Practical reference
HIPAA-Eligible Services Lookup: AWS, Google Cloud, Azure
Last verified 2026-09-26. Vendor terms and prices change; every row links to its source.
A service marked “HIPAA eligible” (AWS), “covered” (Google Cloud) or “in HIPAA BAA scope” (Azure) is one the provider's Business Associate Agreement covers when you configure it the way the provider's guidance says. It does not make your workload compliant. Access control, encryption settings, audit logging, backups and your own policies are still your responsibility.
The lists change every few months, so the date matters. This lookup transcribes all three official lists, shows when each was last checked, and links every row to its source. Have the provider's BAA in place before any PHI reaches a service.
Look up a service
Showing 60 of 515 matching services (515 listed across all three providers).
| Provider | Service | Category | Notes | Source |
|---|---|---|---|---|
| AWS | Alexa for Business | Other | Healthcare skills only; requires the Alexa Skills BAA (see AWS HIPAA whitepaper). | AWS list |
| AWS | AWS Amplify Console | Developer & ops tools | None listed | AWS list |
| AWS | Amazon API Gateway | Integration & messaging | None listed | AWS list |
| AWS | AWS App Mesh | Networking | None listed | AWS list |
| AWS | AWS AppFabric | Integration & messaging | None listed | AWS list |
| AWS | Amazon AppFlow | Integration & messaging | None listed | AWS list |
| AWS | AWS Application Migration Service | Compute | None listed | AWS list |
| AWS | Amazon Application Recovery Controller | Networking | None listed | AWS list |
| AWS | AWS AppSync | Integration & messaging | None listed | AWS list |
| AWS | Amazon Athena | Analytics & data | None listed | AWS list |
| AWS | AWS Audit Manager | Security & identity | None listed | AWS list |
| AWS | Amazon Augmented AI | AI & ML | Excludes Public Workforce and Vendor Workforce for all features. | AWS list |
| AWS | Amazon Aurora | Database | Listed separately from RDS on the AWS page. | AWS list |
| AWS | AWS B2B Data Interchange | Integration & messaging | None listed | AWS list |
| AWS | AWS Backup | Storage | None listed | AWS list |
| AWS | AWS Batch | Compute | None listed | AWS list |
| AWS | Amazon Bedrock | AI & ML | None listed | AWS list |
| AWS | Amazon Bedrock AgentCore | AI & ML | None listed | AWS list |
| AWS | AWS Certificate Manager | Security & identity | None listed | AWS list |
| AWS | Amazon Chime | Integration & messaging | None listed | AWS list |
| AWS | Amazon Chime SDK | Integration & messaging | None listed | AWS list |
| AWS | AWS Clean Rooms | Analytics & data | None listed | AWS list |
| AWS | AWS Cloud 9 | Developer & ops tools | None listed | AWS list |
| AWS | Amazon Cloud Directory | Security & identity | None listed | AWS list |
| AWS | AWS Cloud Map | Networking | None listed | AWS list |
| AWS | AWS CloudEndure | Storage | None listed | AWS list |
| AWS | AWS CloudFormation | Developer & ops tools | None listed | AWS list |
| AWS | Amazon CloudFront | Networking | Excludes content delivery through CloudFront Embedded Points of Presence. | AWS list |
| AWS | AWS CloudHSM | Security & identity | None listed | AWS list |
| AWS | AWS CloudShell | Developer & ops tools | None listed | AWS list |
| AWS | AWS CloudTrail | Security & identity | None listed | AWS list |
| AWS | Amazon CloudWatch | Developer & ops tools | None listed | AWS list |
| AWS | Amazon CloudWatch Logs | Developer & ops tools | None listed | AWS list |
| AWS | Amazon CloudWatch SDK Metrics | Developer & ops tools | None listed | AWS list |
| AWS | AWS CodeBuild | Developer & ops tools | None listed | AWS list |
| AWS | AWS CodeCommit | Developer & ops tools | None listed | AWS list |
| AWS | AWS CodeDeploy | Developer & ops tools | None listed | AWS list |
| AWS | AWS CodePipeline | Developer & ops tools | None listed | AWS list |
| AWS | Amazon Cognito | Security & identity | None listed | AWS list |
| AWS | Amazon Comprehend | AI & ML | None listed | AWS list |
| AWS | Amazon Comprehend Medical | AI & ML | None listed | AWS list |
| AWS | AWS Config | Security & identity | None listed | AWS list |
| AWS | Amazon Connect | Integration & messaging | None listed | AWS list |
| AWS | Amazon Connect Health | Integration & messaging | An HCLS service; the Healthcare and Life Sciences Addendum applies. | AWS list |
| AWS | AWS Control Tower | Developer & ops tools | None listed | AWS list |
| AWS | AWS Data Exchange | Analytics & data | None listed | AWS list |
| AWS | AWS Database Migration Service (DMS) | Database | None listed | AWS list |
| AWS | AWS DataSync | Storage | None listed | AWS list |
| AWS | Amazon DataZone | Analytics & data | None listed | AWS list |
| AWS | Amazon Detective | Security & identity | None listed | AWS list |
| AWS | AWS DevOps Agent | Developer & ops tools | None listed | AWS list |
| AWS | Amazon DevOps Guru | AI & ML | None listed | AWS list |
| AWS | AWS Direct Connect | Networking | None listed | AWS list |
| AWS | AWS Directory Service | Security & identity | Excludes Simple AD. | AWS list |
| AWS | Amazon DocumentDB | Database | With MongoDB compatibility. | AWS list |
| AWS | Amazon DynamoDB | Database | None listed | AWS list |
| AWS | Amazon EC2 Auto Scaling | Compute | None listed | AWS list |
| AWS | Amazon ElastiCache | Database | None listed | AWS list |
| AWS | AWS Elastic Beanstalk | Developer & ops tools | None listed | AWS list |
| AWS | Amazon Elastic Block Store (Amazon EBS) | Storage | None listed | AWS list |
How to read these lists
- Shared responsibility. The provider secures the service underneath; you secure how you use it: identity and access, encryption keys, network exposure, audit logging and retention. AWS, Google and Microsoft all say customers remain responsible for their own HIPAA compliance.
- Configuration conditions. Coverage assumes you follow the provider's guidance. Google, for example, says to keep PHI out of resource metadata, monitoring labels and build configs, because those can surface in logs.
- Sub-features can be excluded. An eligible service can carve out features. SageMaker AI excludes Studio Lab and Ground Truth Plus, RDS covers six named engines, and Fargate covers the ECS and EKS engines only. Read the Notes column before you design around a service.
- Region differences. Google says its BAA covers all regions. Microsoft publishes a separate list for Azure Government; this page covers the Azure public cloud. A listed service may still not be offered in the region your contract or latency needs require.
- Preview services. Google says not to use Pre-GA offerings with PHI unless their terms say otherwise, and AWS extends eligibility to generally available features. Treat preview features as uncovered until the provider lists them.
Services the providers say are not covered
Only exclusions a provider states in its own documentation are listed here. If a service is simply missing from a list, treat it as not covered and keep PHI out of it.
| Provider | Service or feature | What the provider says | Source |
|---|---|---|---|
| AWS | Amazon SageMaker Studio Lab | Explicitly excluded from the SageMaker AI entry. | Source |
| AWS | Amazon SageMaker Ground Truth Plus | Explicitly excluded from the SageMaker AI entry, as are Public and Vendor Workforce. | Source |
| AWS | AWS Directory Service Simple AD | Explicitly excluded from the Directory Service entry. | Source |
| AWS | CloudFront Embedded Points of Presence | Explicitly excluded from the CloudFront entry. | Source |
| AWS | Amazon Pinpoint voice messages and WhatsApp channel | Explicitly excluded from the Pinpoint and End User Messaging entry. | Source |
| Google Cloud | Pre-GA (preview) Google Cloud offerings | Google says not to use Pre-GA offerings with PHI unless the offering's terms expressly allow it. | Source |
| Google Cloud | Firebase Realtime Database | Not on the covered-products list; Firebase's terms say Firebase Services are not intended to create HIPAA obligations. | Source |
| Google Cloud | Firebase Hosting | Not on the covered-products list; Firebase's terms say Firebase Services are not intended to create HIPAA obligations. | Source |
| Google Cloud | Firebase Cloud Messaging | Not on the covered-products list; Firebase's terms say Firebase Services are not intended to create HIPAA obligations. | Source |
| Azure | Playwright | Listed in Appendix A without the HIPAA BAA mark. | Source |
| Azure | Azure Kubernetes Service on Azure Stack HCI | Listed in Appendix A without the HIPAA BAA mark. | Source |
| Azure | Azure Data Manager for Energy | Listed in Appendix A without the HIPAA BAA mark. | Source |
| Azure | Azure Operator Nexus | Listed in Appendix A without the HIPAA BAA mark. | Source |
| Azure | Azure Private and Public Multi-access Edge Compute (MEC) | Listed in Appendix A without the HIPAA BAA mark. | Source |
Related
- AWS vs Google Cloud vs Azure for healthcare software — BAA process, managed Postgres, key management and audit logging side by side.
- Which vendors sign a HIPAA BAA, and on which plan — the SaaS and AI tools around your cloud account.
- AWS HIPAA eligible services: complete list and what's not covered — a longer walkthrough of the AWS list, with an example RDS configuration.
Planning a build that will store PHI? Opexia maps your architecture to these lists before the first record is written. Talk to us about your project.
Sources
- AWS: HIPAA Eligible Services Reference — last updated 2026-09-03, retrieved 2026-09-26
- Google Cloud: HIPAA Compliance on Google Cloud: Covered Products — last updated 2026-09-17, retrieved 2026-09-26
- Microsoft Azure: HIPAA (US) compliance offering — service list from the linked Azure Compliance Offerings document, Appendix A (published 2026-09-09), retrieved 2026-09-26; the BAA is in the Product Terms and DPA
Questions this page answers
Are Amazon RDS and Aurora HIPAA eligible?
Yes. AWS lists Amazon RDS for the SQL Server, MySQL, Oracle, PostgreSQL, Db2 and MariaDB engines only, and lists Amazon Aurora as a separate entry. You still need the AWS BAA in place and must configure encryption, access control and logging yourself.
Are Amazon Bedrock, Rekognition and SageMaker AI covered by the AWS BAA?
All three are on the AWS list, along with Bedrock AgentCore. SageMaker AI carries exclusions: Studio Lab, Ground Truth Plus, and the Public and Vendor Workforce options are not eligible. Amazon Augmented AI excludes the same workforce options.
Is Firebase covered by Google's HIPAA BAA?
Partly. Google's covered-products list names Firestore, Cloud Storage and Identity Platform, but no Firebase-branded product. Plain Firebase Authentication is not named; Identity Platform, its upgrade path, is. Firebase Hosting, Realtime Database and Cloud Messaging are not on the list, and Firebase's own terms say its services are not intended to create HIPAA obligations.
Are Cloud SQL and Vertex AI covered on Google Cloud?
Cloud SQL is on the covered list. Vertex AI now appears under Gemini Enterprise Agent Platform names (the platform, Generative AI on it, and Agent Search), plus Vertex AI Workbench instances. Google also says Pre-GA features should not be used with PHI.
Is Azure OpenAI covered by Microsoft's HIPAA BAA?
Azure OpenAI is not listed by that name. Microsoft's August 2026 compliance document marks "Microsoft Foundry: Foundry Models" as in HIPAA BAA scope, limited to Foundry Models sold by Azure, which include the Azure OpenAI models. Components run by third-party model providers are excluded unless stated otherwise.
Are Cosmos DB, Azure Functions and App Service in HIPAA BAA scope?
Yes. Azure Cosmos DB, Azure Functions and App Service (Web Apps, API Apps and App Center) are all marked HIPAA BAA in Appendix A of the Azure Compliance Offerings document. Microsoft's BAA applies through the Product Terms, so there is no separate contract to sign.
Are S3, Lambda, ECS and EKS HIPAA eligible on AWS?
Yes. Amazon S3, S3 Glacier, AWS Lambda, Amazon ECS and Amazon EKS are all on the AWS list. AWS Fargate is eligible for the ECS and EKS engines only.