AWS Security & Compliance Knowledge Center

Guides, whitepapers, and best practices to help healthtech and software teams secure workloads and stay compliant on AWS.

HIPAA

HIPAA compliance on AWS requires putting the technical, physical, and administrative safeguards in place to safeguard Protected Health Information (PHI) in your cloud environment. This hub covers what AWS's HIPAA eligibility actually means, requirements under the Business Associate Agreement (BAA), mistakes that most often trip up healthtech teams, and service-by-service guidance for services such as EC2, Lambda, RDS, Redshift, and S3.

Explore HIPAA Compliance For AWS

SOC 2

SOC 2 compliance on AWS requires proving your cloud security controls meet the Trust Service Criteria (TSC) and having an auditor evaluate your security program for a Type 1 or Type 2 report. These resources and guides break down AWS's own SOC reports factor into your audit, and what internal controls and evidence you'll need to prepare for SOC 2.

Explore SOC 2 Compliance For AWS

Cloud Security & GRC

Cloud security and GRC (Governance, Risk, and Compliance) on AWS means proving your controls hold up in production, not just on paper. These guides cover AWS cloud security best practices, audit logging, AWS-native tools like Security Hub, GuardDuty, Config, and IAM, and architecture practices that keep your environment provably compliant without slowing down development and operations.

Explore Cloud Security For AWS

Stay Up To Date On AWS Security & Compliance

Read the latest articles about AWS security best practices and compliance.