Skip to content

HIPAA safeguards

Important: Frond is not a medical device and does not market itself for PHI. This page documents how the architecture satisfies the HIPAA Security Rule safeguards if a covered entity or business associate chooses to store PHI in canvases (e.g., clinical sketches). PHI in a drawing app should be minimized by policy; see the data-retention guide.

Prerequisite: the BAA

  • The operator must have a Business Associate Agreement (BAA) with AWS (standard AWS BAA) and, when the app is multi-tenant, with any processors.
  • The services used are HIPAA-eligible: S3, DynamoDB, Lambda, API Gateway, Cognito, CloudFront, CloudWatch, KMS, WAF. (CodePipeline and CodeBuild are not HIPAA-eligible — build artifacts must never contain PHI; this repo’s pipeline only moves code, never customer data.)
  • Published/share links are opt-in; PHI should never be published.

Administrative safeguards

StandardImplementation
§164.308(a)(1) Security management processRisk analysis (SOC 2 guide threat model); quarterly review
§164.308(a)(3) Workforce securityLeast-privilege IAM; offboarding runbook; quarterly access review
§164.308(a)(4) Information access managementPer-document ownership checks; no cross-tenant access paths
§164.308(a)(5) Security awarenessAnnual training (pre-launch)
§164.308(a)(6) Security incidentsIncident-response runbook with breach notification (60-day) workflow
§164.308(a)(7) Contingency planDR runbook, tested twice a year

Physical safeguards — §164.310

AWS-managed data centers (inherited via AWS BAA; AWS SOC 2/ISO 27001 reports). Workstation controls for staff with production access.

Technical safeguards

StandardImplementation
§164.312(a)(1) Access controlUnique Cognito identities, MFA, JWT authorization, token revocation, session timeouts
§164.312(a)(2) Audit controlsCloudTrail (org, multi-region, KMS-encrypted), CloudWatch logs, S3 versioning, CloudFront access logs
§164.312(b) IntegrityS3 versioning + DynamoDB PITR; TLS prevents in-transit tampering; revision model
§164.312(c)(1) Person/entity authenticationCognito (password policy, adaptive auth, MFA)
§164.312(c)(2) Transmission securityTLS 1.2+ everywhere; presigned URLs with 10-minute expiry

Required and addressable implementation decisions

  • Encryption (addressable): implemented — KMS CMKs with rotation for documents, metadata, and logs. Decision documented and reviewed.
  • Automatic logoff (addressable): implemented at the app level (token expiry + refresh) and API level (JWT expiry, 1 hour).
  • ePHI minimization: presigned URLs carry no PHI in query strings beyond the key path; Lambda logs never include document names or content.

Breach notification workflow (summary)

  1. Detect (GuardDuty/alarm/customer report) → 2. contain (revoke publishing, rotate keys, block access) → 3. assess scope from CloudTrail/S3 logs → 4. notify (60-day HIPAA clock; state clocks may be shorter) → 5. remediate and post-incident review. Full runbook in the incident-response guide.