Five essential preventative controls for HCLS | Amazon Web Services
Key Takeaways
This video discusses five essential preventative controls for healthcare and life sciences organizations using AWS, focusing on governance, encryption, and generative AI, specifically Service Control Policies (SCPs) and Resource Control Policies (RCPs).
Full Transcript
Hello, I'm Hector Rodriguez, a healthcare and life sciences principal industry specialist and security leader at AWS. With me, I have my colleague and friend Donnie Wilson, a healthcare and life sciences principal solutions architect at AWS. In this video, we discuss five essential preventative controls for AWS healthcare and life sciences organizations that leverage the AWS service control and resource policies. In this video, we discuss why preventative controls for healthcare and life sciences. We provide an overview of service control policies and resource control policies. Donnie will dive deeper into the five essential preventative controls for HCLS workloads on AWS. And lastly, we'll provide some QR codes to resources to get started with SCPs and RCPs. Healthcare and life sciences organizations can benefit from organizational preventative controls to address constantly evolving regulatory requirements. We're also facing a highly dynamic security threat landscape and we must meet stringent reporting and documentation requirements. We also have to face these challenges with limited developer resources and agility. So we want to leverage foundational SCPs and RCPs to help organizations focus on solutions to drive their mission. Service control policies or SCPs are principal ccentric controls used to define the maximum available permissions to the identity and access management principles in your organization. They can be applied at the root organizational unit or member account level. Resource control policies or RCPs are resource centric controls used to define the maximum available permissions for the AWS resources in your organization. They can also be applied at the root organizational unit or member account level. There are many use cases where SCPs and RCPs can be effectively and efficiently used to enforce access controls. For example, SCP use cases include the ability to prevent identities from accessing external resources, limiting AWS regions, and to protect cloud platform resources. And RCP use cases include the ability to prevent access to your resources by external identities and to apply controls on sensitive resources. Next, my colleague Donnie Wilson will walk us through five essential preventative controls for healthcare and life sciences workloads on AWS. Thanks, Hector. Now that we have an understanding of service and resource control policies, let's go through five examples that are essential for healthcare and life science customers. These five essential service and resource control policies focus on protecting the foundational governance layer of your AWS environment. The first SCP will maintain the integrity of your regulated landing zone. The next SCP can be used to enforce HIPPA eligible services for AWS accounts and or organizational units. Third, we'll cover how to specify specific foundation models in Amazon Bedrock. And for our fourth and fifth examples, we'll show how to enforce encryption for data at rest and in transit for your AWS resources. The AWS landing zone is a well architected multi-account AWS environment that is scalable and secure. It is a starting point where your organization can quickly launch and deploy workloads and applications with confidence in your security and infrastructure environment. This SCP is part of the landing zone accelerator or LZA. The LZA deploys your landing zone using the guidelines and recommendations from the AWS security reference architecture. If you want your AWS landing zone to remain secure, it is important that unintended changes are not made to the LZA. This SCP is designed to maintain the integrity of your landing zone accelerator deployment and can be useful for protecting organizational audit and logging data for preventing changes to foundational resources and exceptional conditions for allowed IM roles. HLS customers often work with sensitive data such as protected health information. AWS customers that are subject to HIPPA can restrict which AWS services are used in an AWS member account or organizational unit. A HIPPA eligible service can be used to create, receive, process, maintain, or transmit electronic protected health information. AWS has evaluated these services to demonstrate its compliance with HIPPA requirements subject to the AWS shared responsibility model. While this list is not exhaustive, it demonstrates a SCP allowing only HIPPA eligible services. The net effect of this statement is to only allow HIPPA eligible services included in the not action section of this policy. This can be useful for dying user or RO requests to AWS services that are not on the HIPPA eligible list. SCPs can be applied to a specific account or OU designated for HIPPA workloads. For a complete list of HIPPA eligible services, visit our AWS services in scope page listed at the bottom of this slide. Organizations can allow or deny access to specific foundation models which can be useful for enforcing compliance requirements, controlling cost, or standardizing on specific models across your organization, allowing you to meet data governance requirements. This SCP provides an example of allowing only a specific foundation model while denying all others. HTLS customers must encrypt data at rest. A way to do this is to use resource control policies to enforce encryption like in this example for S3 buckets. This is useful for ensuring data meets regulatory requirements or creating an immutable security foundation. It also helps eliminate manual tasks for security teams, limiting the impact of a breach and allowing developers more time to focus on building applications. For HTLS customers, data must also be encrypted when it's in transit. This RCP enforces workload isolation by requiring HTTPS across all resources. This helps protect against easedropping, credential theft, and man-in-the-middle attacks. This is also helpful for meeting regulatory encryption requirements, blocking unencrypted API calls, and protecting against network-based attacks. In this session, we covered five essential SCP and RCPs for healthcare and life science customers that can be used to protect their resources, identities, and data. Remember, these are examples, and it's important that you review and make these your own as applicable to your organizational needs. To help you get started with SCPs and RCPs, please use these QR codes. Thank you for joining us and please continue to work with your AWS account team to plan your next steps or for more information.
Original Description
This session will cover five essential preventative SCP and RCP controls for healthcare and life science customers with a focus on governance, encryption, and generative AI.
Learn more about AWS Organizations: https://go.aws/3KGIQIl
Subscribe to AWS: https://go.aws/subscribe
Create a free AWS account: https://go.aws/signup
Try AWS for free: https://go.aws/free
Connect with an expert: https://go.aws/contact
Explore more: https://go.aws/more
Next steps:
Explore on AWS in Analyst Research: https://go.aws/reports
Discover, deploy, and manage software that runs on AWS: https://go.aws/marketplace
Join the AWS Partner Network: https://go.aws/partners
Learn more on how Amazon builds and operates software: https://go.aws/library
Do you have technical AWS questions?
Ask the community of experts on AWS re:Post: https://go.aws/3lPaoPb
Why AWS?
Amazon Web Services is the world’s most comprehensive and broadly adopted cloud, enabling customers to build anything they can imagine. We offer the greatest choice of innovative cloud capabilities and expertise, on the most extensive global infrastructure with industry-leading security, reliability, and performance.
#AWS #AmazonWebServices #CloudComputing
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from Amazon Web Services · Amazon Web Services · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Agentic AI Design Patterns Introduction and walkthrough | Amazon Web Services
Amazon Web Services
Galileo on modernizing on banking infrastructure | Amazon Web Services
Amazon Web Services
Alliander Speeds Innovation and Energy Transition Using AWS | Amazon Web Services
Amazon Web Services
AWS and Scuderia Ferrari HP streamline F1 power unit assembly | Amazon Web Services
Amazon Web Services
How AWS machine learning supports Scuderia Ferrari HP pit stops | Amazon Web Services
Amazon Web Services
Nasdaq Builds Market Infrastructure of the Future with AWS | Amazon Web Services
Amazon Web Services
AWS Security Hub Exposure Findings | Amazon Web Services
Amazon Web Services
How do I use Session Manager port forwarding to connect to my EC2 instance through RDP?
Amazon Web Services
How do I extend an EBS volume with LVM partitions?
Amazon Web Services
AWS Graviton makes it easy to optimize performance, cost, and sustainability | Amazon Web Services
Amazon Web Services
Run Cloud Adoption Framework workshops with Miro | Amazon Web Services
Amazon Web Services
Getting Started with AWS Cost Optimization Hub | Amazon Web Services
Amazon Web Services
Why did my Amazon SQS messages get sent to a dead-letter queue?
Amazon Web Services
Declarative Policies for EC2 | Amazon Web Services
Amazon Web Services
How do I troubleshoot IAM permission issues for the Billing and Cost Management console?
Amazon Web Services
Integrity at Scale: Inside the Flo Health Mission | Amazon Web Services
Amazon Web Services
Fueling Success: Small shifts, powerful performance | Amazon Web Services
Amazon Web Services
WEX enhances customer experience with AI-powered chatbot | Amazon Web Services
Amazon Web Services
Accelerate troubleshooting with Amazon CloudWatch investigations | Amazon Web Services
Amazon Web Services
Why is my Windows WorkSpace stuck in the starting, rebooting, or stopping status?
Amazon Web Services
Telemetry Pipelines for AI | Amazon Web Services
Amazon Web Services
Getting Control over Security and Observability Data | Amazon Web Services
Amazon Web Services
The Problem with Telemetry Data Volume | Amazon Web Services
Amazon Web Services
Telemetry Pipelines on AWS | Amazon Web Services
Amazon Web Services
What are Telemetry Pipelines? | Amazon Web Services
Amazon Web Services
Using AI for RegEx on Telemetry Pipelines | Amazon Web Services
Amazon Web Services
Multi-Session Support in the AWS Console | Amazon Web Services
Amazon Web Services
How CloudHedge delivers assessment with AWS ISV Tooling Program at no cost?
Amazon Web Services
How customers speed up migration and modernization to AWS with CloudHedge | Amazon Web Services
Amazon Web Services
Chaos Experiment with Amazon ElastiCache | Amazon Web Services
Amazon Web Services
Amazon S3 Access Points: Easily manage access for shared datasets on S3 | Amazon Web Services
Amazon Web Services
ElastiCache Valkey 8.0 - Savings and Efficiency | Amazon Web Services
Amazon Web Services
Pennymac scales document processing with AWS | Amazon Web Services
Amazon Web Services
AWS | Next Level Innovation | Amazon Web Services
Amazon Web Services
Driving Cloud Innovation: Mindtickle's Partnership with AWS Enterprise Support | Amazon Web Services
Amazon Web Services
A Leader's Edge from Executive Insights | Amazon Web Services
Amazon Web Services
How do I create a custom Amazon WorkSpaces image?
Amazon Web Services
Charles Leclerc tests his AI-generated race track | Amazon Web Services
Amazon Web Services
Redington Scales India’s Cloud Access with AWS Partnership | Amazon Web Services
Amazon Web Services
How do I prevent the resources in my CloudFormation stack from getting deleted or updated?
Amazon Web Services
How do I troubleshoot authentication errors when I use RDP to connect to an EC2 Windows instance?
Amazon Web Services
Exploring the Possibilities of Digital Twin & AI at the Edge | Amazon Web Services
Amazon Web Services
Exploring the Possibilities of Digital Twin & AI at the Edge | Amazon Web Services
Amazon Web Services
AWS at the FORMULA 1 AWS GRAN PREMIO DELL'EMILIA-ROMAGNA 2025 | Amazon Web Services
Amazon Web Services
What's new in RCPs | Amazon Web Services
Amazon Web Services
API Caching using Amazon ElastiCache | Amazon Web Services
Amazon Web Services
Pendula: Amazon Nova Customer Testimonial | Amazon Web Services
Amazon Web Services
InDebted : Amazon Nova Customer Testimonial | Amazon Web Services
Amazon Web Services
Amazon DynamoDB global tables with multi-Region strong consistency | Amazon Web Services
Amazon Web Services
Siemens Mobility uses AWS to operate securely, efficiently on a global scale | Amazon Web Services
Amazon Web Services
How do I reuse a knowledge base session in Amazon Bedrock?
Amazon Web Services
EP5: MBZUAI, CMU : Causal AI, Answering The “Why“ and “What if“ Questions | AWS for AI Podcast
Amazon Web Services
Hema scales time to market developing a data mesh on AWS (Technical) - Cloud Adventures
Amazon Web Services
Hema scales time to market developing a data mesh on AWS (Business) - Cloud Adventures
Amazon Web Services
How Langfuse Scaled Their AI Platform with AWS: From Open-Source to Enterprise | Amazon Web Services
Amazon Web Services
SLMs and LLMs: What’s the Difference? | Amazon Web Services
Amazon Web Services
SLMs and LLMs: When to use them? | Amazon Web Services
Amazon Web Services
SLMs on CPU | Amazon Web Services
Amazon Web Services
Intelligent Model Routing | Amazon Web Services
Amazon Web Services
SLMs, LLMs, and Model Routing in Agents | Amazon Web Services
Amazon Web Services
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Groovy Open source tools Worth Your Weekend
Medium · DevOps
🚀 MyZubster is Live! From Zero to Production on a VPS
Dev.to AI
MCP Ecosystem Week 30: When Your Developers' AI Tools Connect to Everything—What's in Your Allowlist?
Dev.to AI
Receipts, not labels: what cron trust hand-offs get wrong about provenance
Dev.to · Aloya
🎓
Tutor Explanation
DeepCamp AI