Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Where in the CFR does it say you have to use physical servers or even dedicated cloud instances? AWS will sign a BAA for dedicated instances only (biz policy, not for any valid security reason), but dedicated servers are not required by HIPAA.


The requirement for dedicated instances was lifted earlier this year. See https://aws.amazon.com/blogs/apn/aws-hipaa-program-update-re... for more info.


Thank you! Slipped by my addictive refresh of What’s New!




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: