AWS signs a BAA and lists HIPAA-eligible services. Everything above the hypervisor is still yours.
What you get
- Automated evidence from CloudTrail, Config, GuardDuty, KMS, and IAM
- HIPAA-eligible service verification across your actual account estate
- Encryption, logging, and access control checks mapped to §164.312
- Shared responsibility documentation your auditor accepts
The shared responsibility line
This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.
How it fits together
| Layer | Who owns it | How SuperHIPAA helps |
|---|---|---|
| Infrastructure | Provider (under BAA) | We verify your BAA is current and covers the services you use |
| Configuration | You | Continuous checks mapped to §164.312 |
| Data classification | You | ePHI inventory and flow mapping |
| Workforce | You | Training, acknowledgement, access reviews |
| Documentation | You | Policies, risk analysis, evidence, all versioned |
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.