“HIPAA hosting” is a marketing shorthand, not an HHS certification. A standard cloud service may be used for electronic protected health information (ePHI) when the provider’s role and services are covered by a business associate agreement (BAA) and the customer meets its own HIPAA obligations. What matters is the contract, the specific services and configuration, and how responsibilities are divided—not the hosting label.
When does a cloud provider have HIPAA obligations?
HIPAA applies to covered entities and their business associates. If a cloud service provider creates, receives, maintains, or transmits ePHI on behalf of a covered entity or another business associate, HHS says the provider is a business associate. The relationship generally requires a HIPAA-compliant BAA that describes permitted uses and disclosures, safeguards, and relevant obligations, including those involving subcontractors. See HHS guidance on HIPAA and cloud computing and its business associate guidance.
As an Amazon Associate I earn from qualifying purchases.
Encryption does not by itself change that answer. HHS says a provider that maintains ePHI can still be a business associate even when the data is encrypted and the provider does not possess the decryption key.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Can you use ordinary cloud hosting for ePHI?
Yes. HHS says a covered entity or business associate may use a cloud service to store or process ePHI if the required BAA is in place and the organization otherwise complies with HIPAA. A service marketed as “standard” is not automatically unsuitable; nor does calling a plan “HIPAA hosting” establish that a particular deployment complies. The relevant answer depends on the actual provider relationship and workload. See HHS’s cloud-service FAQ.
#1 Best Overall
What a BAA does—and does not—do
A BAA sets contractual obligations for the business associate relationship. It is necessary where the provider is a business associate, but it does not certify the customer’s system or complete the customer’s HIPAA work. The customer must understand the cloud solution, conduct its own risk analysis, and establish risk-management policies appropriate to its environment. A signed agreement is not a blanket transfer of responsibility.
There is no HHS-approved “HIPAA-certified cloud provider” category. HHS states, “OCR does not endorse, certify, or recommend specific technology or products.” AWS, Google Cloud, and Microsoft also describe the absence of a recognized or approved HIPAA certification program for providers. Treat claims of certification cautiously and examine the underlying contract and service documentation instead.
How responsibilities are divided
HIPAA-related duties are shared, but the precise division depends on the service, architecture, contract, and configuration. HHS notes that a cloud solution may leave some features under the customer’s control while others are the provider’s responsibility. Provider guidance likewise describes shared responsibility. For each component that will handle ePHI, identify who is responsible for:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Identity and access controls, including account permissions and administrative access.
- Encryption choices and key management.
- Logging, monitoring, and review of security events.
- Configuration of the service and any connected systems.
- Incident notification, support, and other operational commitments.
Do not assume that a provider’s infrastructure safeguards configure the customer’s accounts or application automatically. Confirm the division of work for the actual service and deployment.
Rank #3
How to compare a “HIPAA” offering with standard cloud hosting
| What to check | Questions to answer |
|---|---|
| BAA scope | Will the provider execute a BAA for this relationship? Which services and uses are covered, and what obligations apply to safeguards, permitted disclosures, and subcontractors? |
| Service eligibility | Can the specific service in the design handle ePHI under the provider’s terms? Which exclusions or configuration requirements apply? AWS, for example, directs customers to use services identified as HIPAA-eligible under its BAA. |
| Control allocation | Who configures and operates access, encryption, logging, and other relevant controls for each service? |
| Customer risk management | Can the organization understand and assess the full environment, including integrations and customer-managed settings, and manage identified risks? |
| Operational terms | Do service-level terms, support processes, and incident expectations meet the organization’s operational needs? HHS notes that SLAs may address business expectations relevant to HIPAA compliance. |
Provider documentation describes the provider’s position and terms; it is not an independent audit of a customer’s implementation. Service lists and contract terms can change, so confirm current documents directly with the provider. AWS’s HIPAA compliance page, Google Cloud’s HIPAA compliance documentation, and Microsoft’s Azure HIPAA compliance offering provide vendor-specific information.
Quick Recap
Best Value
Rank #4
Practical due-diligence checklist
- Map where ePHI will be created, received, stored, processed, or transmitted, including connected services.
- Determine whether each provider in that path is acting as a business associate and obtain the relevant BAA before relying on the service for ePHI.
- Check that every service handling ePHI is within the provider’s BAA scope and permitted-service terms.
- Document which controls the provider supplies and which your organization must configure and operate.
- Conduct and maintain your own risk analysis and risk-management process for the deployed environment.
- Review support, incident, and service-level terms against your operational requirements, then recheck provider terms when the architecture or service changes.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




