Join our Newsletter — 33% off our NHI Course

Who is accountable for HIPAA compliance when a business uses cloud services?

Accountability stays with the covered entity and its business associates, even when cloud providers host the data. Providers must support compliance through appropriate safeguards and a BAA, but the organisation using the service still owns risk assessment, policy enforcement, access governance, monitoring, and breach response. Delegating infrastructure never delegates responsibility.

Why This Matters for Security Teams

Cloud outsourcing changes where data lives, not where accountability sits. For HIPAA, the covered entity and its business associates still need to prove they selected appropriate services, signed a business associate agreement, and maintained safeguards across the full lifecycle of protected health information. A provider can offer secure infrastructure, but it cannot absorb the organisation’s obligation to assess risk, define access rules, monitor use, and coordinate incident response. That principle aligns with the control logic in NIST Cybersecurity Framework 2.0, where governance and risk ownership remain with the adopting organisation.

Teams often get this wrong by treating the cloud contract as a compliance substitute. In practice, that leads to gaps between policy and configuration, especially when identity controls, logging, encryption, and retention settings are left to default service behaviour. HIPAA does not require a specific cloud model, but it does require defensible oversight. Current guidance suggests that compliance evidence must show how the organisation manages vendor scope, data handling, and ongoing monitoring, not merely how the provider markets its controls. In practice, many security teams encounter HIPAA failure only after a breach review reveals that the cloud provider was assumed to be the control owner rather than the service enabler.

How It Works in Practice

Operational accountability starts with role clarity. The covered entity decides whether the cloud service will store, process, transmit, or back up protected health information, then determines whether the provider is a business associate. If so, the parties need a business associate agreement that defines permitted uses, reporting timelines, subcontractor obligations, and return or destruction terms. That legal step is necessary, but not sufficient. The organisation still has to implement administrative, physical, and technical safeguards across the service configuration, identity layer, and monitoring stack.

Practically, that means security teams should map HIPAA obligations to cloud controls and verify them continuously. Useful baselines include NIST SP 800-53 Rev 5 Security and Privacy Controls, which helps translate HIPAA intent into access control, audit logging, contingency, and system integrity requirements, and ISO/IEC 27001:2022 Information Security Management, which supports governance, ownership, and continual improvement. Common implementation steps include:

  • Define which cloud services process protected health information and document the responsible business owner.
  • Ensure the BAA covers logging, incident notice, subcontractors, and data return or deletion.
  • Apply least privilege, strong authentication, and periodic access review for administrators and application users.
  • Confirm encryption, key management, backup protection, and retention settings are configured and tested.
  • Review audit logs, alerting, and incident workflows so that abnormal access is detected and investigated quickly.

This is also where shared responsibility models create confusion: the provider may secure the platform, but the customer usually secures the data, identities, policies, and application-level controls. Organisations should validate that cloud-native services are actually configured to match policy, rather than assuming compliance because the service is certified. These controls tend to break down when multiple teams provision cloud workloads independently and no single owner reconciles contract terms, identity settings, and logging coverage.

Common Variations and Edge Cases

Tighter control often increases administrative overhead, requiring organisations to balance faster cloud adoption against stronger governance and evidence collection. The main edge case is when the cloud provider is not merely hosting data but also performing operational functions such as managed analytics, messaging, or support access. In those cases, the compliance surface broadens, and the business associate relationship may extend to subcontractors and service chains. Best practice is evolving around how much independent assurance is enough for those dependencies, so there is no universal standard for this yet.

Another variation is multi-tenant or hybrid deployment, where one system spans public cloud, on-premises assets, and third-party APIs. That environment makes boundary definition harder, especially for incident response and data deletion. Organisations should not assume that a provider’s attestation replaces internal control testing. Instead, they should align cloud oversight with governance and control families in ISO/IEC 27002:2022 Information Security Controls and the shared accountability model reflected in HIPAA risk management practice. If the environment includes payment workflows or identity proofing tied to financial data, related obligations may also intersect with FATF Recommendations for KYC and AML control expectations. The practical boundary is simple: once the organisation can influence configuration, access, or data handling, it remains accountable for the outcome even if the cloud provider operates the underlying service.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 Cloud HIPAA accountability depends on clear organisational outcomes and ownership.
NIST SP 800-63 Identity proofing and authentication quality affect who can access cloud-hosted PHI.

Assign HIPAA cloud accountability to named owners and document the expected security outcomes.