Cloud Compliance: What the Provider Covers and What You Still Owe
A compliant cloud provider does not make your workload compliant. Where the responsibility boundary actually falls, and the evidence you have to produce yourself.
GuardsArm Team
Security Experts
"Our cloud provider is HIPAA compliant" is the most common misunderstanding in cloud healthcare deployments. Providers offer HIPAA-eligible services and sign a BAA. What runs inside your account — access control, encryption settings, logging, who can reach what — is yours, and it is where essentially every cloud healthcare breach has originated.
Where the boundary actually falls
| Layer | Who |
|---|---|
| Physical data centre, hardware | Provider |
| Hypervisor, host operating system | Provider |
| Managed service patching | Provider, for managed services only |
| Guest OS on VMs you run | You |
| Network configuration, security groups | You |
| Identity and access management | You |
| Encryption settings and key management | You |
| Data classification and handling | You |
| Application security | You |
| Audit logging configuration and retention | You |
The pattern is consistent: the provider secures the platform, you secure what you build on it. Managed services shift more to the provider, which is a good reason to prefer them — but never all of it, and never the access control.
Read the attestation properly
Providers publish SOC 2 reports, ISO certificates and FedRAMP authorisations. Using them well means:
- Check the scope — which services and which regions are covered
- Check the date — attestations cover a defined period
- Read the complementary user entity controls. Every SOC 2 report lists what the customer must do for the provider's controls to be effective. This section is your homework and is almost universally skipped.
- Map their controls to your framework so you inherit deliberately and can evidence the inheritance
Configuration is where it fails
The provider's compliance does not prevent:
- A storage container made public
- An over-permissive role granting broad access
- A database with a public endpoint
- Audit logging disabled or with short retention
- PHI placed in a service outside the BAA's covered list
- Data stored in a region that breaches a residency requirement
These are covered in preventing cloud misconfiguration. The compliance point is that every one of them is your finding, not theirs.
Residency and jurisdiction
Where data physically sits matters for several regimes, and the answers are less obvious than the region selector suggests:
- Backups and replicas may be configured to a different region by default
- Managed service metadata and logs may transit or reside elsewhere
- Support access may come from other jurisdictions — check the provider's terms
- Sub-processors used by the service, each with their own locations
For organisations operating across jurisdictions, the governing regime differs by country — Nigeria's NDPA, Kenya's DPA, the UK's GDPR and so on each impose different obligations on cross-border transfer.
Evidence you must produce
An auditor will accept the provider's attestation for the provider's layer. For yours they will want:
- Your configuration, evidenced continuously rather than screenshotted at audit
- Access reviews for cloud identities, including roles and service principals
- Your own logging, retained per your obligation
- Your risk analysis covering cloud-hosted systems
- The BAA, and evidence PHI is confined to covered services
See compliance automation for collecting most of that continuously.
Where to start
Find the complementary user entity controls section of your main provider's SOC 2 report and check whether you satisfy each item. It is a short list, it is written by the provider, and it is the part of cloud compliance most often missed entirely.
GuardsArm assesses cloud compliance posture for healthcare workloads. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


