AWS Certified AI PractitionerFoundation ModelsHard

A healthcare provider wants to use a foundation model to assist doctors in diagnosing rare diseases by analyzing patient medical images and clinical notes. Due to the highly sensitive nature of patient data and strict compliance requirements (e.g., HIPAA), they cannot send raw patient data to a public cloud API for inference. Which deployment strategy for the foundation model would best address these stringent data privacy and compliance needs?

  1. ADeploying the foundation model on-premises or in a private cloud environment.
  2. BRelying solely on prompt engineering with a publicly accessible LLM.
  3. CFine-tuning a smaller, open-source model on a general dataset in the public cloud.
  4. DUsing a publicly available, cloud-hosted API with anonymized data.
Show answer & explanation

Correct answer: A. Deploying the foundation model on-premises or in a private cloud environment.

Deploying the foundation model on-premises or within a private cloud environment allows the healthcare provider to maintain complete control over their sensitive patient data, ensuring it never leaves their secure, compliant infrastructure. This addresses strict privacy regulations like HIPAA more effectively than public cloud APIs or anonymized data, which might still carry residual risks.

Why the other options are wrong

  • B. Prompt engineering alone doesn't solve the data privacy issue if the data still needs to be sent to a public LLM for processing.
  • C. Fine-tuning in the public cloud still involves data transfer and storage outside direct control, and a general dataset won't help with rare diseases.
  • D. Even anonymized data can sometimes be de-anonymized, and public APIs inherently involve data leaving the provider's direct control, posing compliance risks.

On-Premises FM Deployment

Hosting and running a foundation model entirely within a private, local data center or dedicated private cloud infrastructure, rather than using a public cloud service.

  • Provides maximum control over data sovereignty and security.
  • Essential for highly sensitive data and strict regulatory compliance (e.g., HIPAA, GDPR).
  • Requires significant internal IT infrastructure and expertise.

Memory trick: Private Placement Protects Patient Privacy.

More Foundation Models questions