Compliance in the cloud
Elevate your operations with AWS, designed to meet rigorous compliance standards including HIPAA, HITRUST, GxP, and more.
Unlocking Innovation with Secure, Compliant Cloud Services
HIPAA Compliance
- HIPAA eligibility maintained by AWS across applicable services
- Streamlined process for executing Business Associate Agreements (BAAs)
- Built-in technical safeguards to protect Protected Health Information (PHI)
- Comprehensive audit trails and fine-grained access controls for enhanced oversight

GxP Compliance
- Reduced time to provision, configure, and test GxP compliance-aligned infrastructure
- Seamless inheritance of global security and compliance controls
- Continuous monitoring and alerting

Comprehensive Security Controls
- End-to-end encryption for data in transit and at rest
- Granular Identity and Access Management (IAM)
- Network isolation and segmentation
- 24/7 infrastructure monitoring and threat detection

Global Compliance Framework
- HITRUST CSF Certified
- SOC 1, 2, and 3 reports
- ISO 27001, 27017, and 27018
- GDPR and regional data protection standards

Building Secure Solutions Together
Compliance is a Shared Responsibility. We believe in transparent security partnerships. While AWS manages the security OF the cloud, you maintain complete control over your security IN the cloud.

What AWS Provides

Shared Responsibility

Your Data, Your Control
GxP Compliance on AWS
With access to purpose-built solutions, technical resources, and a team of GxP experts, AWS makes it easier for life sciences organizations to establish a GxP-alignment environment that reduces costs, improves security, and enhances agility.
Automate GxP compliance
Automate GxP compliance
AWS provides the tools and guidance to automate GxP compliance so you can move fast while staying compliant.
Learn more

Introduce automatic traceability
Use AWS to automatically log activities in your environment to support audit requests.

Develop a consistent and controllable infrastructure
Create templates to use your infrastructure throughout your organization, and control over who can affect elements of your infrastructure software and when.
