Does HIPAA Require US Data Residency for Cloud Workloads
HIPAA does not impose a blanket US-only storage rule for cloud workloads. HHS guidance says a covered entity or business associate may use a cloud service that stores protected health information outside the United States when the parties execute an appropriate business associate agreement and otherwise comply with the HIPAA Rules. Geography still matters because location can change risk, enforceability, access, and the analysis that supports the chosen safeguards.
US residency can therefore be a deliberate policy choice rather than a universal HIPAA command. Choose a home region when it simplifies contracts, latency, support access, customer expectations, or incident response. Do not describe a US region as proof of compliance. Review the service list, BAA scope, identity controls, encryption, logs, backups, support access, and cross-border transfers as separate controls.
What HIPAA actually requires
The HIPAA Security Rule applies to covered entities and business associates handling electronic protected health information. It requires reasonable and appropriate administrative, physical, and technical safeguards, supported by risk analysis and risk management. It does not name one cloud provider, one region, or one architecture as the required answer.
The first legal gate is role and data scope. A provider may be a covered entity if it conducts specified electronic transactions, and a vendor may be a business associate when it creates, receives, maintains, or transmits protected records on behalf of a regulated entity. The eCFR definitions and HHS cloud guidance should be read together with the tenant’s facts. Do not assume that a health-related business is automatically in the same role.
The second gate is the data flow. A region label does not reveal where logs, backups, support tickets, build artifacts, keys, queues, or vendor copies are processed. Inventory each surface. If a provider offers a BAA, read its covered services and exclusions. HHS states that a cloud agreement is necessary when the provider maintains protected records, but the agreement does not make the customer’s configuration or application compliant.
Why overseas storage changes risk analysis
HHS guidance expressly notes that overseas storage can create special considerations for privacy and security protections, including enforceability and geographic risk. That is a risk-analysis input, not a categorical prohibition. Document the country, provider, service, support model, applicable contract, legal access concern, and safeguards used to reduce the risk.
| Location question | What to verify | Why it matters |
|---|---|---|
| Primary records | Database region and failover behavior | Core storage exposure |
| Backups | Vault, replica, retention, restore region | Copies may leave the chosen zone |
| Keys | Key region, operator, rotation, recovery | Access and availability boundary |
| Support | Remote countries and tooling | Human access may cross borders |
| Logs and queues | Collection, export, and retention locations | Operational data can repeat the exposure |
Keep a data-location register with an as-of date. Provider availability, regional behavior, and contract terms can change. A region map from a product page is a planning input, not proof that every service and subprocessor stays in that region.
When a US home region is a sound policy choice
Choose a US home region when the tenant, counsel, and security owner value a simpler residency statement, a familiar legal environment, predictable support routing, or lower cross-border complexity. The decision is especially useful when the tenant contract promises US storage or when a customer procurement process requires it.
Make the policy explicit:
- Every tenant receives an immutable home zone at onboarding.
- Authenticated membership resolves the tenant and zone server-side.
- Records, queues, logs, backups, and keys inherit the zone unless an approved exception exists.
- Support access is time-bound, role-limited, and recorded.
- A move is an export, import, deletion, and contract review project.
Do not use a browser-supplied region header as authorization. Do not promise that a US region stops all international processing when provider support, billing, abuse review, or security operations are global. The policy should state what is controlled, what is outside the operator’s control, and how exceptions are reviewed.
The control plane versus protected records plane article shows how opaque tenant metadata can remain separate from protected records. The article regional backups and keys covers the copies most often missed.
How provider eligibility and BAA scope fit
A provider’s eligible-service list is a product and contract boundary. Check that the exact service, account, tier, region, and feature are included before protected records enter it. AWS publishes a HIPAA eligible services reference, but eligibility is not a certification of a deployment and does not cover unrelated services automatically.
HHS guidance also explains that a cloud provider can remain a business associate even when it stores only encrypted data and cannot see the key. Encryption can reduce exposure and help with incident handling, but it does not erase the provider relationship or the customer’s duties. The BAA, configuration, identity controls, and risk analysis all remain relevant.
Use a provider matrix that records:
- Service and feature name.
- Region and replication behavior.
- Agreement status and covered entity in the chain.
- Subprocessors and support countries.
- Logs, backups, keys, and deletion behavior.
- Owner and next recheck date.
Any unknown row is a stop condition. A green “provider supports HIPAA” label is not enough evidence.
US residency decision table
| Decision | Benefit | Remaining work |
|---|---|---|
| US home region | Simpler contract and customer story | Verify backups, support, keys, and vendors |
| EU or other home region | May serve local latency or customer policy | Assess overseas risk and other privacy regimes |
| Multi-region replication | Availability and disaster recovery | Document every replica and legal boundary |
| Global service with regional records | Operational convenience | Trace control plane, logs, support, and tooling |
Pick the smallest architecture that satisfies the availability and customer contract. A single region may be sufficient for an initial risk decision if backups and restore are tested. Adding replicas increases operational and legal surfaces. If a second region is needed, document why and map the transfer or access mechanism before activation.
Use AWS and Google Cloud region choices only as a current planning map. Re-open provider pages before launch and record changed service coverage.
Tenant approval checklist
Before a residency promise is made, obtain the tenant’s stated requirement and counsel’s review of applicable rules and contracts. Engineering should prove the location policy with configuration checks and synthetic data, not a slide or a region name.
- Role and data scope confirmed.
- Primary record region named.
- Backups, logs, queues, keys, and support mapped.
- Provider eligibility and BAA scope verified.
- International access and subprocessor countries recorded.
- Home region immutable after onboarding or moved only through a controlled project.
- Restore and deletion tests completed.
- Customer wording limited to verified facts.
Stop when a contract says “US only” but a backup, support tool, or provider feature has not been checked. Residency claims should be narrow enough to test continuously.
FAQ
What is the first verification step for HIPAA US data residency?
Read the HHS cloud guidance, then map the tenant’s role and every service that creates, receives, maintains, or transmits protected records. Do not begin with a region selector.
Which source or configuration detail could change this answer?
Provider BAA scope, service eligibility, replication, backup, support countries, and state or contractual requirements can change the decision. Recheck volatile provider terms on the draft and launch dates.
What must be approved before a production claim or outbound action?
The tenant’s residency requirement, provider contract, location map, exception process, and legal analysis should be approved. Engineering must verify the map in configuration and test restore and support paths.
References
- U.S. Department of Health and Human Services, Cloud Computing and HIPAA, retrieved 2026-08-15, https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- Electronic Code of Federal Regulations, 45 CFR 160.103 Definitions, retrieved 2026-08-15, https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- Amazon Web Services, HIPAA Eligible Services Reference, retrieved 2026-08-15, https://aws.amazon.com/compliance/hipaa-eligible-services-reference/
Related articles
How to Run a Tabletop Exercise for Breach Notification
A breach-notification tabletop should test roles, facts, evidence, risk assessment, communications, recovery, and post-exercise actions…
Proposed HIPAA Security Rule Changes for Incident Plans
As of August 15, 2026, distinguish the HIPAA Security Rule currently in effect from proposed modifications. Prepare incident,…
HIPAA Contingency Plans: Backup, Restore, and Testing
A HIPAA contingency plan should cover backup, disaster recovery, emergency mode, restore testing, recovery objectives, and evidence. The…