HomeMachine LearningAmazon Nova Act is now HIPAA eligible

Amazon Nova Act is now HIPAA eligible

Healthcare and life sciences (HCLS) organizations have long relied on repetitive, manual browser-based tasks for critical workflows such as claims processing and referral coordination. These tasks, while essential, are time-consuming and prone to human error. The introduction of agentic AI presents an opportunity to automate these workflows, significantly enhancing efficiency and accuracy. However, compliance requirements under the Health Insurance Portability and Accountability Act (HIPAA) have traditionally limited the adoption of such technologies, particularly where electronically protected health information (ePHI) is involved. With Amazon Nova Act now being considered a HIPAA eligible service, healthcare organizations can deploy autonomous browser-based AI agents to automate complex ePHI-related workflows, ushering in a new era of operational efficiency.

In this article, you’ll discover what Nova Act offers, how HIPAA eligibility applies to agentic AI, and how to get started with this groundbreaking technology.

About the Amazon Nova Act

Amazon Nova Act is an Amazon Web Services (AWS) offering designed to create and manage fleets of trusted AI agents that automate production UI workflows at scale. Nova Act excels at completing repetitive UI workflows in the browser, and when necessary, seamlessly passes tasks to a human supervisor. By integrating with external tools via API calls, Remote Model Control Protocol (MCP), or agentic frameworks like Strand Agents, Nova Act offers a versatile solution for a wide range of applications. Workflow definition is made user-friendly through the combination of natural language and Python code, providing flexibility and ease of use.

For HCLS organizations, the benefits of Amazon Nova Act are substantial. The service automates real-world browser tasks that previously required manual effort, such as navigating websites, filling out forms, extracting information, and executing multi-step workflows. This translates to a reduced administrative burden, faster processing of claims, and more consistent execution of routine processes.

Why HIPAA Eligibility Matters for Agentic AI

Agentic AI systems stand apart from traditional AI models that merely generate text. These systems interact with live environments, access sensitive data, and execute workflows that may involve protected health information (PHI). Under the AWS Shared Responsibility Model, AWS is responsible for managing the security of the underlying infrastructure, while you are tasked with configuring controls to ensure HIPAA compliance within your deployments. This division of responsibility is crucial for maintaining the integrity and confidentiality of ePHI.

Healthcare Use Cases

With the HIPAA eligibility of Amazon Nova Act, healthcare organizations can now automate key processes such as appointment scheduling, insurance verification, and prior authorization across provider and payer portals. Tasks like checking claim status, submitting appeals, and tracking reimbursements on payer websites can be handled automatically, eliminating the need for manual intervention. Furthermore, Nova Act facilitates the sending and tracking of referrals between suppliers and the collection of data from multiple systems for compliance reporting.

Getting Started

To begin using Nova Act in your HIPAA eligible environment, adhere to the following steps:

  1. Run an AWS Business Associate Agreement (BAA) through the self-service process in the AWS Management Console and designate your account as a HIPAA account.
  2. Consult the Nova Act documentation for service-specific security configurations.
  3. Implement security controls, including AWS Identity and Access Management (IAM) access policies, AWS Key Management Service (AWS KMS) encryption, and AWS CloudTrail logging.
  4. Conduct a design review using the AWS Well-Architected tool before deploying workloads involving ePHI.

For detailed implementation guidance, consider leveraging AWS Professional Services or an AWS Generative AI Skills Partner.

Key Considerations

  • HIPAA Eligibility – Amazon Nova Act is among the services listed as HIPAA eligible. With a signed AWS BAA, you can use Nova Act to process ePHI.
  • Integration – Nova Act integrates with the Strands Agents framework and works with Amazon Bedrock AgentCore, Amazon CloudWatch, and IAM.
  • Availability – Amazon Nova Act is currently available in the AWS US East (N. Virginia) Region. For a complete list of available services by region, refer to AWS Capabilities by Region.
  • Pricing – For detailed pricing information, visit the Amazon Nova Act pricing page.
  • Compliance Rating – HIPAA eligibility indicates that the service is designed to adhere to HIPAA requirements. It is your responsibility to configure the service to meet your specific compliance obligations. This announcement does not constitute legal or compliance advice.

Conclusion

With HIPAA eligibility, agentic AI can now be introduced into regulated healthcare environments, offering a new dimension of automation and efficiency. Run your AWS BAA today and delve into the Nova Act documentation to deploy your first compliant agentic AI workflow.

For further information, refer to AWS Cloud Security — HIPAA Compliance and the HIPAA Eligible Services Reference. Here

About the Authors

Abiola Babsalaam is a Senior Technical Account Director at Amazon Web Services (AWS), where he serves as a trusted cloud advisor to enterprise customers in the financial services industry. With deep expertise in generative AI, agentic AI, database architecture, and cloud strategy, Abiola helps organizations harness the power of AWS AI/ML services to modernize their infrastructure, automate complex workflows, and drive innovation at scale.

Nishant Dhiman is a Senior Solutions Architect at AWS based in Sydney. He has extensive experience in serverless, generative AI, security, and mobile platform offerings. He is a voracious reader and passionate technologist. He enjoys interacting with customers and believes in giving back to the community through learning and sharing. Outside of work, he enjoys podcasts, calligraphy, and music.

Shruti Arora is a Specialized GenAI Solutions Architect at Amazon AGI, where she partners with customers across industries to design and deploy agentic systems in production. She brings a strong foundation in software development and solutions architecture, with experience transforming complex AI concepts into real-world applications. Outside of work, Shruti is just as curious. You’ll find her lost in a good book or immersed in a new arts and crafts project.

“`

Must Read
Related News

LEAVE A REPLY

Please enter your comment!
Please enter your name here