2I + Ground Truth; amazon-textract-idp-cdk-constructs stale (2024-04-29). Verdict: CONFIRMED. Rationale: README title "Processing Documents with a Human-in-the-Loop using Amazon Bedrock Data Automation and Amazon A2I"; steps reference Ground Truth "Labeling workforces" and a2i-create-flow-definition. API pushed 2026-07-28, MIT-0. Textract constructs API pushed 2024-04-29, MIT-0.

C49aws-ai-phi-deidentification (2025-04-23, CDK, Textract → Comprehend Medical → redaction UI) only deployable de-id pipeline; Clario blog 2026-08-19, F1 0.975–0.995, HITL. Verdict: CONFIRMED. Rationale: API pushed 2025-04-23, MIT-0; description "De-identify medical documents with Amazon Comprehend Medical and Amazon Textract with a web based UI". Clario blog 2026-08-19: F1 0.9775 (PDF text), 0.9750 (DICOM burned-in), 0.9951 (DICOM tags); "a human expert can review the findings before anyone makes irreversible changes". "Only deployable de-id pipeline" is an absence claim not re-searched.

C50 — U4 Tier 3: none; Accelerator classifies with Bedrock. Verdict: CONFIRMED (absence; Bedrock classification confirmed in C44; not exhaustively re-searched).

C51 — U4 best-covered, lowest new-build value. Verdict: CONFIRMED (judgement consistent with C44–C46 as verified).

C52 — "Ingesting PDF and Image Files to AWS HealthLake" Guidance is architecture-only; Intelligent Healthcare Systems workshop unreadable. Verdict: CONFIRMED. Rationale: Guidance page: CloudFormation + Lambda + S3 + HealthLake architecture, no sample-code/GitHub link. Workshop pages are client-rendered (C67).

U5 — Population health analytics and risk models

C53 — Multi-Modal Guidance (pushed 2024-12-17, MIT-0; one-click CFN SageMaker domain + notebooks; HealthOmics/HealthLake/HealthImaging → Lake Formation → Athena → QuickSight; Feature Store → AutoGluon → endpoint; Synthea; no S3 Tables/Iceberg, no de-id, no cost table). Verdict: CONFIRMED. Rationale: API pushed 2024-12-17, MIT-0. README: "create the Amazon SageMaker domain by 1-click deployment", sequential notebooks, all named services, Synthea Coherent dataset, no cost table, no Iceberg/S3 Tables, no de-identification. Real-time endpoint implied, not explicit.

C54 — Patient Entity Resolution Guidance (2025-09-11) + workshop = EMPI component. Verdict: CONFIRMED (workshop not verifiable). Rationale: API pushed 2025-09-11, MIT-0; README: AWS Entity Resolution matching over HealthLake patient identifiers, CloudFormation + Lambda.

C55 — S3 Tables not on the list by name; no healthcare sample lands data in S3 Tables. Verdict: CONFIRMED. Rationale: List page: S3 Tables absent ("Amazon Simple Storage Service (S3)" and "Amazon S3 Glacier" only). re:Post thread not re-tried; absence of samples not exhaustively re-searched.

C56 — Quick is HIPAA-listed; U5 artefacts still say QuickSight; healthlake-workshop archived (pushed 2026-01-29). Verdict: CONFIRMED. Rationale: List: "Amazon Quick". Multi-Modal README and diagnosis-codes Guidance page both say QuickSight. API: healthlake-workshop archived, pushed 2026-01-29, MIT-0.

C57 — U5 Tier 3 healthcare models all 2021–2022; generic MLOps spine current. Verdict: CONFIRMED. Rationale: Search org:aws-samples readmission: amazon-sagemaker-data-wrangler-hospital-readmission-prediction pushed 2021-10-25; aws-ml-readmission-prediction pushed 2022-04-18 (README: Synthea, Glue/Athena/SageMaker XGBoost). amazon-healthlake-patient-outcome-prediction archived (notice dated 2022-09-06, archived 2022-09-07). 100x-models CDK pushed 2026-07-28. Clean Rooms ML samples not checked.

C58extract-medical-insights-from-amazon-healthlake-with-bedrock (2024-11-05, Apache-2.0, Streamlit, no IaC, text-to-SQL). Verdict: CONFIRMED. Rationale: API pushed 2024-11-05, Apache-2.0. README: streamlit run app_fhir.py, Bedrock generates SQL for Athena over FHIR resources, manual setup steps, no CDK/CFN.

C59 — Clarify successor: no scout answered. Verdict: N/A (gap). See §5 G5 — I closed it.

U6 — Contact center with AI agents

C60 — Connect Health makes U6 T1 verification/scheduling product features; sample-healthcare-realtime-eligibility (2026-03-03) plugs into it. Verdict: CONFIRMED (and G14 closed). Rationale: Product page capability labels as in C37. API: eligibility sample pushed 2026-03-03, MIT-0; description: RTE insurance verification Lambda for Amazon Connect Health. G14: pricing page: Ambient documentation "$99/user/month subscription for up to 600 encounters per user/month", overage "$0.036 per minute"; Patient verification $0.15 per action (end-to-end patient conversation); free tiers 60-day trial / 30,000 actions.

C61 — Connect and Lex HIPAA-listed. Verdict: CONFIRMED. List has "Amazon Connect" and "Amazon Lex".

C62sample-amazon-connect-bedrock-agent-voice-integration uses Bedrock Agents classic; CDK TS; Connect + Lex. Verdict: CONFIRMED. Rationale: README: "Create and configure an Amazon Bedrock Agent with custom actions", "The Bedrock Agent orchestrates … calls appropriate actions implemented in AWS Lambda", "Integrate the Bedrock Agent with Amazon Connect via Amazon Lex"; CDK TypeScript stacks (lex-chat-stack.ts, connect-call-stack.ts). API pushed 2025-11-18, MIT-0. voice-enabled-patient-diary not checked.

C63sample-Nova-Sonic-AgentCore-Healthcare-Call-Center (2026-05-21, CDK Python, MIT, AgentCore + Nova 2 Sonic, no Connect). Verdict: CONFIRMED. Rationale: API pushed 2026-05-21, licence MIT (not MIT-0), 4 stars. README/file tree: CDK Python (infrastructure/app.py), "Amazon Bedrock AgentCore" runtime, "Amazon Nova 2 Sonic", direct WebSocket — no Amazon Connect. Note GitHub's language field says TypeScript (frontend); the IaC is Python as the comparison states.

C64 — No healthcare-specific Connect workshop/Guidance; U6 T3 forecasting is a Connect feature. Verdict: CONFIRMED (absence; no contrary evidence; workshop catalog unreadable, not re-searched).

C65 — Pinpoint engagement successor = Connect Customer campaigns + Customer Profiles, so U1 reminders and U6 share a service. Verdict: CONFIRMED (inference; premises verified in C20/C21).

P0 — Education portal

C66 — Workshop Studio repo contract (contentspec.yaml v2.0, accountSources: [WorkshopStudio, CustomerProvided], participant IAM policy, region config, cloudformationTemplates[]); Builder Center discovery 2025-11-18. Verdict: CONFIRMED. Rationale: rancher-on-aws-workshop/contentspec.yaml: version: 2.0; account sources WorkshopStudio and CustomerProvided; static/rke2-eks-cluster-workshop.yaml CloudFormation template; participant role with static/iam-policy.json + managed policies; region us-east-1. What's New 2025-11-18 "Workshops now available in AWS Builder Center". workshops.aws/categories redirect and the jailbreak repo not re-tested.

C67 — Workshop Studio / Builder Center pages unreadable by the fetch tool. Verdict: CONFIRMED. Rationale: The SMART-on-FHIR workshop URL returns only the title "Workshop Studio" with no body.

C68 — Solutions Library pages moved to docs.aws.amazon.com/solutions/<slug>/ (301); Guidance page anatomy; cost/deploy live in repo README; "not for production accounts" disclaimer. Verdict: CONFIRMED. Rationale: aws.amazon.com/solutions/implementations/landing-zone-accelerator-on-aws/ and …/solutions/guidance/app-based-condition-monitoring-… both 301 to docs.aws.amazon.com/solutions/…. Diagnosis-codes and IDP Guidance pages show overview → diagram + numbered steps → "Go to sample code" → six pillar paragraphs → related content → "Read usage guidelines". Disclaimers page verbatim: "You should not use this AWS Content in your production accounts, or on production or other critical data."

C69 — aws-samples conventions; serverless-patterns example-pattern.json is the smallest proven docs-from-metadata contract. Verdict: CONFIRMED (cited path wrong). Rationale: The cited root-level example-pattern.json returns 404; the file lives at serverless-patterns/_pattern-model/example-pattern.json (alongside template.yaml, README.md, src/). MIT-0 default is consistent with every aws-samples repo I checked except sample-Nova-Sonic-… (MIT) and aws-ai-intelligent-document-processing (undetected licence, README says MIT-0). No public template repo found by me either.

C70 — HCLS Toolkit GitHub-Pages site (Astro) and eks-workshop-v2 (Docusaurus + Terraform) are the repo-generated-site examples; P0 is build-new; MADR 4 recommended. Verdict: CONFIRMED. Rationale: aws-samples.github.io/amazon-bedrock-agents-healthcare-lifesciences/ exists, has a Catalog dashboard and Developer Guide, assets under /_astro/ (Astro). eks-workshop-v2 README: Docusaurus site in website, Terraform in terraform, Apache-2.0. MADR current major is 4.0.0 (2024-09-17). Backstage TechDocs not checked.

C71 — Comparators: Serverless Land, Google Jump Start Solutions (behind console sign-in), Azure Architecture Center; Health AI Hub / awsaccelerators demos without deploy links. Verdict: CONFIRMED (Practitioner tier; partial check). Rationale: Google's JSS guide URL now 301s to console.cloud.google.com/products/solutions/catalog, which confirms "behind console sign-in". Serverless Land's contract is the _pattern-model JSON (C69). Azure Architecture Center, Health AI Hub and awsaccelerators not checked.

Cross-cutting

C72 — F-15 closes: Bedrock FAQ/security page say content not used to improve base models nor shared with providers; compliance list as stated; IL4/IL5 not seen. Verdict: CONFIRMED. Rationale: FAQ verbatim: "your content is not used to improve the base models and is not shared with any model providers"; FAQ compliance: HIPAA eligible, SOC 1/2/3, ISO 9001/27001/27017/27018/27701/22301/20000, GDPR, FedRAMP Moderate, CSA STAR Level 2. Security page: "FedRAMP High authorized service in the AWS GovCloud (US-West) Region"; IL4/IL5 absent. The "per-region model deployment accounts" phrase was not on either page I fetched (data-protection page not fetched) — keep that detail at Medium.

C73 — Bedrock retention modes; Fable 5/5.1 require aws_review (30-day retention, AWS human review of flagged traffic); Opus 4.8 allows none; EFS customers ZDR through 2026-12-31; SCP keys; destination-region storage. Verdict: CONFIRMED (verbatim on every element). Rationale: Data-retention page: mode table none < default < aws_review < provider_data_share; "Claude Fable 5 and Claude Fable 5.1 require human review (allowed_modes: ["aws_review", "provider_data_share"])"; "Claude Opus 4.8 … permits none"; "retained within the AWS boundary for up to 30 days"; SCP examples with bedrock-mantle:DataRetentionMode and bedrock:DataRetentionMode; "retained inputs and outputs are stored in destination regions". Abuse-detection page: "Classifier-flagged traffic will be subject to potential human review performed by AWS"; "Enterprise Frontier Safeguards program will receive ZDR through December 31, 2026". Design inference stays Medium.

C74 — Guardrails sensitive-information filter evaluates model text only; tool-use note verbatim; logs keep original request; trace match carries raw PII; only CA/UK health-number built-ins. Verdict: CONFIRMED. Rationale: Page note verbatim: "In tool use (function calling) workloads, it does not evaluate … toolUse.inputtoolResulttoolSpec.description, toolSpec.inputSchema". Second note: "the input field in Amazon CloudWatch Logs always contains the original, unmodified request regardless of guardrail intervention"; "The match field … contains the original PII value". Built-in health types: CA_HEALTH_NUMBER, UK_NATIONAL_HEALTH_SERVICE_NUMBER only; no US MRN/Medicare/NPI.

C75 — AgentCore Gateway Policy (Cedar) and Lambda interceptors (blog 2026-06-01); RESPONSE interceptors can integrate with Guardrails for PII redaction; all target types. Verdict: CONFIRMED. Rationale: Blog dated 01 JUN 2026; Cedar permit/forbid over principal/action/resource; REQUEST interceptor "full read/write access to headers and body"; "You can also integrate with services such as Amazon Bedrock Guardrails for use cases like personally identifiable information (PII) redaction"; "Interceptors work with all Gateway target types including Lambda functions, OpenAPI endpoints, and MCP servers".

C76 — Security Hub CSPM AI Security Best Practices standard; HIPAA pairing = FSBP + NIST 800-53 r5 + Config HIPAA pack. Verdict: CONFIRMED. Rationale: Standards page: "AI Security Best Practices … covering domains such as network isolation, encryption, VPC placement, and AWS KMS key usage". Pairing is a recommendation, consistent with the page's "no HIPAA standard" state.

C77 — Retired-service dependents list; HCLS toolkit safe. Verdict: CONFIRMED. Rationale: Each dependency re-verified from its README: Pinpoint (patient-engagement), Bedrock Agent custom actions (Connect voice sample), A2I + Ground Truth (BDA HITL sample), aws.greengrass.SageMakerEdgeManager component (Greengrass v2 sample), IoT Analytics + Greengrass v1 (archived forecasting sample), six action groups (Connect Health unified workflow), Amplify v1 + AWSIoT/AWSMobileClient pods (BLE app). amazon-archives/medical-mobile-iot-with-aws: archived, pushed 2020-07-27 (its KDA use not re-checked; description is generic). Last-mile BLE Guidance (app-based-condition-monitoring-for-last-mile-logistics-on-aws): architecture says "Amazon Timestream" with no flavour stated — "likely LiveAnalytics" is inference; Android BLE gateway → IoT Core confirmed; no sample-code link on the page. HCLS toolkit: Strands + AgentCore, no classic Agents.

C78 — Region constraints converge on us-east-1. Verdict: CONFIRMED (derivative). HealthScribe us-east-1 only (C35) is the binding constraint; HealthLake is in seven regions (C24), which loosens rather than tightens the picture.

C79 — Licence census. Verdict: CONFIRMED (two additions). Rationale: Apache-2.0 confirmed on landing-zone-accelerator-on-aws, aws-greengrass-ec2-device-farm, extract-medical-insights-…, eks-workshop-v2, aws-iot-device-sdk-swift; MIT on sample-Nova-Sonic-…; CC-BY-SA-4.0 on SRA examples and on medical-mobile-iot-with-aws (root LICENSE is CC BY-SA 4.0 for the whole repo, not just docs); no licence on cleverdevil/healthlake. Add: aws-ai-intelligent-document-processing has no GitHub-detected licence (README claims MIT-0). Clean Rooms sibling not checked.


2. Contradictions — do I agree with the comparator's resolution?

XComparator resolutionValidator view
X1Partly resolved: model-call Guardrails don't cover tool I/O; achievable via Gateway interceptors + Cedar + logs data protection.Agree. Both primary texts re-fetched verbatim (C74, C75). One addition: the Clarify availability-change page independently describes Guardrails as runtime PII redaction for model traffic only, consistent with the scope limit.
X2Resolved: EUM Push / SNS for push; SES email; Connect Customer engagement; Kinesis analytics.Agree, with one nuance the comparator missed: Connect Customer journeys can send push via a Lambda action with Connect Customer push templates (migration guide "Unavailable features"). The residual caveat about the Pinpoint application resource surviving 2026-10-30 stands — AWS text names the APIs, not the resource.
X3Partly resolved; unified-workflow sample is worse than "near-full".Agree. README re-read confirms Bedrock Agents classic (six action groups) and the Connect-instance prerequisite. G16 closed: the point-of-care sibling is not Agents-based, but still needs a Connect Health domain and subscription. Connect Health pricing (G14) is now known and is subscription-shaped (US$99/user/month ambient), which strengthens the "couples U3 to a Connect footprint" concern.
X4Open; both fork bases current and permissive.Agree, and add: the Guidance repo implements only the Comprehend Medical → Bedrock → OpenSearch slice of its page architecture (C40 caveat), so the "port the coding step" composition is realistic but the page should not be cited as if the repo delivered HealthScribe→QuickSight end to end.
X5Open; "fork content, build infrastructure".Agree. Facts re-verified (C53, C57).
X6Resolved: CDK current, iOS layer on EOS SDK.Agree. Commits and Podfile re-fetched verbatim (C31).
X7Resolved: at least one AWS-official Gen 2 web+IoT sample exists.Agree. README and metadata re-fetched (C27).
X8Open but complementary; close G13 before forking the Guidance repo.Agree. G13 narrowed: the Guidance repo README does describe the AgentCore multi-agent architecture; licence detection issue is the new blocker (C45).
X92026-03-05, not 2026-04-28.Agree. What's New dated Mar 5, 2026 re-fetched.

3. Confidence calibration notes

  • Single-source claims presented as High that I could fully re-verify from the primary text and therefore leave at High: C5, C6, C8, C10, C17, C19, C39, C43 (first sentence), C44, C46 (except the PDF attribute), C62, C63, C72–C76.
  • Single-source claims whose High rating rests on a summariser's reading of a page I could not read either (client-rendered workshops): keep provisional as the comparator already says (C47 workshop titles, C52, C54 workshop, C64).
  • Absence claims (C2, C13, C23, C26, C28, C42, C50, C55, C64): I ran GitHub org-scoped searches for the obvious keywords (healthkit, remote patient monitoring, patient portal, readmission, timestream influxdb, ble) and found nothing contrary. These remain "High (absence)" only in the sense that no one has found a counter-example; they are not proofs.

4. Downgrade list for the lead

  1. C11 — Bedrock Knowledge Bases / Guardrails eligibility: Medium → Medium-Low. The 2025-10-13 industries blog does not state eligibility; both rest on the "GA features of listed services" rule exactly as BDA does. Say so in the compliance chapter.
  2. C1 — remove the quotation "not designed for single-account deployments". Not found in any cited or adjacent LZA source. Replace with the LZA Mandatory-accounts wording ("requires these three accounts at minimum") and the Prerequisites page's Organizations-with-all-features requirement.
  3. C24 — HealthLake regions. Replace "us-east-1 and us-west-2" with "seven regions incl. both defaults (FAQ)". Region pinning to us-east-1 (C78/A15) is driven by HealthScribe alone.
  4. C29 — IoT Device SDK for Swift GA date is 2026-06-24 (What's New), not 2026-06-01. Drop "iOS 16+" and "MQTT5" from the What's New attribution; MQTT 5 is on the IoT SDKs docs page, the iOS floor needs the SDK README.
  5. C43 — "Transcribe PHI identification is free" is unsourced. The pricing page is silent on PHI identification. Either find the statement or drop it.
  6. C46 — sample-healthcare-agents "no PDF intake" → "no patient-document intake; has payor-policy PDF upload tools". Matters for U4 T2 composition.
  7. C40 — Diagnosis-codes Guidance: page vs repo scope. The repo implements Comprehend Medical → Bedrock → OpenSearch Serverless; HealthScribe/Lake Formation/Athena/QuickSight are diagram-only. Adjust the X4 fork description.
  8. C45 / C69 / C79 — licence hygiene. aws-ai-intelligent-document-processing has no GitHub-detected licence (README says MIT-0); confirm the LICENSE text before forking. Fix the example-pattern.json path to _pattern-model/example-pattern.json.
  9. C36 — archive date. amazon-comprehend-medical-fhir-integration was archived 2024-07-24, not 2024-01-22.
  10. C21 / X2 — add the journeys-plus-Lambda push path in Connect Customer so U1 reminders are not described as push-less on the engagement side.
  11. C16 — "Push dropped in Gen 2" is inference from the matrix's silence, not a matrix row; word it as "not listed in the Gen 2 feature matrix".
  12. C6 — add the pre-2023-08-02 static-set nuance so the F0 Macie step does not assume PHI identifiers are always off by default.

5. Gaps closed or narrowed while validating

  • G5 (Clarify successor) — closed. docs.aws.amazon.com/sagemaker/latest/dg/clarify-availability-change.html: "Amazon SageMaker Clarify is no longer open to new customers. Existing customers can continue to use the service as normal … we do not plan to introduce new features." Named replacement: AWS-published open-source SageMaker AI monitoring solutions (aws-samples/sample-aiops-on-amazon-sagemakerai/monitoring), the standardized bias metrics computed with pandas/scikit-learn, the SHAP library, SageMaker AI MLflow, CloudWatch, QuickSight, and Amazon Bedrock Evaluations (foundation-model evaluation only; "not a replacement for predictive … bias detection"). The 2026-06 "AWS Service Availability Updates" post lists Clarify — and Model Monitor, A2I, Ground Truth, Debugger — as SageMaker AI features in maintenance, no new customers from 2026-07-30. Consequence for U5 T3: bias/explainability is a build-it-in-the-pipeline step (SHAP + metrics logged to MLflow), not a managed feature; and Model Monitor should be treated the same way.
  • G13 (IDP Guidance repo contents) — narrowed. Repo README describes the AgentCore multi-agent architecture shown on the page. Remaining risk is the undetected licence, not architecture drift.
  • G14 (Connect Health pricing) — closed. Ambient documentation US$99/user/month (600 encounters), overage US$0.036/min; Patient verification US$0.15/action; free tiers as in C60.
  • G16 (point-of-care sibling) — closed. Direct Bedrock calls, not Agents classic; CloudFormation; requires a Connect Health domain and subscription plus a HealthLake datastore.
  • G3 / G2 remain open; my list-page fetch confirms neither "Timestream for InfluxDB" nor "S3 Tables" appears anywhere on the page.

6. Sources re-fetched (all 2026-09-04)

AWS docs: pinpoint migrate.html; pinpoint FAQ; whats-new 2026/03 Connect Health; hipaa-eligible-services-reference (2 targeted fetches); bedrock guardrails-sensitive-filters, data-retention, abuse-detection, compliance-validation; bedrock FAQ and security-compliance; securityhub standards-reference and securityhub-compliance; whats-new 2025/12 Security Hub; macie mdis-reference, discovery-asdd-settings-defaults, discovery-jobs-mdis-recommended, managed-data-identifiers; artifact accept-org-agreement; config HIPAA pack page; whitepaper and Healthcare Lens document-revisions; whats-new 2026/07 AFT and 2025/11 controls-dedicated; LZA solution-overview, cost, prerequisites, mandatory-accounts, awslabs FAQ; cognito authentication-flow-methods and feature-plans; iot iot-sdks and cognito-identities; whats-new 2026/06 IoT Device SDK for Swift; devicefarm endpoints; sagemaker edge-eol and clarify-availability-change; transcribe health-scribe and phi-id; healthscribe pricing; healthlake pricing and FAQ; comprehend-medical textanalysis-phi and FAQ; transcribe pricing; connect health product and pricing pages; solutions pages for diagnosis-codes, IDP, ingesting-PDF, last-mile BLE, guidance-disclaimers; whats-new 2025/11 Builder Center; whats-new 2026/06 service-availability; push-notifications reference-send-message; sns mobile push; prescriptive-guidance appsync-api-gateway; amplify swift feature-matrix. AWS blogs: ML 2026-06-01 (Gateway interceptors), public-sector 2026-08-14, industries 2025-10-13, architecture 2026-08-19 (Clario). GitHub: repo metadata/README/LICENSE/commits for every repository named in §1; amplify-cli #14881; amplify-flutter #6094, #6106, PR #6851; amplify-swift/android/flutter latest releases; rancher-on-aws-workshop contentspec.yaml; serverless-patterns _pattern-model; eks-workshop-v2; HCLS toolkit GitHub Pages site. Other: Apple App Store guidelines 5.1.3; Android Health Connect guide; MADR site; Google JSS redirect target.