Subsystem 01
Video visit gateway
Encrypted WebRTC video consultations (DTLS-SRTP)
Typical stack
Amazon Chime SDK / self-hosted LiveKit
Reference architecture
An AWS environment built around HIPAA's technical safeguards: encrypted video visits, tamper-evident audit trails and least-privilege access to patient data. Compliance also depends on your policies and risk analysis, not the infrastructure alone.
Design constraints
Targets for the scenario this reference is sized for. A real engagement starts by replacing them with your own numbers.
Component topology
Subsystems with separate responsibilities, clear contracts between them and storage that scales on its own. The stack named for each is typical, not mandatory.
Stack topology
Telehealth infrastructure on AWS designed for HIPAA
Illustrative reference architecture
Video visit gateway
Encrypted WebRTC video consultations (DTLS-SRTP)
Amazon Chime SDK / self-hosted LiveKit
Core ePHI services
Isolated patient record and prescription workflows
Amazon EKS on Fargate (no shared hosts)
Encrypted patient storage
PostgreSQL with column-level encryption for SSNs and MRNs
Amazon Aurora PostgreSQL with AWS KMS
Immutable audit log engine
Write-once audit trail of every access event
AWS CloudTrail + Amazon S3 Object Lock
Subsystem 01
Encrypted WebRTC video consultations (DTLS-SRTP)
Typical stack
Amazon Chime SDK / self-hosted LiveKit
Subsystem 02
Isolated patient record and prescription workflows
Typical stack
Amazon EKS on Fargate (no shared hosts)
Subsystem 03
PostgreSQL with column-level encryption for SSNs and MRNs
Typical stack
Amazon Aurora PostgreSQL with AWS KMS
Subsystem 04
Write-once audit trail of every access event
Typical stack
AWS CloudTrail + Amazon S3 Object Lock
Data lifecycle
Clinician and patient sign in with WebAuthn MFA through an identity provider covered by a BAA.
WebRTC signaling negotiates encrypted DTLS-SRTP audio and video streams.
Clinical notes and diagnoses are encrypted with patient-specific KMS keys before they are written to Aurora PostgreSQL.
An access interceptor writes structured audit records (who opened which record, when and from where) to S3 Object Lock.
Backup pipelines replicate encrypted snapshots to a second AWS region on a schedule.
Reliability and resilience
Failure mode 01
Mitigation
Log-scrubbing filters detect and redact MRNs, SSNs and names before logs reach CloudWatch.
Failure mode 02
Mitigation
15-minute inactivity timeouts, and biometric re-authentication before any prescription action.
Failure mode 03
Mitigation
Service control policies in AWS Organizations block the creation of unencrypted RDS instances and S3 buckets.
Questions
A contract under which AWS takes on HIPAA obligations as your business associate for the HIPAA-eligible services you use. It covers AWS's side of the shared responsibility model; your application, configuration and policies remain your responsibility.
Yes. Fargate is on AWS's list of HIPAA-eligible services and runs each task in its own isolated compute environment. Eligibility covers the service; your configuration, access controls and policies still determine whether the system as a whole meets HIPAA.
Send us your requirements, expected load and budget. We'll reply within one business day with an honest read on the design, and on whether we're the right team to build it.