Back to Blog
Compliance
8 min read

Cloud Compliance: What the Provider Covers and What You Still Owe

A compliant cloud provider does not make your workload compliant. Where the responsibility boundary actually falls, and the evidence you have to produce yourself.

GuardsArm Team

Security Experts

May 5, 2025

Cloud compliance

"Our cloud provider is HIPAA compliant" is the most common misunderstanding in cloud healthcare deployments. Providers offer HIPAA-eligible services and sign a BAA. What runs inside your account — access control, encryption settings, logging, who can reach what — is yours, and it is where essentially every cloud healthcare breach has originated.

Eligible, not compliant
The provider makes compliance possible; your configuration decides it
Defined service list
A BAA covers named services only — using others for PHI is outside it
Evidence is yours
Their attestation covers their layer; yours covers the rest

Where the boundary actually falls

LayerWho
Physical data centre, hardwareProvider
Hypervisor, host operating systemProvider
Managed service patchingProvider, for managed services only
Guest OS on VMs you runYou
Network configuration, security groupsYou
Identity and access managementYou
Encryption settings and key managementYou
Data classification and handlingYou
Application securityYou
Audit logging configuration and retentionYou

The pattern is consistent: the provider secures the platform, you secure what you build on it. Managed services shift more to the provider, which is a good reason to prefer them — but never all of it, and never the access control.


Read the attestation properly

Providers publish SOC 2 reports, ISO certificates and FedRAMP authorisations. Using them well means:

  • Check the scope — which services and which regions are covered
  • Check the date — attestations cover a defined period
  • Read the complementary user entity controls. Every SOC 2 report lists what the customer must do for the provider's controls to be effective. This section is your homework and is almost universally skipped.
  • Map their controls to your framework so you inherit deliberately and can evidence the inheritance
The CUEC section is your requirements list
Complementary user entity controls state, in the provider’s own report, the things you must do. An assessor who reads the provider report will read that section and ask how you satisfy it. It is the single most useful page in the document.

Configuration is where it fails

The provider's compliance does not prevent:

  • A storage container made public
  • An over-permissive role granting broad access
  • A database with a public endpoint
  • Audit logging disabled or with short retention
  • PHI placed in a service outside the BAA's covered list
  • Data stored in a region that breaches a residency requirement

These are covered in preventing cloud misconfiguration. The compliance point is that every one of them is your finding, not theirs.


Residency and jurisdiction

Where data physically sits matters for several regimes, and the answers are less obvious than the region selector suggests:

  • Backups and replicas may be configured to a different region by default
  • Managed service metadata and logs may transit or reside elsewhere
  • Support access may come from other jurisdictions — check the provider's terms
  • Sub-processors used by the service, each with their own locations

For organisations operating across jurisdictions, the governing regime differs by country — Nigeria's NDPA, Kenya's DPA, the UK's GDPR and so on each impose different obligations on cross-border transfer.


Evidence you must produce

An auditor will accept the provider's attestation for the provider's layer. For yours they will want:

  • Your configuration, evidenced continuously rather than screenshotted at audit
  • Access reviews for cloud identities, including roles and service principals
  • Your own logging, retained per your obligation
  • Your risk analysis covering cloud-hosted systems
  • The BAA, and evidence PHI is confined to covered services

See compliance automation for collecting most of that continuously.


Where to start

Find the complementary user entity controls section of your main provider's SOC 2 report and check whether you satisfy each item. It is a short list, it is written by the provider, and it is the part of cloud compliance most often missed entirely.

GuardsArm assesses cloud compliance posture for healthcare workloads. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.