apprunner-roadmap icon indicating copy to clipboard operation
apprunner-roadmap copied to clipboard

Adding app runner to AWS compliance program

Open princepathria97 opened this issue 3 years ago • 9 comments

Background - Customers may use any AWS service in an account designated as a HIPAA account, but they should only process, store, and transmit protected health information (PHI) in the HIPAA-eligible services defined in the Business Associate Addendum (BAA). Ref. - https://aws.amazon.com/compliance/hipaa-compliance/

This is a feature request for adding App runner to compliance scope. AWS Services in Scope by Compliance Program

princepathria97 avatar May 19 '21 23:05 princepathria97

HIPPA compliance is key for our industry. I cannot consider AppRunner until we get some kind of certification here.

NapalmCodes avatar Feb 22 '22 17:02 NapalmCodes

Any news with this one? Would love to use App Runner but w/o HIPAA it's not an option. Looking at Fargate atm.

@napalm684 @princepathria97 and other, what are you using instead until App Runner is HIPAA compliant ?

vladshcherbin avatar Mar 09 '22 20:03 vladshcherbin

Any news with this one? Would love to use App Runner but w/o HIPAA it's not an option. Looking at Fargate atm.

@napalm684 @princepathria97 and other, what are you using instead until App Runner is HIPAA compliant ?

Fargate ECS

NapalmCodes avatar Mar 09 '22 23:03 NapalmCodes

Any progress here? This would be great for us.

f0rk avatar Jun 28 '22 20:06 f0rk

This would be great to have, or at least some information on why it is not covered as it seems under the hood it uses all covered services.

zachallia avatar Oct 17 '22 19:10 zachallia

They have documentation kinda outlining the overall architecture diagram of App Runner services and it is indeed using all of their already compliant services. Find more information here: https://aws.amazon.com/blogs/containers/deep-dive-on-aws-app-runner-vpc-networking/.

msetegn avatar Feb 26 '23 17:02 msetegn

I suspect the main issue for app runner getting HIPAA compliance (and others) is that it uses a VPC (at least one per region) that is shared among customers. Ideally, app runner would be able to run in a customer controlled VPC.

acooper avatar Aug 10 '23 15:08 acooper

Now there is private vpc, is this hipaa compliant now?

masterbater avatar Oct 08 '23 02:10 masterbater

Would love to see HIPAA compliance in App Runner! It'd be a game-changer for healthcare deployments like ours.

veeru-artrya avatar Oct 10 '23 23:10 veeru-artrya