AWS HIPAA Eligible Services: RDS, S3, Lambda, Bedrock 2026
Last updated: July 22, 2026
AWS HIPAA eligible services are the AWS products that Amazon will cover under its Business Associate Addendum (BAA). Only those services may store, process, or send protected health information (PHI). The list is the gate. AWS HIPAA eligible services now number over 200. Amazon updates the list often; the current version is dated July 22, 2026. The everyday building blocks are all on it: EC2, S3, RDS, Aurora, Lambda, DynamoDB, and Amazon Bedrock. But eligible does not mean compliant. Eligible means the service CAN hold PHI once your BAA is signed and your settings are right. This guide shows how to read the list. It answers the common service questions. And it covers what stays your job.
TL;DR: Quick answer
AWS HIPAA eligible services are the ones the AWS BAA covers. You accept the BAA in AWS Artifact. PHI must stay inside that list (45 CFR § 164.308(b)).
The list passed 200 services on July 22, 2026. RDS, Aurora, S3, EC2, Lambda, DynamoDB, EBS, KMS, CloudTrail, CloudFront, SES, HealthLake, and Bedrock are all on it.
Eligible is not compliant. You still set up encryption, access, and logging for every service you use.
Some services carry footnotes. A feature or a model can sit outside the listing. Read the fine print for each service.
The list changes. Check AWS's own page before you send PHI to a new service. A popular service can still be off the list.
What does "HIPAA eligible" actually mean?

HIPAA requires a signed Business Associate Agreement before a vendor holds PHI for you. Amazon meets this with its Business Associate Addendum. You accept it in AWS Artifact. The BAA does not cover everything AWS sells. It covers a named list. That is what "eligible" means. Amazon built the service for PHI use and will stand behind it in the contract. Use an off-list service for PHI and you are in violation, even in a covered account. The wider verdict on the platform is in is AWS HIPAA compliant. This guide zooms in on the list itself.
How to read the AWS HIPAA eligible services list

Amazon publishes the official list and updates it through the year. Three rules keep you safe. First, treat AWS's page as the only source of truth. Blog lists go stale, ours included. Second, watch the footnotes. Some entries leave a feature or a model out. So a service can be on the list while one piece of it is not. Third, recheck before each new launch. The AWS HIPAA eligible services list grows often. A service that was off the list last quarter may be on it now.
The building blocks, checked July 22, 2026

Service | Eligible? | What you still set up |
|---|---|---|
Amazon EC2 (servers) | Yes | OS hardening, patching, encrypted volumes, restricted access |
Amazon S3 (object storage) | Yes | Block public access, encrypt buckets, log access |
Amazon RDS and Aurora (databases) | Yes | Encryption at rest, network isolation, least-privilege users |
AWS Lambda (serverless code) | Yes | Keep PHI out of environment variables and plain logs |
Amazon DynamoDB (NoSQL) | Yes | Encryption, IAM scoping, backup policy |
Amazon EBS, AWS KMS, AWS CloudTrail | Yes | Encrypted disks, managed keys, logs kept six years |
Amazon CloudFront and SES | Yes, with footnotes | Check feature exclusions; TLS everywhere; no PHI in plain email |
Amazon Bedrock (AI models) | Yes, with model footnotes | Confirm your model is covered; note AI use in your risk analysis |
Amazon HealthLake (health data) | Yes | Access scoping and audit review, like any PHI store |
Every row assumes the BAA is already accepted in AWS Artifact. No row is compliant without that step.
The questions teams actually ask

Is RDS HIPAA compliant? RDS is eligible, and Aurora with it. Turn on encryption at rest. Isolate the network. Scope the database users and log access. Then it can be part of a compliant system. The database tier has its own guide: HIPAA compliant database hosting.
Is Lambda HIPAA compliant? Lambda is eligible. The traps are day-to-day ones. PHI pasted into environment variables. PHI logged in plain text to CloudWatch. Treat function logs as a PHI surface.
Is Bedrock HIPAA compliant? Bedrock is on the AWS HIPAA eligible services list, with footnotes. A listing can leave out specific models. Confirm the model you call is covered before PHI touches a prompt. AI workloads also belong in your risk analysis under 45 CFR § 164.308(a)(1)(ii)(A).
Is S3 HIPAA compliant? S3 is eligible. It is also where the loudest breaches happen. A public bucket is one checkbox away. Block public access at the account level. Encrypt by default and alert on policy changes.
Eligible parts, compliant systems

Amazon secures the cloud. You secure what you build in it. That is the shared responsibility model. It is why the AWS HIPAA eligible services list is the start of the work, not the end. Encryption settings, IAM scoping, logging, backup tests, and the risk analysis are all on your side under 45 CFR § 164.312. The full setup walkthrough is in our guide to HIPAA compliant cloud hosting. Software teams that build on these services have their own checklist in HIPAA compliant hosting for healthcare SaaS.
If you would rather not run this yourself

The gap between eligible and compliant is setup work, and it never stops. Maybe your team would rather ship product than tune IAM policies. Our managed HIPAA cloud hosting runs single-tenant environments on these same AWS HIPAA eligible services. The BAA is signed within 24 hours. Encryption, a firewall, six-year audit logs, and tested backups arrive pre-set. Plans start at $229 per month with migration included. We sell this, so weigh that as a disclosure. Self-managed teams can start smaller with our HIPAA compliant hosting plans. Either way, tell us what you are building and you will get a straight answer.
Frequently asked questions
How many AWS HIPAA eligible services are there?
Over 200 as of July 22, 2026. The list grows through the year. Check AWS's own page before you use a new service for PHI.
Is Amazon RDS HIPAA eligible?
Yes, and Aurora too. The listing covers the service. You still set up encryption, network isolation, scoped users, and logging before patient data arrives.
Is Amazon Bedrock HIPAA eligible?
Yes, with footnotes. Specific models can sit outside the listing. Confirm your model is covered and note the AI workload in your risk analysis.
Does using only eligible services make my app HIPAA compliant?
No. Eligible services plus a signed BAA are needed, not enough. Your settings, access choices, logging, and documented risk analysis decide compliance.
What happens if PHI lands in a non-eligible service?
That is a violation of 45 CFR § 164.308(b), even in a covered account. It may also be a reportable breach. Send PHI only through listed services, and audit where your data really flows.
Recap: AWS HIPAA eligible services
To recap, AWS HIPAA eligible services are the 200-plus products the AWS BAA covers, per the list updated July 22, 2026. RDS, S3, EC2, Lambda, DynamoDB, and Bedrock are all on it. Some carry footnotes. Sign the BAA in AWS Artifact first. Keep PHI inside listed services only. Then do your side of the work: encryption, access scoping, logging, and a written risk analysis. Eligible parts, set up right, are what a compliant system is made of.
This article is general information, not legal advice. The AWS HIPAA Eligible Services Reference changes frequently; the details here reflect the July 22, 2026 version. Confirm the current list with AWS, consult qualified counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed July 2026.