3 ms·
Windows Azure and AWS both support HIPAA compliance http://www.windowsazure.com/en-us/support/trust-center/compliance/ http://www.windowsazure.com/en-us/suppor
by kellros 13y ago
Windows Azure and AWS both support HIPAA compliance
http://www.windowsazure.com/en-us/support/trust-center/compliance/ http://www.windowsazure.com/en-us/support/trust-center/compl...
http://aws.amazon.com/about-aws/whats-new/2009/04/06/whitepaper-hipaa/ http://aws.amazon.com/about-aws/whats-new/2009/04/06/whitepa...
I know a couple of things regarding HIPAA compliance, first-most you need a very high level of security on the transport layer (I believe it's 256 bits AES or higher for SSL - some spout that 128 bits is sufficient, but effectively a standard SSL certificate doesn't cut it). The second is HIPAA compliance is multi-part (see http://luxsci.com/blog/what-makes-a-web-site-hipaa-secure.html http://luxsci.com/blog/what-makes-a-web-site-hipaa-secure.ht...) and the infrastructure can only support HIPAA compliance (ex. if you're using AWS S3), but your application is responsible for the implementation thereof.
Your application cannot be branded to be HIPAA compliant simply because your infrastructure supports it. You'll have to go through the requirements list in order to construct your infrastructure to support it and then enforce the rules on the application and systems thereof (at least via unit/behavioral testing). You cannot really prove your application is compliant without proper test cases that enforce the rules.