Amazon CloudFront is a content delivery network (CDN) service from Amazon Web Services (AWS) that speeds up the distribution of static and dynamic web content, APIs, and video to end users by routing traffic through a global network of edge locations.

With Amazon CloudFront, companies can reduce latency, improve reliability, and securely deliver websites, applications, and APIs to users worldwide while integrating with other AWS security and monitoring tools.

Is Amazon CloudFront HIPAA compliant? Yes, based on our research, Amazon CloudFront can be HIPAA compliant.

 

What changed this year?

As of June 2026, our review did not identify any publicly disclosed changes to Amazon CloudFront HIPAA-related policies or BAA terms.

 

Will Amazon CloudFront sign a business associate agreement (BAA)?

Yes, Amazon CloudFront is covered under AWS's standard business associate agreement, which can be reviewed and accepted through AWS Artifact in the AWS Management Console.

 

What does the Amazon CloudFront BAA cover?

The Amazon Cloudfront BAA covers the use and disclosure of protected health information (PHI), stating, "The AWS HIPAA compliance program includes CloudFront (excluding content delivery through CloudFront Embedded POPs) as a HIPAA eligible service. If you have an executed Business Associate Addendum (BAA) with AWS, you can use CloudFront (excluding content delivery through CloudFront Embedded POPs) to deliver content that contains protected health information (PHI)."

Under the AWS BAA, CloudFront usage is covered for:

  • Use and disclosure of PHI within content delivered through CloudFront
  • AWS's contractual obligations to safeguard PHI in transit through the CDN
  • Logging and monitoring support (CloudFront access logs and AWS CloudTrail) to help customers meet audit requirements
  • Alignment with the broader AWS shared responsibility model, where AWS secures the underlying infrastructure

 

What does the Amazon CloudFront BAA exclude?

AWS excludes one delivery method from CloudFront's HIPAA-eligible scope and that is content delivered through CloudFront Embedded Points of Presence (POPs). This means any workload relying on Embedded POPs to deliver content containing PHI would fall outside the protections of the AWS BAA, even though standard CloudFront distributions are covered. Organizations using CloudFront for PHI delivery should confirm they are not relying on this excluded delivery path.

 

Conclusion

Amazon CloudFront signs a BAA and is therefore HIPAA compliant.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQS

What is a business associate agreement?

A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.

 

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.