AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsMedium

A healthcare provider is deploying a new patient management system that requires strict adherence to HIPAA compliance. The system will store sensitive patient health information (PHI) and must ensure data is encrypted at rest and in transit, access is tightly controlled, and all access attempts are logged for auditing purposes. The application will be deployed as microservices on Amazon EKS. Which set of security measures should be implemented?

  1. AUse EC2 instance store for data, assign IAM roles to EKS Pods, and enable CloudTrail logging.
  2. BStore PHI in Amazon DynamoDB without encryption, use service accounts for Pods, and enable Amazon GuardDuty.
  3. CEncrypt EBS volumes and S3 buckets with KMS, implement Network ACLs, use IRSA for EKS Pods, and enable CloudTrail and VPC Flow Logs.
  4. DEncrypt data using application-level encryption, use security groups, and enable AWS Config rules.
Show answer & explanation

Correct answer: C. Encrypt EBS volumes and S3 buckets with KMS, implement Network ACLs, use IRSA for EKS Pods, and enable CloudTrail and VPC Flow Logs.

Encrypting EBS volumes and S3 buckets with KMS ensures data at rest encryption. Network ACLs provide subnet-level traffic filtering. IAM Roles for Service Accounts (IRSA) allows granular IAM permissions for EKS Pods, controlling access. CloudTrail logs API calls for auditing, and VPC Flow Logs capture network traffic, both critical for HIPAA compliance and security monitoring.

Why the other options are wrong

  • A. EC2 instance store is ephemeral and not recommended for persistent PHI. Assigning IAM roles directly to Pods is less secure and flexible than IRSA for EKS. CloudTrail is good but insufficient on its own.
  • B. Storing PHI without encryption is a critical HIPAA violation. Using generic service accounts without IAM roles is less secure. GuardDuty is for threat detection but doesn't cover fundamental encryption, access control, or comprehensive logging requirements.
  • D. Application-level encryption is good but should complement infrastructure-level encryption. Security groups are essential but Network ACLs add another layer. AWS Config rules help with compliance but don't cover all operational security needs like access control for Pods or comprehensive logging.

HIPAA Compliance on AWS

Adhering to HIPAA regulations when handling Protected Health Information (PHI) on AWS, focusing on data encryption, access control, auditing, and network security.

  • Encrypt PHI at rest (KMS for EBS, S3) and in transit (TLS/SSL).
  • Implement fine-grained access control (IAM, IRSA).
  • Log all access and activity (CloudTrail, VPC Flow Logs).
  • Secure network boundaries (Security Groups, Network ACLs).
  • Use AWS services that are HIPAA eligible and sign a BAA.

Memory trick: Encrypt everything, control access, log all activity, secure the network.

More Design for New Solutions questions