AWS HIPAA Cost in 2026
There is no HIPAA line item on the AWS price list. AWS publishes a list price for each of the services a HIPAA workload leans on, bills them at those ordinary rates whether or not PHI is involved, and publishes no combined security-stack total. This page gives you the four rates that matter, each attributed to the AWS pricing page that publishes it and dated to the day we checked, plus one worked example so you can see which dimension actually dominates the bill.
The structural point
The cost of HIPAA on AWS is not a surcharge. It is the services you choose to run, at published rates, plus the engineering time to architect and evidence them. AWS publishes no price for the BAA and no HIPAA premium on any service. If you were already going to encrypt at rest, log the management plane and monitor for threats, the HIPAA-attributable delta on your AWS invoice is close to nothing. If you were not, the delta is the published price of the services you now add, computed against your own volumes.
The AWS BAA mechanics
AWS publishes the Business Associate Addendum through AWS Artifact. Acceptance is a self-service workflow: open AWS Artifact in the AWS Management Console, locate the AWS Business Associate Addendum, review the terms and accept. AWS publishes no fee for the BAA on the Artifact page, in the Artifact FAQ, or on the HIPAA Eligible Services Reference, checked July 2026. We report that as the absence of a published price rather than as a promise of a free one, because AWS makes no statement either way.
The BAA covers AWS's obligations as a business associate under HIPAA: safeguards under the Security Rule for the in-scope services, breach notification under 45 CFR 164.410, and use and disclosure of PHI only as the BAA and the Privacy Rule permit. The BAA's scope is bounded by the HIPAA-eligible service list.
This is an informational cost reference, not legal or compliance advice. Consult a cloud-compliance attorney or a HIPAA-qualified compliance professional before architecting a HIPAA workload on AWS.
The HIPAA-eligible service constraint
The AWS HIPAA Eligible Services Reference lists the services that may be used to store, process or transmit ePHI under the AWS BAA, roughly 200 of them as at July 2026, spanning compute, storage, databases, analytics, AI/ML, the healthcare-specific services, networking, security and management. AWS states the condition directly on that page: you agree not to use these HIPAA Eligible Services with Protected Health Information without first entering into an AWS business associate agreement.
Services not on the list sit outside the BAA's scope for PHI. The architecture work that follows:
- Use AWS Organizations with Service Control Policies to block non-eligible services in BAA-protected accounts, so the constraint is enforced by the platform rather than by developer discipline.
- Tag PHI-bearing resources with a standardised classification tag for ongoing audit.
- Document the architecture so each service maps to its eligibility status and to the data flows it handles.
- Check the published reference before assuming a service is eligible. Eligibility can be Region-specific, and the list changes.
None of this appears on an invoice, which is precisely why it gets underestimated. The SCP guardrail and the architecture documentation are engineering time, and engineering time is the largest HIPAA-attributable cost on most AWS estates. No AWS surface publishes a figure for it, and it depends on your team, so this page does not estimate one.
The published rates, per service
Each of these is a separate published dimension on a separate AWS pricing page. AWS does not publish them as a bundle, and they are not additive into a headline: what you pay depends on which you run and at what volume.
$1 per key per month, prorated hourly, plus $0.03 per 10,000 requests
First 20,000 requests per month free
First copy of ongoing management events to S3 free via trails
$2.00 per 100,000 management events for additional copies; $0.10 per 100,000 data events
$0.003 per continuous configuration item
$0.012 per periodic configuration item; conformance-pack evaluations $0.001 each for the first 100,000
$4.00 per million CloudTrail management events per month
VPC Flow and DNS query logs $1.00/GB first 500 GB, $0.50/GB next 2,000 GB, $0.25/GB beyond
All rates us-east-1, read off the linked AWS pricing pages and checked July 2026. Regional variation, Savings Plans and Enterprise Discount Program terms change effective pricing at scale, and none of those discounts is published.
What the stack costs at one worked volume
Our arithmetic, not a vendor price
AWS publishes the per-unit rates below. AWS does not publish this total. The volumes are assumptions we chose to make the rates legible, not a claim about your workload. Substitute your own numbers.
| Assumed monthly volume | Against the published rate | Line |
|---|---|---|
| 5 customer-managed KMS keys | 5 x $1 | $5.00 |
| 2,000,000 KMS requests (20,000 free) | 198 x $0.03 | $5.94 |
| One CloudTrail trail, management events | first copy free | $0.00 |
| 3,000,000 CloudTrail events analysed by GuardDuty | 3 x $4.00 | $12.00 |
| 200 GB VPC Flow + DNS logs to GuardDuty | 200 x $1.00 | $200.00 |
| 20,000 continuous Config items | 20,000 x $0.003 | $60.00 |
| Our total for these assumed volumes | $282.94 | |
The useful thing this example shows is not the total, which is ours and applies to nobody. It is the shape: at these volumes, GuardDuty log ingestion is about 75 percent of the bill and every key, trail and config item together is the rest. Encryption keys are almost free. Threat-detection log volume is the lever. If you want to know what your own security baseline costs, meter your VPC Flow Log and DNS query volume first, because that single number moves the answer more than every other line combined.
Common AWS HIPAA budget mistakes
Spinning up a workload before accepting the BAA. Until the BAA is accepted, no AWS service is in BAA scope. Accept it before any PHI is loaded, not after.
Using non-eligible services with PHI. Easy to do in development, when the convenient service beats the appropriate one. SCPs prevent it at the platform level.
Default S3 encryption only. Default S3 encryption uses an AWS-managed key. For HIPAA-grade auditability, customer-managed keys through KMS give you rotation control and per-key access logging in CloudTrail, at the published $1 per key per month.
Budgeting the tooling and forgetting the log volume. The worked example above is the reason. Teams price GuardDuty as a product and discover it is a function of how chatty their VPC is.
Single AWS account for everything. A multi-account Organization with separate production, staging, security, logging and shared-services accounts is the pattern AWS recommends. Single-account architectures are harder to audit and harder to isolate after an incident.
AWS HIPAA cost FAQ
Does AWS charge for the HIPAA BAA?
What is the HIPAA-eligible services list?
What do the AWS security services actually cost?
What HIPAA-relevant security tooling do I need on AWS beyond the BAA?
Does AWS handle HIPAA compliance for me?
How much of my bill is the HIPAA part?
How does HITRUST CSF certification on AWS work?
Related cost guides
Azure HIPAA Cost
Defender, Sentinel and Key Vault rates
GCP HIPAA Cost
The one cloud that states its HIPAA pricing policy
Digital Health Startup Cost
Seed to Series A HIPAA pricing
Business Associate Agreements
BAA scope, cost, and red flags
EHR HIPAA Cost
The three EHR vendors that publish a price
2026 Security Rule Changes
Cloud-architecture impact