Start Free Trial

AWS security for HealthTech start-ups

Health data is among the most sensitive information a company can hold, and NHS and healthcare partners expect proof that it is protected. bearhug continuously checks your AWS environment for the misconfigurations that expose data, and helps you fix them in minutes.

What NHS and healthcare buyers ask about cloud security

NHS organisations and healthcare partners usually ask suppliers to complete security assessments and questionnaires before they share data. For a HealthTech on AWS, these are the questions that come up most.

  1. Where is patient data stored, and is it encrypted?

    Buyers want to know that health data is encrypted at rest and in transit, wherever it lives.

    How bearhug helps: Findings flag unencrypted RDS databases and EBS volumes, and S3 buckets that do not enforce TLS.

  2. Who can access it?

    Access to patient data should be limited to the people and systems that need it.

    How bearhug helps: IAM findings show users without MFA, unused access keys and policies that are broader than they need to be.

  3. Is access logged and monitored?

    You need to be able to show who accessed what, and to spot unusual activity quickly.

    How bearhug helps: bearhug checks that CloudTrail is logging management events, and GuardDuty threat detections arrive as plain-English email alerts. Recording who read individual files in S3 needs CloudTrail data events or S3 server access logging as well.

  4. Could data be exposed by mistake?

    A single public bucket or open database can turn into a reportable data breach.

    How bearhug helps: One-click fixes block public access on S3 buckets and close security group rules that are open to the internet.

Encrypting and restricting access to patient data on AWS

  • Encrypt everything at rest. S3 encrypts new objects by default, but RDS and EBS encryption must be turned on. Consider AWS KMS customer managed keys for the most sensitive data, so you control and log every use of the key.
  • Enforce encryption in transit. Require TLS for every connection, including in S3 bucket policies.
  • Keep data private by default. Turn on S3 Block Public Access at account level, and keep databases out of public subnets. Read more about AWS S3 bucket security.
  • Grant least privilege. Give each person and service only the permissions they need, and remove access keys that are no longer used.
  • Keep a record. CloudTrail logs management activity across your account. To record access to individual objects in buckets that hold patient data, turn on CloudTrail data events or S3 server access logging. Versioning on important buckets protects against accidental deletion.

GDPR and ISO 27001 foundations

Under UK GDPR, health data is special category data, which carries stricter requirements for how it is protected. Many healthcare buyers also look for ISO 27001 as evidence of a mature approach to information security.

bearhug maps its AWS findings to GDPR and ISO 27001 controls, so you can see which issues affect which framework and show progress over time. It is a foundation, not a certification: it covers the AWS configuration side, not your policies, training or wider processes.

Built for small HealthTech teams

Most HealthTech start-ups have engineers who know AWS well but no one whose full-time job is security. bearhug explains every finding in plain English, fixes common issues in one click with rollback and alerts you when something new and critical appears. Set-up takes under five minutes with a CloudFormation stack, and it costs $100 per AWS account per month.

See how the real-time AWS security alerts work, or read more about AWS security for start-ups.

HealthTech questions

No. bearhug does not certify you against any healthcare standard. It finds and fixes the AWS configuration issues that healthcare buyers and assessments look for, and maps findings to GDPR and ISO 27001 controls.

No. bearhug works with security settings and findings from your AWS account. It does not read the contents of your databases, files or backups.

Yes. bearhug works in any AWS Region where Security Hub is available. Findings come from the controls enabled in each Region, and some controls are not available in every Region. That includes London (eu-west-2).

bearhug costs $100 per AWS account per month, with every feature included. A HealthTech with production, staging and development accounts pays $300 a month, billed through AWS Marketplace.

Show healthcare buyers your AWS security is under control

14-day free trial. The paid plan is $100 per AWS account per month, billed through AWS Marketplace.

No credit card. No procurement. Starts from your AWS console.