AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A healthcare company wants to build an application that processes protected health information (PHI) on AWS and needs assurance that the underlying AWS services used are eligible for a HIPAA Business Associate Addendum (BAA). Where should the company confirm which services are HIPAA-eligible and obtain the necessary agreement?
- AReview AWS Artifact for compliance reports and execute the AWS BAA through AWS Artifact Agreements
- BEnable AWS Config conformance packs tagged as HIPAA
- CRequest a HIPAA eligibility list from AWS Trusted Advisor checks
- DContact AWS Shield support to enable HIPAA-compliant DDoS protection
Show answer & explanationAnswer & explanation
Correct answer: A. Review AWS Artifact for compliance reports and execute the AWS BAA through AWS Artifact Agreements
AWS Artifact provides on-demand access to compliance documentation and allows eligible customers to review and accept the AWS Business Associate Addendum (BAA), which is required before processing PHI using HIPAA-eligible services.
Why the other options are wrong
- B. Config conformance packs check resource configuration, not legal agreements
- C. Trusted Advisor performs cost/security/performance checks, not compliance agreements
- D. Shield addresses DDoS protection and has no role in HIPAA agreements
AWS Artifact & HIPAA BAA
AWS Artifact is the self-service portal for downloading compliance reports and accepting agreements like the AWS Business Associate Addendum needed for HIPAA workloads.
- HIPAA is a shared responsibility; customers must also configure services correctly
- Artifact Agreements section lets eligible accounts accept the BAA online
- Not all AWS services are HIPAA-eligible; check the eligible services list
Memory trick: Artifact is the filing cabinet holding the HIPAA handshake agreement.