I am really excited to release our white paper on how to create HIPAA-compliant information processing systems in the Cloud. The paper focuses on the HIPAA sections: The Privacy Rule and The Security Rule, and how to encrypt and protect your data in the AWS cloud.
White paper is now available on AWS website for download.
U.S. companies that are handling healthcare information, specifically personally identifiable information, are subject to the security and privacy regulations of Health Insurance Portability and Accountability Act (HIPAA). The White paper talks about applications that deal with Protected Health Information (PHI) and use Amazon S3 should encrypt their "in-flight" and "at-rest" data using traditional encryption mechanisms they have used in the past. For eg. TC3 Health used PGP Encryption for their implementation. The paper also makes several recommendations like creating a data backup plan, leveraging multiple EC2 Availability Zones for high availability and disaster recovery, creating point-in-time snapshots of EBS volumes etc. in order to comply with HIPAA's Security standards.
Various developer tools/libraries (for Encryption)
Solutions (with built-in Encryption Support):
- Zmanda Cloud Backup
- ElephantDrive
- Sonian Networks
- Vembu's StoreGrid
- DataCastle Data Protection
- Moonwalk
- Microlite BackupEDGE
- SecoBackup SecoVault and S3SQL
Read about customers who have built HIPAA-compliant apps on AWS:
-Jinesh


Lots of white papers, although I don't like them, but I have to know them. Anyway, good news!
Posted by: Jack | April 14, 2009 at 08:36 PM
Zmanda CEO discusses use of Amazon S3 for backup to the cloud:
http://www.youtube.com/watch?v=VFbfOZdRoug
Zmanda Cloud Backup enables adherence to HIPAA compliance for data backed up to the cloud.
Posted by: Zmanda | July 02, 2010 at 01:55 PM