A healthcare provider is deploying a new patient management system that stores highly sensitive patient health information (PHI). The system must comply with HIPAA regulations, which requires stringent data encryption at rest and in transit, access controls, audit logging, and data backup/recovery. The architect needs to design the storage solution for the PHI. Which combination of AWS services and practices will ensure HIPAA compliance for data storage?
- AStore PHI in Amazon RDS for PostgreSQL, enable encryption at rest with KMS, enforce access via Security Groups, configure automated backups, and enable RDS enhanced monitoring.
- BStore PHI in Amazon DynamoDB, enable encryption at rest with AWS owned keys, use IAM policies for access, enable point-in-time recovery, and stream changes to Amazon Kinesis for auditing.
- CStore PHI in Amazon S3 with server-side encryption (SSE-S3), enforce access control with S3 Bucket Policies and IAM, enable S3 Object Lock, and configure S3 Cross-Region Replication.
- DStore PHI in Amazon EBS volumes attached to EC2 instances, encrypt volumes using KMS, manage access via EC2 Security Groups, and create manual EBS snapshots for backup.
Show answer & explanationAnswer & explanation
Correct answer: C. Store PHI in Amazon S3 with server-side encryption (SSE-S3), enforce access control with S3 Bucket Policies and IAM, enable S3 Object Lock, and configure S3 Cross-Region Replication.
Storing PHI in S3 with SSE-S3 ensures encryption at rest. S3 Bucket Policies and IAM provide granular access control. S3 Object Lock helps meet immutability requirements for audit trails. Cross-Region Replication provides disaster recovery. This combination effectively addresses HIPAA requirements for data storage.
Why the other options are wrong
- A. RDS encrypts data and has automated backups, but enhanced monitoring is for performance, not a primary HIPAA storage control. It doesn't explicitly mention immutability for audit trails or object-level access control like S3.
- B. DynamoDB encryption, IAM, and point-in-time recovery are good, but using AWS owned keys might not meet specific key management requirements, and streaming to Kinesis is for auditing, not the primary storage compliance itself regarding immutability or specific S3 features.
- D. While EBS encryption is good, manual snapshots are not ideal for robust backup/recovery. EC2 Security Groups are network firewalls, not granular data access controls for the data itself. It lacks a comprehensive audit trail and immutability.
HIPAA-Compliant Data Storage on AWS
Achieving HIPAA compliance for data storage on AWS involves using services that offer encryption at rest and in transit, robust access controls, audit capabilities, and reliable backup/recovery strategies.
- Encryption of PHI both at rest and in transit is mandatory.
- Strict access controls (e.g., IAM, S3 Bucket Policies) must be implemented.
- Audit logging (e.g., CloudTrail, S3 access logs) is essential for monitoring.
- Data backup and disaster recovery plans are required.
Memory trick: S3's Secure Shield Protects Patient Privacy.