There's No Such Thing as a HIPAA Certified Cloud — And That's the Problem
Last year, a health tech startup told me they were fully covered because they used a "HIPAA certified cloud." They had the vendor's marketing brochure to prove it. Six weeks later, an unsecured S3 bucket exposed the ePHI of 11,000 patients.
Here's the uncomfortable truth: no government body certifies any cloud provider as HIPAA compliant. HHS doesn't do it. OCR doesn't do it. There is no official HIPAA certified cloud designation. The phrase is a marketing term — and a dangerous one if you take it at face value.
If you're shopping for cloud infrastructure to store, process, or transmit protected health information, you need to know exactly what to look for and what questions to ask. This post breaks it all down.
Why HHS Doesn't Certify Cloud Providers
The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for ePHI. But HHS has never created a certification program for technology vendors — cloud or otherwise.
HHS makes this explicit in its own guidance on cloud computing: "No HHS certification is required for cloud service providers." The responsibility sits squarely on the covered entity to vet its vendors and ensure proper safeguards are in place.
So when a vendor tells you their platform is a HIPAA certified cloud, what they usually mean is one or more of the following:
- They've completed a third-party audit like SOC 2 Type II or HITRUST CSF.
- They're willing to sign a Business Associate Agreement (BAA).
- They offer encryption, access controls, and audit logging that align with HIPAA requirements.
None of those things are bad. But none of them equal government certification.
The BAA Is the Starting Line, Not the Finish
I've seen organizations breathe a sigh of relief the moment a cloud vendor signs a BAA. That's like locking your front door and leaving every window open.
A Business Associate Agreement establishes legal obligations. It says the vendor will protect PHI, report breaches, and allow for termination if they violate the agreement. That's critical. But a BAA doesn't mean the vendor has actually implemented adequate security controls. And it doesn't shift your liability.
Under the HIPAA Omnibus Rule, covered entities remain responsible for ensuring their business associates comply. If your cloud vendor suffers a breach because of poor configuration — and you never verified their safeguards — OCR will come looking at both of you.
What a BAA Should Actually Include
At minimum, your BAA with a cloud provider should cover:
- Permitted uses and disclosures of PHI
- Breach notification timelines (the 60-day clock under the Breach Notification Rule)
- Requirements for encryption of ePHI at rest and in transit
- Rights of the covered entity to audit the vendor's practices
- Return or destruction of PHI upon contract termination
If your cloud vendor pushes back on any of these, that's your answer.
What to Actually Evaluate When Choosing a Cloud Platform for PHI
Forget the marketing labels. Here's the checklist I walk clients through when they're evaluating cloud infrastructure for ePHI workloads.
1. Encryption Standards
You need AES-256 encryption at rest and TLS 1.2 or higher in transit. Period. Some vendors offer encryption as an add-on or only enable it for certain storage tiers. Verify it's on by default for every service you'll use.
2. Access Controls and Identity Management
Role-based access control (RBAC) is the baseline. Multi-factor authentication for admin accounts is non-negotiable. I've reviewed breach investigations where a single compromised admin credential led to full exposure of a patient database. Your cloud platform should support granular permissions and enforce the minimum necessary standard.
3. Audit Logging and Monitoring
The HIPAA Security Rule at 45 CFR Part 164, Subpart C requires audit controls that record and examine activity in systems containing ePHI. Your cloud vendor should provide immutable logs, real-time alerting, and easy integration with your SIEM or monitoring tools.
4. Data Residency and Backup
Where does your data physically reside? Some cloud providers replicate data across regions — including international ones. Know where your ePHI sits and make sure backups are encrypted and tested for recovery.
5. Incident Response Capability
Ask for documentation of the vendor's incident response plan. How quickly will they notify you of a suspected breach? The Breach Notification Rule requires covered entities to notify affected individuals within 60 days, so your vendor's internal timeline needs to give you room to investigate and respond.
The $1.55 Million Lesson from Oregon Health & Science University
In 2016, Oregon Health & Science University (OHSU) paid $2.7 million to settle HIPAA violations with OCR. Among the findings: OHSU had stored ePHI on a cloud-based server without a BAA in place. The university had used a cloud platform and simply assumed it was secure enough.
This case remains one of the clearest examples of what goes wrong when organizations trust a cloud vendor's reputation instead of doing due diligence. OCR's resolution agreement with OHSU spelled it out: no BAA, no risk analysis, no excuse.
Your organization doesn't have to repeat this mistake.
Does Your Workforce Know How to Handle PHI in the Cloud?
Technology is only half the equation. I've audited organizations with enterprise-grade cloud infrastructure where staff routinely emailed unencrypted PHI, shared login credentials, or stored patient files in personal cloud accounts.
Workforce training under the HIPAA Security Rule isn't optional. Every member of your team who touches PHI — including those who transport it physically — needs to understand the rules. If you're looking for targeted training, the HIPAA training program for medical couriers is a strong example of role-specific education that actually changes behavior.
For a broader look at available programs, check the full HIPAA training catalog.
What Does "HIPAA Compliant Cloud" Actually Look Like?
Since there's no official HIPAA certified cloud, here's how I describe a genuinely compliant cloud setup to my clients:
- A signed BAA between the covered entity and the cloud service provider.
- A completed risk analysis that specifically addresses cloud-hosted ePHI.
- Encryption at rest and in transit across all services storing or processing PHI.
- Access controls with MFA, RBAC, and automatic session timeouts.
- Audit logging enabled and reviewed regularly.
- Workforce training covering cloud-specific PHI handling procedures.
- A tested incident response plan that accounts for cloud-based breaches.
If you check every box, you don't have a HIPAA certified cloud. You have something better: a defensible compliance posture that will hold up under OCR scrutiny.
Stop Chasing Certifications. Start Building Compliance.
The appeal of a HIPAA certified cloud is obvious. You want someone to hand you a certificate that says "you're good." But HIPAA doesn't work that way. Compliance is an ongoing process, not a product you buy.
Vet your vendors rigorously. Get your BAAs in writing. Run your risk analysis annually. Train your people. And stop trusting marketing copy to do your compliance work for you.
The organizations that get this right aren't the ones with the fanciest cloud platforms. They're the ones that treat every PHI touchpoint — digital, physical, human — as a risk that requires active management.