apointoo.
HIPAA

Azure vs AWS vs Google Cloud for a HIPAA Workload

cmsapointoo··9 min read

Short answer: Azure, AWS, and Google Cloud can each be evaluated for a HIPAA workload, but the provider choice is only one part of the decision. Compare the current BAA process, covered-service lists, regions, support and subprocessor paths, customer controls, and operator evidence. As of August 15, 2026, no provider agreement or service list makes an application compliant by itself.

Vendor scope and BAA boundary

Microsoft’s HIPAA and HITECH offering, AWS’s HIPAA eligible-services reference, and Google Cloud’s HIPAA compliance material describe provider commitments and covered services. Each page must be read with the current agreement and service terms. A list of covered products is not a deployment approval, and a signed BAA does not settle application configuration, legal status, or tenant isolation.

Start by naming the workload and its data flows. Which service receives the booking, which service stores it, where are backups and logs, which keys protect it, who supports it, and what downstream service receives a copy? Then compare whether Azure, AWS, or Google Cloud documents and contracts that exact path. If one provider requires a feature or tier that the design does not use, do not infer coverage from the provider’s general healthcare page.

Record source and pricing observations as of August 15, 2026. Service eligibility, region availability, plan terms, and support options change. Estimates should be labelled and recalculated before procurement.

Compare agreement and service scope

Decision axis Azure AWS Google Cloud
Agreement Confirm current HIPAA offering and contractual scope. Confirm current BAA and organization or account path. Confirm current BAA and covered-product terms.
Service list Match each Azure service to the audit-scope documentation. Match each service to the eligible-services reference. Match each product and feature to current compliance documentation.
Regions Verify workload, backup, log, key, and support locations. Verify selected region and cross-region copies. Verify selected region, data location, and support path.
Operations Assign customer identity, application, and evidence controls. Assign IAM, application, logging, backup, and key owners. Assign project, identity, application, logging, backup, and key owners.

The table is a comparison framework, not a claim that all three providers have identical scope. Reopen each official page for the service and account actually planned. Ask procurement to retain the effective agreement and security exhibits.

Feature, region, and subprocessor review

Cloud geography is more than a compute setting. Map database, object storage, queues, logs, monitoring, key management, backups, build artifacts, support access, and subprocessors. A regional deployment can still send control metadata or support information elsewhere. If a tenant has a residency requirement, document the approved region and the legal transfer analysis separately.

Use a responsibility matrix:

  • Provider: underlying facilities, defined service operations, provider-side safeguards, and documented commitments.
  • Customer: identities, MFA, tenant authorization, data fields, keys, logs, retention, backups, incident process, and application code.
  • Shared: vulnerability response, configuration changes, evidence requests, and incident coordination.

For Google Ads, all three options use the same data-minimization rule. Allow only generic conversion data after tenant-specific legal approval. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. Keep the outbound route off by default. Cloud choice does not answer advertising policy or state privacy questions.

Use the managed versus raw-cloud comparison, the hosting operations review, and the region-scope guide for adjacent options.

Operator fit and evidence

Choose the platform the team can operate safely. A service is not a control until an owner can configure it, test it, detect failure, respond to an incident, restore a backup, and produce evidence. Compare the work required for:

  • identity and least privilege across accounts, subscriptions, projects, and service roles;
  • network boundaries, private access, secure transport, and administrative paths;
  • encryption, key creation, rotation, recovery, and deletion;
  • audit logging, monitoring, retention, alerting, and redaction;
  • backup, restore, deletion, tenant offboarding, and regional restrictions;
  • deployment, rollback, vulnerability response, incident notification, and support.

NIST control guidance can structure the evidence but cannot certify the design. A provider BAA, assessment, region, or plan tier does not make the application compliant. Use a dated risk analysis with current facts.

Exit, support, and evidence questions

Run the same non-production proof on each shortlisted platform. Use synthetic tenants and records. Test allowed and denied access, logging redaction, key use, backup restore, region enforcement, support approval, export, deletion, and a disabled outbound conversion path. Measure effort and record failures; those results are more useful than a feature checklist.

Gate Pass condition Stop condition
Contract Current BAA and service scope match the architecture. General healthcare marketing is the only evidence.
Region Data, logs, backups, keys, and support are mapped. Compute region is treated as complete residency proof.
Operations Named owner can operate and evidence controls. Critical service has no trained owner.
Exit Export, restore, revoke, and deletion are tested. Copies or keys cannot be enumerated.

Escalate when a provider’s service list is ambiguous, a customer contract requires dedicated isolation, support crosses a jurisdiction, a region lacks a needed service, or a proposed outbound disclosure is not approved. Do not hide the issue in a migration estimate.

Comparison decision checklist

  1. Define workload, data, roles, regions, services, and legal parties.
  2. Read current Azure, AWS, and Google Cloud agreement and covered-service material.
  3. Map provider, customer, and shared controls.
  4. Compare operator hours, evidence burden, recovery, exit, and estimates.
  5. Run the same synthetic-data test on shortlisted options.
  6. Obtain counsel, security, procurement, and tenant approval before production.

The best cloud is the one that leaves the fewest unowned controls for the real team. If evidence cannot be produced, the platform is not ready for the workload regardless of its published offering.

Compare one workload, not three marketing pages

Create a common worksheet before comparing vendors. List the request path, runtime, database, files, queues, keys, logs, backups, support identities, build pipeline, region, and outbound destinations. Give each provider the same questions. If a service is not needed for the workload, do not score it as an advantage. If a required service is unavailable in the approved region, record that as a decision constraint.

Use the same synthetic-data test on each platform. Create two tenants, exercise allowed and denied reads and writes, inspect logs, run a backup and restore, review a support access event, export the minimum fields, and verify deletion. Record operator time and remediation. A provider may have a strong service list but still be a poor fit if the team cannot operate or evidence the selected path.

Question Why it matters Owner
Who signs the BAA? Confirms legal parties and effective relationship. Counsel and procurement.
Which services are covered? Avoids assuming a connected tool inherits scope. Platform and procurement.
Where is support performed? Remote access can create transfer and residency questions. Privacy and security.
What is the exit path? Prevents backup, key, or log copies being stranded. Engineering and records owner.
What is the cost? Separates cloud estimate from migration and compliance work. Finance and product.

Keep all cost numbers labelled as estimates with workload, region, currency, and retrieval date. A provider price page is not a quote. A compliance add-on is not a compliance program. Contract and risk work can exceed raw request charges.

Keep advertising outside the cloud comparison

Azure, AWS, and Google Cloud do not answer whether a health-linked conversion is appropriate for Google Ads. If tenant-specific counsel approves a generic conversion design, use only the approved click signal, generic action, value if approved, and opaque deduplication reference. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. Queue server-side and keep the default off.

If counsel rejects per-booking sync, the cloud architecture should still support aggregate campaign reporting. This fallback reduces the need to move sensitive booking context to an advertising destination and avoids making the hosting decision carry an unrelated legal conclusion.

Revisit the comparison after proof

Do not finalize a platform from a proposal alone. Reopen the comparison after a non-production migration, database slice, restore exercise, support review, and contract check. Note which assumptions changed. A platform that looks cheapest at request volume can have a higher fixed cost for logs, load balancing, backups, or always-on database capacity. A platform that appears complex may reduce engineering work through managed services.

Keep the comparison open until the database slice, restore exercise, and contract review agree. A provider preference is not evidence that the selected workload can be operated safely.

FAQ

What is the first verification step for Azure, AWS, and Google Cloud HIPAA?

List exact services, regions, data paths, support paths, backups, logs, and keys, then match each to current provider and agreement documentation.

Which source or configuration detail could change the answer?

Covered-service lists, agreement terms, region availability, feature configuration, support access, subprocessor, or customer contract can change the result.

Is one cloud automatically safer for HIPAA?

No. Operator skill, architecture, tenant isolation, evidence, and legal scope matter more than a brand comparison.

What must be approved before a production claim or outbound action?

Approve current provider scope, controls, regions, risk analysis, contract, and payload. For Google Ads, require tenant-specific legal approval and keep the event off.

References

Related articles