{"product_id":"healthcare-cloud-architecture-hipaa-blueprint","title":"Healthcare Cloud Architecture HIPAA Blueprint","description":"\u003ch3\u003eThe Problem This Blueprint Solves\u003c\/h3\u003e\n\u003cp\u003eYour healthcare application processes Protected Health Information under HIPAA, and your cloud environment needs to satisfy §164.312 technical safeguards before your compliance team will approve production launch. You have auditors arriving in 90 days, your DevOps team has never built a HIPAA-compliant architecture, and the gap between \"we use AWS\" and \"we pass a HIPAA audit\" is a 200-page compliance matrix your team does not know how to fill.\u003c\/p\u003e\n\n\u003cp\u003eThis blueprint is the architecture I built for a telehealth platform processing 1.2M patient encounters monthly. It passed OCR audit readiness assessment on the first attempt and has maintained compliance through three annual reviews.\u003c\/p\u003e\n\n\u003ch3\u003eWhat You Get\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eArchitecture diagram\u003c\/strong\u003e — Full HIPAA-compliant VPC topology with encryption boundaries, PHI data flow paths, audit log pipeline, and network segmentation (Draw.io)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTerraform modules\u003c\/strong\u003e — KMS key hierarchy, S3 bucket policies with deny-unencrypted rules, RDS encryption at rest, ALB with TLS 1.2+ enforcement, CloudTrail + CloudWatch Logs with tamper-evident logging, VPC Flow Logs\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCompliance mapping spreadsheet\u003c\/strong\u003e — Every §164.312 control mapped to a specific AWS service configuration with evidence collection instructions\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAudit preparation checklist\u003c\/strong\u003e — 68-item checklist covering access controls, encryption, audit logging, integrity controls, and transmission security\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eKey Architecture Decisions\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eKMS Customer Managed Keys over AWS Managed Keys\u003c\/strong\u003e — §164.312(a)(2)(iv) requires encryption key management. Customer managed KMS keys give you key rotation control, usage audit trails in CloudTrail, and the ability to revoke access by disabling keys — none of which AWS managed keys provide.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDedicated VPC with no internet gateway for PHI workloads\u003c\/strong\u003e — PHI processing happens in a private VPC with VPC endpoints for AWS services. No NAT gateway, no internet gateway. Outbound traffic routes through AWS PrivateLink. This eliminates an entire category of data exfiltration vectors that auditors will ask about.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCloudTrail with S3 Object Lock for audit logs\u003c\/strong\u003e — §164.312(b) requires audit controls. CloudTrail logs land in an S3 bucket with Object Lock in compliance mode and a 7-year retention policy. No one — including root — can delete or modify these logs during the retention period. This is the control auditors care most about.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSeparate AWS accounts for PHI and non-PHI workloads\u003c\/strong\u003e — AWS Organizations with SCPs enforcing encryption policies at the account level. PHI accounts have SCPs that deny any API call that would create unencrypted resources. This makes compliance violations architecturally impossible rather than policy-dependent.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho This Blueprint Is For\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCloud Architects building their first HIPAA-compliant environment on AWS\u003c\/li\u003e\n\u003cli\u003eCompliance Officers who need to map AWS controls to §164.312 requirements\u003c\/li\u003e\n\u003cli\u003eCTOs at health tech startups preparing for their first HIPAA audit\u003c\/li\u003e\n\u003cli\u003eDevOps Engineers tasked with hardening an existing AWS environment for PHI processing\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eYour First 48 Hours\u003c\/h3\u003e\n\u003cp\u003eStart with the compliance mapping spreadsheet — identify which §164.312 controls you already satisfy and which have gaps. Then deploy the KMS and CloudTrail Terraform modules into a sandbox account. Verify that CloudTrail logs capture KMS key usage events. On day two, deploy the VPC module and confirm that PHI subnets have no route to an internet gateway. Run the provided \u003ccode\u003eaws configservice\u003c\/code\u003e conformance pack to validate encryption-at-rest compliance across all resources.\u003c\/p\u003e\n\n\u003ch3\u003eLimitations and Trade-offs\u003c\/h3\u003e\n\u003cp\u003eThis blueprint covers the technical safeguards of §164.312 only. Administrative safeguards (workforce training, policies and procedures) and physical safeguards (facility access) are outside scope. The architecture assumes a signed AWS Business Associate Agreement is already in place. VPC endpoint costs add $7-22\/month per endpoint, and a fully private VPC typically needs 8-12 endpoints. The Terraform modules do not cover application-layer encryption — your application must handle field-level encryption of PHI independently.\u003c\/p\u003e","brand":"Citadel Cloud Management","offers":[{"title":"Default Title","offer_id":54890408018211,"sku":"CCM-ARC-011","price":79.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0979\/8539\/7027\/files\/citadel-architecture-product_1da84a78-9659-40be-b275-a4f0f92796a9.png?v=1775138105","url":"https:\/\/citadel-cloud-management.myshopify.com\/products\/healthcare-cloud-architecture-hipaa-blueprint","provider":"Citadel Cloud Management","version":"1.0","type":"link"}