Skip to content

Reference architecture

Telehealth infrastructure on AWS designed for HIPAA

An AWS environment built around HIPAA's technical safeguards: encrypted video visits, tamper-evident audit trails and least-privilege access to patient data. Compliance also depends on your policies and risk analysis, not the infrastructure alone.

Design constraints

What the design has to hold to

Targets for the scenario this reference is sized for. A real engagement starts by replacing them with your own numbers.

  • 01Signed AWS Business Associate Addendum, with ePHI only on HIPAA-eligible services
  • 02Encryption for all ePHI in transit (TLS 1.3) and at rest (AES-256 via AWS KMS)
  • 03Tamper-evident audit logging of every ePHI view and change
  • 04Disaster recovery targets: RPO under 15 minutes, RTO under 1 hour

Component topology

System components and technologies

Subsystems with separate responsibilities, clear contracts between them and storage that scales on its own. The stack named for each is typical, not mandatory.

Stack topology

Telehealth infrastructure on AWS designed for HIPAA

Illustrative reference architecture

  1. 01

    Video visit gateway

    Encrypted WebRTC video consultations (DTLS-SRTP)

    Amazon Chime SDK / self-hosted LiveKit

  2. 02

    Core ePHI services

    Isolated patient record and prescription workflows

    Amazon EKS on Fargate (no shared hosts)

  3. 03

    Encrypted patient storage

    PostgreSQL with column-level encryption for SSNs and MRNs

    Amazon Aurora PostgreSQL with AWS KMS

  4. 04

    Immutable audit log engine

    Write-once audit trail of every access event

    AWS CloudTrail + Amazon S3 Object Lock

Subsystem 01

Video visit gateway

Encrypted WebRTC video consultations (DTLS-SRTP)

Typical stack

Amazon Chime SDK / self-hosted LiveKit

Subsystem 02

Core ePHI services

Isolated patient record and prescription workflows

Typical stack

Amazon EKS on Fargate (no shared hosts)

Subsystem 03

Encrypted patient storage

PostgreSQL with column-level encryption for SSNs and MRNs

Typical stack

Amazon Aurora PostgreSQL with AWS KMS

Subsystem 04

Immutable audit log engine

Write-once audit trail of every access event

Typical stack

AWS CloudTrail + Amazon S3 Object Lock

Data lifecycle

End-to-end data flow

  1. Clinician and patient sign in with WebAuthn MFA through an identity provider covered by a BAA.

  2. WebRTC signaling negotiates encrypted DTLS-SRTP audio and video streams.

  3. Clinical notes and diagnoses are encrypted with patient-specific KMS keys before they are written to Aurora PostgreSQL.

  4. An access interceptor writes structured audit records (who opened which record, when and from where) to S3 Object Lock.

  5. Backup pipelines replicate encrypted snapshots to a second AWS region on a schedule.

Reliability and resilience

Failure modes and how each is contained

Failure mode 01

ePHI leaking into application logs

Mitigation

Log-scrubbing filters detect and redact MRNs, SSNs and names before logs reach CloudWatch.

Failure mode 02

Session hijacking on shared clinic terminals

Mitigation

15-minute inactivity timeouts, and biometric re-authentication before any prescription action.

Failure mode 03

Unencrypted database backups

Mitigation

Service control policies in AWS Organizations block the creation of unencrypted RDS instances and S3 buckets.

Questions

What teams ask about this design

A contract under which AWS takes on HIPAA obligations as your business associate for the HIPAA-eligible services you use. It covers AWS's side of the shared responsibility model; your application, configuration and policies remain your responsibility.

Yes. Fargate is on AWS's list of HIPAA-eligible services and runs each task in its own isolated compute environment. Eligibility covers the service; your configuration, access controls and policies still determine whether the system as a whole meets HIPAA.

Planning a system like this?

Send us your requirements, expected load and budget. We'll reply within one business day with an honest read on the design, and on whether we're the right team to build it.