AI Infrastructure — Vendor Intelligence Profile
AWS managed foundation model service for building generative AI applications on HIPAA-eligible infrastructure.
Enterprise Buyer Journey
A structured seven-step journey from governance foundation to implementation planning.
Understand AI Governance
Build a governance foundation before evaluating any vendor.
Create Vendor Requirements
Define what your organization needs from an AI vendor by category.
Build Evaluation Criteria
Establish compliance, security, and workflow scoring rubrics.
Compare Vendors
Evaluate vendors side-by-side across risk, compliance, and fit.
Review Compliance
Assess BAA availability, HIPAA posture, and PHI exposure risk.
Approval Recommendation
Determine the vendor approval tier and governance conditions.
Implementation Planning
Execute the approval workflow and plan deployment with oversight.
Available (AWS Enterprise)
Conditional
Not publicly disclosed
Not publicly disclosed
Not publicly disclosed
Cloud (API — AWS)
Vendor Overview
Industry
Artificial Intelligence / Cloud Infrastructure
Deployment Model
Cloud (API — AWS)
Primary Users
Healthcare AI developers, enterprise engineering teams, clinical AI builders
Healthcare Suitability
Conditional — AWS HIPAA BAA required, model selection and data handling review required
Headquarters
Seattle, WA (Amazon Web Services)
Primary Use Cases
Security & Compliance
BAA Availability
Available (AWS Enterprise)
HIPAA Suitability
Conditional
SOC 2 Status
Not publicly disclosed.
ISO Certification
Not publicly disclosed.
Authentication / SSO
Not publicly disclosed.
Access Controls
Not publicly disclosed.
Audit Logging
Not publicly disclosed.
Data Retention
AWS Bedrock is HIPAA-eligible under the AWS HIPAA BAA. Input data is not used to train foundation models by default. Data residency and retention are configurable within AWS. Model provider subprocessor terms must be reviewed.
Customer Data Usage
Not publicly disclosed.
Model Training Practices
Not publicly disclosed.
Security Documentation
Not publicly disclosed.
Privacy Documentation
Not publicly disclosed.
Incident Response
Not publicly disclosed.
BAA Details
AWS Bedrock is covered under the AWS HIPAA BAA for eligible accounts. Execute or confirm existing AWS BAA covers Bedrock. Review model-specific subprocessor terms for third-party foundation model providers.
Compliance Notes
Confirm AWS BAA covers Bedrock, review model provider subprocessor agreements, enable CloudTrail logging for all Bedrock API calls, restrict IAM permissions to least privilege, and document in vendor risk register.
AI Governance
AI Classification
AI Infrastructure / Platform
Human Review
Required — AI outputs must be reviewed by a qualified professional before clinical or operational action.
AI Output Risk
Not publicly disclosed.
Oversight Considerations
PHI must only be processed through HIPAA-eligible Bedrock configurations with BAA in place. Third-party model provider subprocessor terms must be reviewed before use with PHI.
Approval Workflow
Standard VNDRIQ vendor approval workflow recommended.
Monitoring Cadence
Quarterly
Suggested Owner
IT / Compliance / Clinical Governance (varies by use case)
Escalation Triggers
BAA changes, privacy policy updates, new AI features, security incidents, acquisitions.
Enterprise Readiness
Ideal Customer
Healthcare AI developers, enterprise engineering teams, clinical AI builders
Vendor Maturity
Growing — Active in healthcare with expanding compliance posture.
Enterprise Readiness
Mid-Market — Appropriate for mid-size practices and growing organizations.
Implementation Complexity
Not publicly disclosed.
Integration Requirements
Not publicly disclosed.
EHR Integrations
Not publicly disclosed.
SSO / API
Not publicly disclosed.
Support Model
Not publicly disclosed.
Business Continuity
Not publicly disclosed.
Evaluation Criteria
Security Controls
4/5
Compliance
3/5
Data Privacy
3/5
Vendor Transparency
4/5
Healthcare Readiness
3/5
Governance Readiness
3/5
Implementation Guidance
Restrictions
PHI must only be processed through HIPAA-eligible Bedrock configurations with BAA in place. Third-party model provider subprocessor terms must be reviewed before use with PHI.
Implementation Notes
Confirm AWS BAA scope includes Bedrock, review model subprocessor terms, enable CloudTrail, configure IAM least privilege, establish AI governance policy for Bedrock workloads, and document in vendor risk register.
Monitoring & Review
Review Cadence
Quarterly
Items to Monitor
BAA status, privacy policy, AI feature changes, security certifications, EHR integrations.
Documentation Gaps
Not publicly disclosed.
Vendor Change Triggers
Approval Recommendation
Review Required
Vendor requires additional documentation review before approval. BAA, security certifications, and data handling policies must be verified.
Required Due Diligence
Internal Owner
IT / Compliance / Clinical Governance
Documents to Collect
BAA, security questionnaire, privacy policy, data processing agreement.
Executive Buyer Checklist
0/11Use this checklist to track your evaluation progress for AWS Bedrock.
Vendor Intelligence Hub
Comparisons
Approval Status
AI Risk
Resources
Reports
Related Vendors
Similar Vendors
Other AI Infrastructure vendors in the VNDRIQ registry.
Approved Alternatives
Vendors with approved or conditional approval status for healthcare use.
Frequently Compared
Compare AWS Bedrock side-by-side with these vendors.
Related Vendors
Similar vendors to evaluate alongside AWS Bedrock:
Profile Completeness
Missing Fields
Vendor Snapshot
Category
AI Infrastructure
Headquarters
Seattle, WA (Amazon Web Services)
Deployment Model
Cloud (API — AWS)
Healthcare Suitability
Conditional — AWS HIPAA BAA required, model selection and data handling review required
Risk Level
Elevated Risk
Review Confidence
Under Review
Last Reviewed
2026-06-15
Risk Score
58/100
AI Trust Score
75/100
Governance Resources
Alternative Vendors
Related Checklists
Comparison Guides
VNDRIQ vendor profiles are for operational risk screening and governance support. This is not legal, compliance, or cybersecurity advice. Final vendor approval should include legal, compliance, security, and contract review. Data is based on publicly available information and internal review at time of last verification.