AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsMedium

A healthcare provider is deploying a new patient management system that stores highly sensitive patient health information (PHI). The system must comply with HIPAA regulations, ensuring data encryption at rest and in transit, strict access controls, and comprehensive auditing. The application will be hosted on Amazon EC2 instances within a private subnet, accessing an Amazon S3 bucket for medical images and an Amazon RDS for PostgreSQL database for patient records. Which configuration elements are ESSENTIAL to ensure HIPAA compliance for these services?

  1. AUse S3 bucket policies for access control, enable RDS encryption at rest, and implement network ACLs for EC2 instances.
  2. BEnable S3 default encryption, configure RDS encryption at rest with KMS, enforce IAM policies for least privilege, and enable CloudTrail for auditing.
  3. CUse Server-Side Encryption with Customer-Provided Keys (SSE-C) for S3, enable RDS storage auto-scaling, and configure EC2 instance profiles.
  4. DImplement S3 Object Lock for immutability, use RDS read replicas for high availability, and deploy AWS WAF for application security.
Show answer & explanation

Correct answer: B. Enable S3 default encryption, configure RDS encryption at rest with KMS, enforce IAM policies for least privilege, and enable CloudTrail for auditing.

For HIPAA compliance, data encryption at rest and in transit is critical. Enabling S3 default encryption (e.g., with SSE-S3 or KMS) and configuring RDS encryption at rest with AWS KMS ensures data protection. IAM policies with least privilege control access to PHI. CloudTrail provides comprehensive auditing of all API calls, which is essential for compliance. These are foundational elements for securing PHI.

Why the other options are wrong

  • A. While bucket policies and NACLs are part of security, they alone are not sufficient for comprehensive HIPAA compliance without explicit encryption at rest for S3 and robust auditing.
  • C. SSE-C is an option for S3 encryption, but auto-scaling and instance profiles are not directly security controls for data at rest/in transit or auditing for HIPAA compliance.
  • D. S3 Object Lock is for immutability (retention), read replicas for availability, and WAF for application security (DDoS, XSS, SQLi). While valuable, these are not the core elements for data encryption, access control, and auditing for HIPAA compliance.

HIPAA Compliance on AWS

Ensuring the security and privacy of Protected Health Information (PHI) on AWS by implementing technical and administrative safeguards as required by the Health Insurance Portability and Accountability Act.

  • Requires encryption of PHI at rest and in transit.
  • Mandates strict access controls (least privilege).
  • Demands comprehensive auditing and logging of access.

Memory trick: Encrypt, control, and audit: The HIPAA trinity protects patient data.

More Design for New Solutions questions