HIPAA safeguards
Important: Frond is not a medical device and does not market itself for PHI. This page documents how the architecture satisfies the HIPAA Security Rule safeguards if a covered entity or business associate chooses to store PHI in canvases (e.g., clinical sketches). PHI in a drawing app should be minimized by policy; see the data-retention guide.
Prerequisite: the BAA
- The operator must have a Business Associate Agreement (BAA) with AWS (standard AWS BAA) and, when the app is multi-tenant, with any processors.
- The services used are HIPAA-eligible: S3, DynamoDB, Lambda, API Gateway, Cognito, CloudFront, CloudWatch, KMS, WAF. (CodePipeline and CodeBuild are not HIPAA-eligible — build artifacts must never contain PHI; this repo’s pipeline only moves code, never customer data.)
- Published/share links are opt-in; PHI should never be published.
Administrative safeguards
| Standard | Implementation |
|---|---|
| §164.308(a)(1) Security management process | Risk analysis (SOC 2 guide threat model); quarterly review |
| §164.308(a)(3) Workforce security | Least-privilege IAM; offboarding runbook; quarterly access review |
| §164.308(a)(4) Information access management | Per-document ownership checks; no cross-tenant access paths |
| §164.308(a)(5) Security awareness | Annual training (pre-launch) |
| §164.308(a)(6) Security incidents | Incident-response runbook with breach notification (60-day) workflow |
| §164.308(a)(7) Contingency plan | DR runbook, tested twice a year |
Physical safeguards — §164.310
AWS-managed data centers (inherited via AWS BAA; AWS SOC 2/ISO 27001 reports). Workstation controls for staff with production access.
Technical safeguards
| Standard | Implementation |
|---|---|
| §164.312(a)(1) Access control | Unique Cognito identities, MFA, JWT authorization, token revocation, session timeouts |
| §164.312(a)(2) Audit controls | CloudTrail (org, multi-region, KMS-encrypted), CloudWatch logs, S3 versioning, CloudFront access logs |
| §164.312(b) Integrity | S3 versioning + DynamoDB PITR; TLS prevents in-transit tampering; revision model |
| §164.312(c)(1) Person/entity authentication | Cognito (password policy, adaptive auth, MFA) |
| §164.312(c)(2) Transmission security | TLS 1.2+ everywhere; presigned URLs with 10-minute expiry |
Required and addressable implementation decisions
- Encryption (addressable): implemented — KMS CMKs with rotation for documents, metadata, and logs. Decision documented and reviewed.
- Automatic logoff (addressable): implemented at the app level (token expiry + refresh) and API level (JWT expiry, 1 hour).
- ePHI minimization: presigned URLs carry no PHI in query strings beyond the key path; Lambda logs never include document names or content.
Breach notification workflow (summary)
- Detect (GuardDuty/alarm/customer report) → 2. contain (revoke publishing, rotate keys, block access) → 3. assess scope from CloudTrail/S3 logs → 4. notify (60-day HIPAA clock; state clocks may be shorter) → 5. remediate and post-incident review. Full runbook in the incident-response guide.