A mid-sized cardiology practice in the Southeast migrated their patient records to a popular cloud platform in 2021. They chose a reputable vendor. They assumed encryption was handled. They never signed a Business Associate Agreement. When a misconfigured storage bucket exposed 287,000 patient records, they learned a brutal lesson: HIPAA compliance and the cloud doesn't happen automatically just because your vendor has a good reputation.
I've seen this pattern dozens of times. Organizations move to the cloud with confidence — and skip the compliance steps that actually matter. If you're storing, processing, or transmitting protected health information in any cloud environment, this post breaks down exactly what you're responsible for and where the real risks hide.
Why the Cloud Doesn't Come HIPAA-Compliant Out of the Box
Here's the misconception I run into most often: "Our cloud vendor is HIPAA compliant, so we're covered." That's not how it works. Not even close.
HIPAA doesn't certify cloud providers. No federal agency stamps a cloud vendor as "HIPAA approved." The HHS guidance on cloud computing makes this clear — a cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate. Period. That means a signed Business Associate Agreement (BAA) is required before any PHI touches their servers.
Amazon Web Services, Microsoft Azure, and Google Cloud all offer HIPAA-eligible services. But "eligible" means they'll sign a BAA and provide the tools. Configuring those tools correctly? That's on you.
The BAA: Your Single Most Important Cloud Document
Without a BAA in place, every piece of ePHI you put in the cloud is an active HIPAA violation. I'm not being dramatic — this is exactly how OCR sees it.
A BAA spells out what the cloud vendor (business associate) can and cannot do with your data, how they'll safeguard it, and what happens when a breach occurs. It creates shared liability. Without one, your organization holds 100% of the risk.
What a Strong Cloud BAA Should Cover
- The specific cloud services covered (not just a blanket statement)
- Encryption requirements at rest and in transit
- Breach notification timelines — the HIPAA Breach Notification Rule requires notification within 60 days, but your BAA can set tighter deadlines
- Data return and destruction procedures upon contract termination
- Subcontractor obligations — if your cloud vendor uses third-party services, those subcontractors need BAAs too
If your vendor won't sign a BAA, walk away. There's no workaround.
The $1.5 Million Mistake: Real Enforcement in the Cloud Era
In 2018, OCR settled with Cottage Health for $3 million after a server misconfiguration exposed ePHI of over 62,000 patients. The records were accessible via basic internet searches. A core issue? Failure to conduct a thorough risk analysis of their electronic environment — including how data was stored and transmitted.
More recently, OCR's enforcement actions have repeatedly targeted organizations that failed to assess the risks of their cloud infrastructure. The OCR resolution agreements page is full of settlements where inadequate risk analysis — especially around electronic systems — was the primary finding.
HHS doesn't care whether the server is in your basement or in a data center in Virginia. If ePHI lives there, the Security Rule applies.
HIPAA Compliance and the Cloud: The Shared Responsibility Model
Every major cloud provider operates on a shared responsibility model. Understanding where your vendor's responsibility ends and yours begins is critical for HIPAA compliance and the cloud.
What the Cloud Provider Typically Handles
- Physical security of data centers
- Infrastructure availability and redundancy
- Hypervisor and network-level security
What Your Organization Must Handle
- Access controls — who on your workforce can access ePHI in the cloud
- Encryption configuration — enabling and managing encryption keys
- Audit logging — turning on and monitoring access logs
- Identity management — multi-factor authentication, role-based access
- Data classification — knowing which data qualifies as PHI
- Risk analysis — conducting and documenting a thorough HIPAA risk assessment
Most breaches I've investigated in cloud environments trace back to the customer's side of this line. Misconfigured S3 buckets. Disabled logging. Overly permissive access policies. Your vendor gave you the tools. You didn't use them.
What Counts as ePHI in the Cloud? More Than You Think
Your EHR database is obvious. But HIPAA compliance and the cloud extends far beyond your primary clinical system.
Think about every cloud-based tool your workforce touches: email platforms, file-sharing services, scheduling apps, telehealth software, messaging tools, even voicemail transcription services. If any of these handle information that identifies a patient and relates to their health, treatment, or payment, you're dealing with ePHI.
I worked with a behavioral health clinic that had therapists uploading session notes to a personal cloud storage account. No BAA. No encryption. No access controls. They didn't even realize it was happening until an employee left and we discovered 14 months of patient records sitting in an unprotected folder.
Your workforce training needs to cover this. The HIPAA Training for Remote Healthcare Workers course addresses exactly these scenarios — cloud storage, remote access, and the tools that create risk when used outside controlled environments.
Encryption: Non-Negotiable in Every Cloud Deployment
The HIPAA Security Rule lists encryption as an "addressable" specification. In practice, if you're putting ePHI in the cloud without encryption at rest and in transit, you'll have an almost impossible time justifying that decision to OCR.
Addressable doesn't mean optional. It means you must implement encryption or document an equivalent alternative that provides the same level of protection. In cloud environments, there is no equivalent alternative. Encrypt everything.
Encryption Checkpoints for Cloud ePHI
- In transit: TLS 1.2 or higher for all data moving between your systems and the cloud
- At rest: AES-256 encryption for stored data, with your organization managing the keys when possible
- Backups: Cloud backups containing ePHI must be encrypted to the same standard
- End-user devices: Laptops and phones accessing cloud-based ePHI need full-disk encryption
Risk Analysis: The Step Everyone Skips
If I had to pick the single most common failure point in cloud HIPAA compliance, it's the risk analysis. Not that organizations skip it entirely — though many do — but that they treat it as a one-time checkbox instead of an ongoing process.
Every time you adopt a new cloud service, change a configuration, or add a workflow that touches ePHI, your risk analysis needs updating. The HHS Security Risk Assessment guidance lays out what OCR expects, and it's thorough.
Document everything. Who evaluated the risk. What they found. What you did about it. When you reviewed it again. OCR investigators will ask for this documentation first. If you can't produce it, the conversation goes downhill fast.
Training Your Workforce for Cloud-Based PHI
Your IT team might understand shared responsibility models and encryption key management. Your front-desk staff, billing team, and clinicians probably don't. And under the HIPAA Privacy and Security Rules, every member of your workforce who handles PHI needs training relevant to their role.
Cloud-specific training should cover:
- Which cloud tools are approved for PHI — and which are explicitly banned
- How to recognize when PHI is being stored in unapproved locations
- Proper procedures for sharing files and communicating through cloud platforms
- What to do — and who to notify — if they suspect a cloud-related breach
If your team hasn't completed foundational HIPAA training recently, the HIPAA Introduction Training 2026 course covers the baseline every covered entity needs, including updated guidance on electronic safeguards.
Can You Use Public Cloud Services and Stay HIPAA Compliant?
Yes — but only with the right safeguards. Public cloud services from major providers can be configured to meet HIPAA requirements. The key word is "configured." A default deployment of almost any cloud service will not meet HIPAA standards.
You need a signed BAA, properly enabled encryption, configured access controls, active audit logging, and a documented risk analysis specific to that service. When all of those are in place, public cloud infrastructure can actually offer stronger physical and technical safeguards than most on-premises setups.
The risk isn't the cloud itself. The risk is assuming the cloud handles compliance for you.
Your Cloud Compliance Checklist for 2026
- Inventory every cloud service that touches, stores, or transmits ePHI
- Verify a signed, current BAA is in place for each one
- Confirm encryption at rest and in transit for all ePHI
- Enable and regularly review audit logs
- Implement multi-factor authentication for all cloud access to ePHI
- Conduct and document a risk analysis that specifically addresses cloud environments
- Train all workforce members on cloud-specific PHI handling procedures
- Establish and test an incident response plan that includes cloud breach scenarios
If any item on that list makes you uneasy, start there. And if your workforce training hasn't kept pace with your technology, the HIPAA Fundamentals course can close that gap quickly.
The Bottom Line on HIPAA and Cloud Computing
The cloud isn't the problem. Complacency is. Every covered entity and business associate using cloud services has the same obligation: protect ePHI with administrative, physical, and technical safeguards — no matter where that data lives.
Sign the BAA. Encrypt everything. Train your people. Document your risk analysis. Review it regularly. The organizations that get this right don't just avoid penalties — they build the kind of security posture that earns patient trust and survives OCR scrutiny.