HIPAA requires healthcare organizations moving to the cloud to execute a Business Associate Agreement (BAA) with every cloud service provider that stores, processes, or transmits ePHI; conduct a risk analysis that includes the cloud environment in scope; and implement technical safeguards that apply to cloud-hosted systems under the same standards as on-premises ones. Moving to the cloud doesn’t transfer compliance obligations; rather, it adds new ones.
Does HIPAA Apply to Cloud Storage and Cloud-Hosted Systems?
HIPAA applies fully to cloud-hosted systems and cloud storage that contain, process, or transmit ePHI. The physical location of the system, whether on-premises server, private cloud, or public cloud infrastructure, doesn’t change the covered entity’s obligation to protect the information it contains.
This is a point that creates recurring compliance gaps. Healthcare organizations tend to dangerously treat cloud adoption as a transfer of responsibility: once the data is in a cloud vendor’s environment, the vendor is handling compliance. That’s not how HIPAA works. The covered entity remains responsible for the security of ePHI regardless of where it lives. The cloud vendor may have its own security certifications and controls, but those don’t extend to the covered entity’s obligations.
The relevant question for every cloud adoption decision isn’t “is this vendor secure?” It’s “does moving this workload to the cloud create new risks or access pathways that our current risk analysis doesn’t account for, and have we implemented the controls and documentation that HIPAA requires for this environment?”
What HIPAA Requirements Apply Specifically to Cloud Environments?
Four HIPAA requirements carry specific implications for cloud environments: Business Associate Agreements, risk analysis, access controls, and encryption and audit logging.
Business Associate Agreements: Any cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a Business Associate under HIPAA. This includes cloud storage platforms, cloud-hosted EHR systems, SaaS applications that process patient data, and cloud infrastructure providers whose services touch ePHI. A BAA must be in place before ePHI moves to the platform. HHS has issued specific guidance confirming that cloud service providers acting as conduits for ePHI meet the definition of Business Associate.
Risk analysis: HIPAA’s Security Rule requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI. When a healthcare organization adds cloud systems to its environment, the risk analysis must be updated to reflect the new attack surface, access pathways, and configuration-specific risks those systems introduce. A risk analysis that doesn’t include cloud-hosted systems containing ePHI is incomplete.
Access controls: The Security Rule’s access control standard, which ensures that only authorized individuals can access ePHI, applies equally to cloud environments. In cloud platforms, access control failures often look different than in on-premises systems: overly permissive sharing settings, misconfigured storage buckets, service accounts with excessive privileges, and third-party integrations with unnecessary access to cloud-hosted data. These are configuration issues, not technical limitations, and they require active management.
Encryption and audit logging: The Security Rule addresses encryption of ePHI in transit and at rest. In cloud environments, both need to be confirmed as active and properly configured. Audit logging, which records who accessed what and when, is a required safeguard that cloud environments must implement and that the organization must be able to retrieve and review.
What Are the Most Common HIPAA Cloud Compliance Mistakes?
The most common HIPAA cloud compliance mistakes are missing Business Associate Agreements; misconfigured access permissions; incomplete risk analysis scope; and assumptions about vendor compliance that don’t hold under scrutiny.
- Missing BAAs: Healthcare organizations frequently adopt cloud services such as collaboration tools; backup solutions; productivity platforms; and SaaS applications, without identifying whether those services handle ePHI and whether a BAA is required. A cloud tool that an administrator uses to share patient-related documents, even occasionally, may trigger the BAA requirement.
- Misconfigured permissions: Cloud platforms default to configurations that prioritize access and convenience. Restricting those defaults, such as limiting sharing; tightening storage permissions; and removing unnecessary integrations; requires active configuration management. Default settings in major cloud platforms are frequently not HIPAA-compliant out of the box.
- Scope gaps in risk analysis: Organizations that have conducted HIPAA risk analyses for their on-premises environments often haven’t updated them to reflect cloud migrations. Each cloud workload added to the environment expands the ePHI footprint and the risk surface that the risk analysis is required to cover.
- Vendor compliance assumptions: A vendor’s SOC 2 certification or HIPAA compliance attestation describes their controls, not yours. It doesn’t confirm that your configuration of their platform meets HIPAA requirements, or that the BAA terms are sufficient, or that your staff is using the platform in a compliant way.
Vertikal6 has encountered healthcare organizations that migrated to a cloud platform under the assumption that the vendor’s HIPAA-eligible service designation covered their compliance obligations, only to find later that a specific configuration gap or missing Business Associate Agreement (BAA) created exposure the organization wasn’t aware of.
How Should Healthcare Organizations Manage HIPAA Compliance After a Cloud Migration?
After a cloud migration, healthcare organizations should treat the cloud environment as a permanent addition to their compliance program, not a one-time project to complete and set aside.
The ongoing management requirements include:
- BAA inventory maintenance: Track every cloud service that touches ePHI, confirm a current BAA is in place, and review BAA terms when vendor agreements change.
- Configuration review: Conduct periodic reviews of access permissions, sharing settings, and integrations in cloud platforms containing ePHI. Cloud configurations change, via ways such as updates, new features, and user behavior. These scenarios can create compliance gaps over time.
- Risk analysis updates: Revisit the risk analysis when cloud workloads change significantly, when new services are added, or when the organization’s use of existing services expands.
- Workforce training: Staff who use cloud platforms to handle ePHI need specific training on compliant use: what can be shared, through which tools, with whom, and under what circumstances.
Vertikal6’s ADVANTAGE service supports healthcare organizations through cloud migration compliance planning and ongoing HIPAA program management. The controls that HIPAA requires in a cloud environment aren’t fundamentally different from what it requires on-premises. What’s different is how they’re implemented; and that difference requires specific, current knowledge of the platforms in use.