HIPAA: Health Information Protection

AWS 42 automated checks

Technical, administrative, and physical safeguards aligned with the HIPAA Security Rule (45 CFR Part 164) for protecting electronic protected health information (ePHI) in AWS environments

Administrative Safeguards

Administrative Safeguards: Awareness & Training (164.308(a)(5))

Administrative Safeguards: Contingency Plan (164.308(a)(7))

Administrative Safeguards: Incident Procedures (164.308(a)(6))

Administrative Safeguards: Information Access Management (164.308(a)(4))

Administrative Safeguards: Security Management (164.308(a)(1))

Administrative Safeguards: Workforce Security (164.308(a)(3))

Breach Notification

Business Associate Contracts

Contingency Plan

Physical Safeguards

Physical Safeguards: Facility Access (164.310(a)(1))

Physical Safeguards: Workstation Security (164.310(b))

Security Awareness

Security Incident Procedures

Technical Safeguards: Access Control (164.312(a)(1))

Technical Safeguards: Audit Controls (164.312(b))

Technical Safeguards: Encryption (164.312(e)(2))

Technical Safeguards: Integrity (164.312(c)(1))

Technical Safeguards: Transmission Security (164.312(e)(1))

Workforce Security

Measure your HIPAA: Health Information Protection posture

CGPulse maps live Azure and AWS findings to these controls and tracks drift over time.

Start free scan

Official framework documentation

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.