Bedrock AWS HIPPA compliance with 3rd party (OpenAI) LLM API Calls

0

Came across claims that bedrock calls were HIPPA compliant even with OpenAI traffic, seeking clarification. Generally, medical documents must be sterilized before using public access models such as GPT-4. If AWS has access to some sort of "Do Not Record" argument unique to bedrock offerings, I'd very much like to know that. I've seen bedrock claims, something along the lines as, "all end-points are HIPPA compliant" but obviously if there is a third-party service, along the information custody chain, this is irrelevant. Please provide clarity.

2 Respuestas
0

Hi Russel, you can find further information on Amazon Bedrock compliance validation in the user guide documentation.

In general the Security section of the user guide and also the security section of the FAQ are the recommended starting points for any clarification related to compliance.

To download security and compliance documents you can use AWS Artifact.

AWS
respondido hace 2 meses
0

The practice of sterilizing PHI when using OpenAI is a safe minimum practice. According to their public documentation ChatGPT is not offering a BAA (assume PHI is used insecurely, likely to train the model in question). AWS will also sign a BAA with our covered-entity customers and AWS Bedrock is a HIPAA eligible service -- meaning, if configured and used appropriately it can be used in HIPAA-regulated solutions (or be part of a solution that is HIPAA-compliant). While Bedrock encrypts data it uses at-rest and in-transit, the whole of HIPAA-compliance is a bigger conversation, so the previous links should be read and understood fully.

As an aside, Amazon Q, Q Business, CodeWhisperer (Q Developer/Builder) should not be fed PHI -- these services are special implementations of the same models that Bedrock uses, but are not intended for medical record purposes.

AWS
respondido hace 22 días

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas