GDPR Compliance on Healthlake

0

We are trying to build a health lake and considering to leverage Amazon health lake, However our security team would like to confirm that Healthlake offers GDPR Compliance. In specific right to be forgotten requests. I dont see any specific documentation around this. Can you please let us know how AWS supports this

2 Answers
0
Accepted Answer

Yes. HL is GDPR compliant. using the delete API customers can logically delete the patient data entry in HL, which is then deleted from the media as part of the recurring job. Its a soft delete but thereafter it is deleted from media (3-13 days SLA)

AWS
answered 9 months ago
0

Hi,

On your very specific question, you should analyze S3 Find & Forget: https://aws.amazon.com/blogs/big-data/handling-data-erasure-requests-in-your-data-lake-with-amazon-s3-find-and-forget/

You should also go to AWS Artifact on your AWS console and download reports related to GDPR: https://aws.amazon.com/artifact/

Then, you should also go to AWS GDPR Center: https://aws.amazon.com/compliance/gdpr-center/ and download this extensive wp about GDPR: https://docs.aws.amazon.com/pdfs/whitepapers/latest/navigating-gdpr-compliance/navigating-gdpr-compliance.pdf

You may also want to review the Shared Security Model to see how AWS services help you achieve GDPR compliance: https://aws.amazon.com/compliance/shared-responsibility-model/

Best,

Didier

profile pictureAWS
EXPERT
answered 9 months ago
profile picture
EXPERT
reviewed 9 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions