AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsMedium

A healthcare provider is deploying a new patient management system that stores highly sensitive patient health information (PHI). The system must comply with HIPAA regulations, which mandate strict data privacy, security, and auditability. The architect must design the data storage layer to encrypt data at rest, encrypt data in transit, ensure access control, and maintain detailed audit logs of all data access. Which combination of AWS services and configurations will provide the most comprehensive compliance for the PHI data storage?

  1. AAmazon RDS for PostgreSQL with Storage Level Encryption (SLE), SSL/TLS for connections, IAM database authentication, and AWS CloudTrail/CloudWatch Logs.
  2. BAmazon S3 with SSE-S3 encryption, VPC Endpoints, and AWS CloudTrail.
  3. CAmazon DynamoDB with Server-Side Encryption (SSE) using KMS, VPC Endpoints, and Amazon GuardDuty.
  4. DAWS Key Management Service (KMS) for encryption keys, AWS Config for compliance rules, and Amazon Macie for data discovery.
Show answer & explanation

Correct answer: A. Amazon RDS for PostgreSQL with Storage Level Encryption (SLE), SSL/TLS for connections, IAM database authentication, and AWS CloudTrail/CloudWatch Logs.

This option provides a relational database solution, which is often preferred for structured PHI, with comprehensive controls: Storage Level Encryption for data at rest, SSL/TLS for data in transit, IAM database authentication for fine-grained access control, and CloudTrail/CloudWatch Logs for auditing, all critical for HIPAA compliance.

Why the other options are wrong

  • B. While S3 with SSE-S3 encrypts at rest, and VPC Endpoints secure transit, it lacks database-specific access controls (like row/column level) and fine-grained auditing directly on data access within the application layer.
  • C. DynamoDB with SSE-KMS encrypts at rest, and VPC Endpoints secure transit, but GuardDuty is for threat detection, not direct auditing of data access within the database itself. IAM database authentication for DynamoDB is only for specific use cases (e.g., API Gateway), and fine-grained auditing of table items is more complex.
  • D. KMS, Config, and Macie are important security services, but they are not a complete data storage solution. They provide key management, compliance auditing, and data discovery, but not the primary storage, encryption-in-transit, access control, and direct audit logging of the data layer itself.

HIPAA-Compliant Data Storage on AWS

Designing data storage on AWS to meet HIPAA requirements for Protected Health Information (PHI), emphasizing encryption, access control, and auditability.

  • Encrypt data at rest (e.g., RDS SLE, S3 SSE-KMS).
  • Encrypt data in transit (e.g., SSL/TLS, VPC Endpoints).
  • Implement strong access controls (e.g., IAM, database authentication).
  • Maintain detailed audit logs (e.g., CloudTrail, database logs).

Memory trick: PHI Needs Protection: Encrypt, Access Control, Audit, and Transit Secure.

More Design for New Solutions questions