AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityMedium

A healthcare provider is developing a new patient portal application on AWS. The application needs to handle sensitive patient health information (PHI) and must comply with HIPAA regulations. The solutions architect needs to ensure that the application is highly available, scalable, and secure, with a strong emphasis on data encryption, access logging, and regular security assessments. Which combination of AWS services and practices should be recommended to meet these requirements?

  1. AHost the application on AWS Lambda with Amazon API Gateway, store PHI in Amazon DynamoDB with encryption at rest, and use AWS Shield Advanced for DDoS protection.
  2. BDeploy the application on Amazon EC2 instances in a single Availability Zone, use Amazon S3 for data storage with default encryption, and implement AWS WAF for security.
  3. CDeploy the application using Amazon Lightsail, store PHI in Amazon EBS volumes with encryption, and rely on built-in operating system logging for auditing.
  4. DUtilize AWS Elastic Beanstalk for application deployment in a Multi-AZ configuration, store PHI in Amazon RDS for PostgreSQL with encryption at rest and in transit, and enable AWS CloudTrail and Amazon GuardDuty.
Show answer & explanation

Correct answer: D. Utilize AWS Elastic Beanstalk for application deployment in a Multi-AZ configuration, store PHI in Amazon RDS for PostgreSQL with encryption at rest and in transit, and enable AWS CloudTrail and Amazon GuardDuty.

Elastic Beanstalk in Multi-AZ provides high availability and scalability. RDS for PostgreSQL with encryption at rest and in transit secures PHI. CloudTrail logs all API calls for auditing, and GuardDuty provides intelligent threat detection, all crucial for HIPAA compliance and robust security.

Why the other options are wrong

  • A. While Lambda/API Gateway/DynamoDB are scalable, DynamoDB encryption at rest is good, but Shield Advanced is for DDoS protection, not comprehensive security for PHI, and this option doesn't explicitly cover detailed access logging or threat detection for PHI as robustly as CloudTrail/GuardDuty.
  • B. Single AZ deployment does not provide high availability. S3 default encryption is good, but WAF alone is not sufficient for comprehensive HIPAA compliance for PHI. This option lacks robust auditing and threat detection.
  • C. Lightsail is a simplified service, not typically recommended for mission-critical, highly regulated applications like PHI. EBS is block storage, and relying solely on OS logging is insufficient for comprehensive auditing required by HIPAA.

HIPAA Compliance on AWS

Adhering to the Health Insurance Portability and Accountability Act (HIPAA) regulations when handling Protected Health Information (PHI) on AWS, requiring specific security and privacy controls.

  • Requires encryption at rest and in transit.
  • Strict access controls and auditing.
  • Business Associate Addendum (BAA) with AWS.

Memory trick: Multi-AZ for uptime, Encrypt for PHI, Audit for compliance, Guard for threats.

More Design Solutions for Organizational Complexity questions