HITRUST-Certified Bedrock Deployment — PHI-Safe RAG + AI for Healthcare
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
**HITRUST listings exist. Amazon Bedrock listings exist. The combination does not — until now.**
HITRUST CSF v11.6 (2024) introduced the **HITRUST AI Security Assessment**, the first AI-specific control set with 51+ requirements covering lifecycle controls, prompt injection, output validation, and training data governance. Health systems, payers, and digital health now face a gap: HITRUST MyCSF includes AI workloads, but Bedrock deployments (ambient scribes, clinical copilots, claims AI, PHI-safe RAG) weren’t built with HITRUST mapping. HHS OCR 2024 enforcement (Cascade Eye & Skin $1.5M; Doctors’ Management Services) plus proposed 2025 Security Rule updates increase pressure, while insurers and enterprise buyers now require HITRUST AI attestation.
Show the rest of the publisher’s description (11 more lines)
Current AWS Marketplace listings are one-or-the-other. ClearDATA sells HITRUST-inheritable managed cloud at $15K–$75K/mo ($180K–$900K/yr) but locks Customer into ClearDATA tenancy with no Bedrock blueprint. HI-TEX is infrastructure-only. Mactores is SageMaker-era. Traditional SI HITRUST + AWS engagements $250K–$750K over 4–8 months. Big-4 AI governance + HITRUST combined deals $500K–$1.5M. **N23 is the first transparent, fixed-fee, turn-key Bedrock deployment on a HITRUST-certified AWS landing zone with AI Security Assessment evidence packaged for EAO handoff.**
Methodology leverages Kriv's live **N8 HITRUST Roadmap**, **N11 FHIR Patient Engagement**, and **E3 HIPAA AI Governance Framework**. Deployment on Customer's AWS account (not ClearDATA-style managed tenancy).
**Reference architecture.**
AWS Landing Zone (Organizations Security/Audit/Workload/Sandbox; Control Tower; SCPs mapped to CSF families). Identity & Access (IAM Identity Center + SAML; MFA; least-privilege; Access Analyzer; quarterly reviews). Network (private VPC; PrivateLink for Bedrock / SageMaker / S3 / Secrets Manager; zero internet egress for PHI; VPC Flow Logs). Encryption (KMS CMKs; BYOK / CloudHSM; envelope; annual rotation). **Bedrock** with **Guardrails** (PHI, denied topics, medical-misinformation, bias/fairness), **Model Invocation Logging** to S3 Object Lock, **Knowledge Bases** PHI-safe RAG, **Agents** with HITL clinical gates, **Model Cards** + **Model Monitor**. **PHI-Safe RAG** via OpenSearch Serverless (KMS); ingestion via Textract + Comprehend Medical + Macie redaction; §164.514 Safe Harbor de-id; embeddings stay in Customer AWS account. **Audit Manager HITRUST framework** automated evidence indexed to CSF v11.6 control IDs; CloudTrail org trail + S3 Object Lock 7-yr HIPAA §164.316. Threat Detection (GuardDuty + Security Hub + Macie + Inspector). IR (CloudWatch + EventBridge + SNS to SOC; AI IR Runbooks). BCDR aligned to CSF §10.02.
**CSF v11.6 coverage.**
All 19 control families at infrastructure layer. The 51+ AI Security Assessment requirements covered through Bedrock + Guardrails + Model Monitor + CloudTrail + Audit Manager — model governance, prompt-injection defenses, data lineage, bias testing, explainability, AI IR, vendor AI risk.
**Week-by-week (8-week Foundation).**
W1 Kickoff + HITRUST scope (e1/i1/r2/r2+AI) + use-case discovery + EAO shortlist (A-LIGN, Schellman, Coalfire, Insight Assurance). W2 Landing-zone provisioning. W3 Bedrock + Guardrails + Model Invocation Logging. W4 PHI-safe RAG. W5 Guardrails tuning + Agents HITL + Model Cards. W6 Audit Manager HITRUST + Model Monitor. W7 Security controls (GuardDuty, Security Hub, Macie, Inspector, IR runbooks). W8 EAO handoff + UAT + readout + 30-day warranty.
**Three tiers.**
Foundation $95K (6–8 wk; 1 use case; 19 CSF families; e1/i1 scope; 30-day warranty) for digital health Series B–C, single-hospital providers, small payers. Standard $175K (10 wk; up to 3 use cases; full AI Security Assessment evidence; r2 scope; 60-day warranty) for regional systems $1B–$5B, Medicaid MCOs, regional MA. Enterprise $275K (12 wk; up to 5 entities; r2+AI scope; Bedrock Agents orchestration; EAO engagement support; 90-day hypercare) for large IDNs, national Blues, Series D digital health, AMCs. Optional Extra Use-Case $40K each. EDP-eligible — HITRUST deployment engagement fees ($95K–$275K) count toward your AWS Enterprise Discount Program commitment (up to 25%). AWS infrastructure (Bedrock, KMS, OpenSearch, Audit Manager, Macie, GuardDuty) billed separately by AWS. Contact info@kriv.ai to structure a private offer against your EDP or PPA.
**Important disclosures**. Kriv is NOT a HITRUST External Assessor Organization (EAO); HITRUST certification is issued by HITRUST Alliance via independent EAO assessment—Kriv prepares evidence only. Kriv issues no HITRUST, SOC 2, ISO 42001, or HIPAA certifications. Acts as Customer’s BA where PHI flows (BAA required pre-kickoff). No legal, regulatory, or clinical advice. AWS infrastructure billed separately. Bedrock/Claude outputs require CMIO/medical director governance review. No guarantee of HITRUST certification, OCR audit outcome, enforcement avoidance, or cyber-insurance benefit.
Highlights
Highlighted by the publisher on AWS Marketplace.
First HITRUST-certified Bedrock deployment SKU on AWS Marketplace — CSF v11.6 + HITRUST AI Security Assessment (51+ requirements) evidence indexed for EAO handoff. All 19 CSF control families addressed at infrastructure layer. Bedrock with Guardrails (PHI detection + denied topics + medical-misinformation + bias/fairness), Model Invocation Logging to S3 Object Lock, Knowledge Bases for PHI-safe RAG, Agents with HITL clinical gates, Model Cards, Model Monitor.
PHI-safe RAG via Amazon OpenSearch Serverless (KMS-encrypted) + Textract + Comprehend Medical + Macie redaction. §164.514 Safe Harbor de-identification path. Embeddings remain in Customer AWS account — no cross-account or external-vendor egress. CloudTrail org trail with S3 Object Lock immutable retention (7-year HIPAA §164.316). AWS Audit Manager HITRUST framework automated evidence collection indexed to CSF v11.6 control IDs. IAM Identity Center with SAML + MFA + quarterly access reviews.
Deploys on Customer's AWS account (no managed-cloud lock-in) — AWS Select + Databricks + Anthropic CPN. EAO handoff package included (A-LIGN, Schellman, Coalfire, Insight Assurance shortlist). Three tiers: Foundation $95K (6–8 weeks; 1 use case; e1/i1 scope) for digital health Series B–C; Standard $175K (10 weeks; 3 use cases; r2 scope; full AI Security Assessment evidence) for regional health systems; Enterprise $275K (12 weeks; IDN up to 5 entities; r2+AI scope; 90-day hypercare)
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

