The cloud did not change HIPAA’s rules; it changed who was holding the evidence. OCR resolved the definitional debate back in 2016, storage is maintenance, maintenance means business associate, no decryption key required, and the hyperscalers responded with standard BAAs and eligible-service lists. What remains unresolved, breach after breach, is the customer half of shared responsibility: the public bucket, the unlogged admin account, the eligible service configured ineligibly. A signed BAA plus a misconfigured console is still a reportable breach, just one with better paperwork.
| CSP status | Business associate (even no-view, encrypted storage) |
|---|---|
| Guidance | OCR Cloud Computing Guidance (2016) |
| BAA scope | Eligible/covered services lists only |
| CSP owns | Security of the cloud (infrastructure) |
| You own | Security in the cloud (config, IAM, keys, logs) |
| Top breach vector | Customer misconfiguration |
Getting cloud HIPAA right
Gate architecture on the eligible list. Every component in an ePHI workload, including logging and AI services, gets checked against the BAA’s service list before deployment; the BAA guide covers the contract layer.
Treat configuration as the compliance surface. CSPM or provider posture tools plus periodic IAM review operationalize the Security Rule in cloud terms; feed findings into the risk analysis.
Own your keys and your logs. Documented key management and reviewed audit logs are the two artifacts OCR asks for first after a cloud incident; the breach playbook shows how discovery timing turns on them.
Chain the BAAs upward. SaaS on IaaS means two business associates, not one, map the full stack in the vendor inventory per the compliance roadmap.
Cloud-hosted patient portals still leak through client-side trackers: check what your web layer discloses with a free scan.