Is AWS HiTRUST Certified?
Amazon Web Services (AWS) currently has 64 services certified under the Health Information Trust Alliance Common Security Framework (HiTRUST CSF), enabling healthcare organizations to customize security controls for regulatory compliance including HIPAA, PCI-DSS, ISO/IEC 27000, and NIST standards, while AWS supports this compliance with tools, services, and a Business Associate Addendum (BAA) to protect protected health information (PHI) and personally identifiable information (PII).
Currently, the Health Information Trust Alliance Common Security Framework (HiTRUST CSF) certifies 64 Amazon Web Services (AWS) services. These HiTRUST-certified services include Amazon Elastic Compute Cloud, Amazon EMR, Amazon Redshift, and AWS Managed Services.
The HiTRUST certification allows AWS customers to customize their security control baselines according to various factors, including regulatory requirements and the type of organization.
The CSF is described by HiTRUST as “a certifiable framework that provides organizations with a comprehensive, flexible and efficient approach to regulatory compliance and risk management.”
HiTRUST developed the CSF framework in collaboration with healthcare and information security professionals. The CSF consolidates security controls from federal law, such as HIPAA (Health Insurance Portability and Accountability Act), state law, and industry standards like PCI-DSS (Payment Card Industry Data Security Standard), into a single framework designed for the healthcare industry.
Organizations can use the HiTRUST framework to comply with other compliance standards, including:
- HIPAA compliance
- PCI-DSS
- ISO/IEC 27000 series (information security standards published jointly by the International Organization for Standardization and the International Electrotechnical Commission)
- NIST (National Institute of Standards and Technology) standards
To help customers comply with HIPAA and/or HiTRUST, AWS provides access to tools and services that protect the security and privacy of protected health information (PHI) and personally identifiable information (PII).
According to Amazon, more AWS customers, especially healthcare payers, are using the AWS Cloud to ensure compliance with HIPAA and HiTRUST. Amazon Web Services offers its customers a Business Associate Addendum (BAA), a contract required under HIPAA rules to ensure that AWS appropriately safeguards protected health information.
The BAA provides a list of HIPAA-eligible services that customers can use to process, store, and transmit protected health information under the BAA.