Hacker News new | ask | show | jobs
by Seb86 4345 days ago
but once you have the BAA , does Amazon force you to run the dedicated instance 24/7 ? I'm very confused , just running an app on a dedicated instance, does not make it HIPAA compliant since the app needs encryption in-transit and at-rest to be HIPAA compliant. You can achieve that on a regular instance ...
1 comments

The BAA only applies to the dedicated instances—in particular, you have to VPC them—you cannot achieve HIPAA compliance with a non-dedicated instance.