Amazon RDS for PostgreSQL - Architecting for HIPAA Security and Compliance on Amazon Web Services

Amazon RDS for PostgreSQL

Amazon RDS for PostgreSQL allows customers to encrypt PostgreSQL databases using keys that customers manage through AWS KMS. On a database instance running with Amazon RDS encryption, data stored at-rest in the underlying storage is encrypted consistent with the Guidance in effect at the time of publication of this whitepaper, as are automated backups, read replicas, and snapshots.

Because the Guidance might be updated, customers should continue to evaluate and determine whether Amazon RDS for PostgreSQL encryption satisfies their compliance and regulatory requirements. For more information on encryption at-rest using Amazon RDS, see Encrypting Amazon RDS Resources.

Connections to RDS for PostgreSQL containing PHI must use transport encryption. For more information on enabling encrypted connections, see Using SSL/TLS to Encrypt a Connection to a DB Instance.