AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A healthcare company wants to build an application that processes protected health information (PHI) on AWS and needs assurance that the underlying AWS services used are eligible for a HIPAA Business Associate Addendum (BAA). Where should the company confirm which services are HIPAA-eligible and obtain the necessary agreement?

  1. AReview AWS Artifact for compliance reports and execute the AWS BAA through AWS Artifact Agreements
  2. BEnable AWS Config conformance packs tagged as HIPAA
  3. CRequest a HIPAA eligibility list from AWS Trusted Advisor checks
  4. DContact AWS Shield support to enable HIPAA-compliant DDoS protection
Show answer & explanation

Correct answer: A. Review AWS Artifact for compliance reports and execute the AWS BAA through AWS Artifact Agreements

AWS Artifact provides on-demand access to compliance documentation and allows eligible customers to review and accept the AWS Business Associate Addendum (BAA), which is required before processing PHI using HIPAA-eligible services.

Why the other options are wrong

  • B. Config conformance packs check resource configuration, not legal agreements
  • C. Trusted Advisor performs cost/security/performance checks, not compliance agreements
  • D. Shield addresses DDoS protection and has no role in HIPAA agreements

AWS Artifact & HIPAA BAA

AWS Artifact is the self-service portal for downloading compliance reports and accepting agreements like the AWS Business Associate Addendum needed for HIPAA workloads.

  • HIPAA is a shared responsibility; customers must also configure services correctly
  • Artifact Agreements section lets eligible accounts accept the BAA online
  • Not all AWS services are HIPAA-eligible; check the eligible services list

Memory trick: Artifact is the filing cabinet holding the HIPAA handshake agreement.

More Security and Compliance questions