Healthcare data tends to spread across object storage: patient uploads, exports, backups, reports, support attachments, migration files, model inputs, and temporary processing artifacts. Access controls and encryption protect known locations. They do not tell you where sensitive data has appeared unexpectedly.
Amazon Macie is an AWS sensitive-data discovery service for Amazon S3. In each enabled Region, it inventories general purpose buckets, evaluates security and access settings, and analyzes eligible objects using machine learning and pattern matching for credentials, financial information, PII, and PHI-related data types.
For a healthcare software team, the practical question is narrower than "are we compliant?" It is whether S3 buckets, exports, logs, uploads, and migration artifacts contain PHI in places the architecture did not intend.
Macie eligibility and service scope rechecked September 24, 2026, against the AWS HIPAA Eligible Services Reference and Macie overview. The broader review below retains its original scope.
Reviewed 22 August 2026: current AWS Macie, HIPAA-eligible services, BAA, S3 security, pricing, endpoints, and CloudTrail documentation, plus HHS cloud-computing guidance.
HIPAA eligible is not HIPAA compliant
AWS lists Amazon Macie among services eligible for workloads involving ePHI. AWS also says covered entities and business associates must enter into an AWS business associate agreement before using HIPAA-eligible services with PHI, and customers remain responsible for their own HIPAA compliance.
HHS cloud guidance likewise says using a cloud service with ePHI requires an applicable BAA and compliance with the HIPAA Rules, including the customer's own risk analysis and risk management. This article is engineering guidance, not legal advice; the organization's privacy, security, and legal owners should determine whether data is PHI and whether a design meets its obligations.
Macie can support data inventory, risk analysis, monitoring, and investigation. It does not provide a legal determination that a value is PHI, replace least-privilege access, remediate unsafe buckets automatically, establish retention policy, or satisfy every Privacy, Security, and Breach Notification Rule obligation.
Macie is primarily an S3 control
Macie creates an inventory of S3 general purpose buckets in each Region where it is enabled. It can identify bucket-level policy issues and inspect eligible objects for sensitive data. It does not directly scan application databases, EBS volumes, message queues, file systems, or third-party storage. Application logs are in scope only when eligible log objects are stored in S3.
AWS documents a workaround for some other data stores: export supported RDS, Aurora, or DynamoDB data into S3 and scan the export. That creates another copy of potentially sensitive data, so the export bucket, encryption, permissions, retention, and deletion need their own design.
Supported formats include Avro, Parquet, common archives, email, non-binary text, PDF, Word, and Excel files. Macie does not analyze images, audio, video, S3 directory buckets, or objects in unsupported storage classes such as Glacier Deep Archive and S3 Express One Zone. File-size, archive-depth, extraction, and occurrence-reporting quotas also limit analysis.
Macie analyzes the latest version of an eligible object. Unsupported, inaccessible, over-quota, or otherwise skipped objects must remain visible in coverage and discovery results rather than being counted as clean.
Does a clean Macie scan mean there is no PHI?
No. Coverage depends on bucket scope, Region, object version, storage class, file format, size, permissions, job configuration, sampling, and the identifiers selected. Treat a clean result as evidence about the documented scope, not proof that the workload is free of PHI.
Before using a scan to approve an export or migration, record what was selected, what was actually analyzed, and what was skipped. Assign an owner to unresolved coverage gaps. A discovery result is one input to a data-handling decision, not permission to copy patient data into a less restricted environment. The production-data and staging guide covers that separate approval decision.
Use broad discovery and targeted jobs differently
Automated discovery
Evaluates the current Region's S3 inventory daily and samples representative eligible objects. Use it for broad visibility and to identify buckets that need deeper investigation.
Discovery jobs
Analyze selected buckets or buckets matching runtime criteria once or on a daily, weekly, or monthly schedule. Use them for controlled reviews of defined data zones.
Automated discovery is deliberately representative, not exhaustive. A job can also sample less than 100% of eligible objects; that percentage selects whole objects, not the same percentage of bytes from every object. For a migration, incident, new data lake, patient-document bucket, or control requiring defined coverage, create a targeted job with 100% sampling and record its bucket and object criteria, object eligibility, failures, and results.
A saved job's scope and analysis settings cannot be edited. Treat its configuration as audit evidence, and create a new job when the scope or identifier set must change.
Managed identifiers find patterns, not every clinical fact
Managed data identifiers are built-in detectors for specific data types. The PHI category includes particular health-insurance, medical-identification, and procedure-code patterns; several require a nearby keyword and support only specified countries or geographic regions.
That label does not mean Macie understands every diagnosis, narrative note, DICOM image, organization-specific patient identifier, or the legal context that makes information PHI. Detection depends on the available identifiers, language and keyword rules, file structure, and supported format.
Use custom data identifiers for stable organization-specific patterns such as a patient-account format, internal member number, or document marker. A custom identifier combines a regular expression with optional keywords, ignore words, proximity, and finding-severity settings. Test it against representative synthetic positives, near misses, and benign values before production use.
Allow lists suppress exact text or matching patterns across managed and custom identifiers. Keep them narrow and review them like code: an overly broad regex can turn a noisy detector into a false-negative gap.
Plan KMS access without widening human access
Macie uses the AWSServiceRoleForAmazonMacie service-linked role to inventory buckets and retrieve objects. A restrictive bucket policy with an explicit deny can still block it. Review coverage errors, bucket policies, organization boundaries, and cross-account access before assuming a bucket is covered.
Macie can decrypt objects protected with SSE-S3 and AWS-managed KMS keys. For SSE-KMS or DSSE-KMS with a customer-managed key, the Macie role needs kms:Decrypt permission on that key. Macie cannot decrypt SSE-C or client-side encrypted objects and can report only their metadata.
Grant the service only the access required for discovery. Do not solve a scan failure by broadly granting staff or unrelated roles access to patient data. Investigate the error, correct the narrow policy path where appropriate, or record the object set as a known coverage gap.
Protect findings and discovery results
Macie sensitive-data findings report the category, type, count, affected bucket and object, severity, encryption and access information, and up to 15 detection locations. A finding does not include the sensitive value itself. Macie retains findings for 90 days.
Sensitive-data discovery results are per-object analysis records, including objects that produced no finding or could not be analyzed. They can include up to 1,000 locations per detected data type, but not the sensitive values. Macie also retains these results for 90 days; for accessible long-term retention, configure a Region-appropriate S3 repository and customer-managed KMS key.
The results repository needs Block Public Access, restricted write and read paths, SSE-KMS, lifecycle and deletion policy, access logging decisions, and separation from the source data. Configure it in each Macie Region; an administrator account's repository receives results for member-account data that it analyzes.
Object names, bucket names, paths, and occurrence locations can still reveal sensitive context. AWS also recommends keeping confidential information out of tags and free-form resource names because those values may appear in billing or diagnostic logs.
Revealing a sample is a privileged action
Macie can optionally retrieve and reveal samples behind a finding. It locates the first 1–10 occurrences, extracts the first 1–128 characters of each, encrypts them with a customer-specified KMS key, stores them briefly in an encrypted cache, and then deletes them. The required actions are logged in CloudTrail.
Sample reveal does not use the Macie service-linked role. It uses the investigator's IAM identity or a role that Macie is allowed to assume, plus access to the affected object, discovery result, and KMS key. AWS recommends custom IAM policies and a dedicated KMS key. The feature is unavailable in Asia Pacific (Osaka) and Israel (Tel Aviv), and it supports a narrower set of object formats and sizes than classification.
This capability displays actual sensitive values. Limit it to named investigators, alert on CloudTrail activity, and define when reveal is justified. Routine triage should begin with finding metadata and a synthetic reproduction where possible.
Budget and enable Macie Region by Region
Macie is available in a defined subset of AWS Regions, and its inventory, automated-discovery settings, jobs, findings, coverage, quotas, and cost estimates are Regional. Enable and configure it in every Region that can contain in-scope S3 data; do not infer global coverage from one console view.
Macie cost has three relevant dimensions: monitoring general purpose buckets for security and access control, monitoring S3 objects for automated discovery, and analyzing uncompressed bytes through automated discovery or jobs. AWS currently includes 1 GB of sensitive-data analysis per month at no charge; the allowance is shared across an organization under consolidated billing and does not roll over.
Forecast a targeted job before submitting it, inspect the current Region's month-to-date estimate, and include S3, KMS, CloudTrail, EventBridge, Security Hub, and downstream processing in the operating budget. Use job criteria and sampling when they match the risk question. Excluding buckets solely to reduce spend creates a documented coverage gap, not a clean result.
Route findings without spreading PHI context
Macie automatically publishes findings to Amazon EventBridge and can publish them to AWS Security Hub CSPM. That enables alerting, ticket creation, quarantine workflows, ownership routing, and reporting. Each destination becomes part of the security data flow.
Keep notifications minimal. Send a finding ID, severity, account, approved resource reference, and response link rather than copying full details into email or chat. Confirm that downstream services are HIPAA eligible where they will process ePHI, included under the applicable AWS BAA, and configured appropriately.
CloudTrail captures Macie API calls as management events, including listing findings, creating jobs, and revealing samples. Separately decide whether CloudTrail S3 data events or S3 server access logging are needed for object-level access evidence; Macie does not replace those logs.
Use sample findings to test EventBridge and Security Hub automation without placing real patient data into development or test channels.
A finding is a lead, not an incident verdict
Route each finding to an accountable data owner. First verify that the object, identifier type, occurrence count, and access posture match the reported metadata. Reveal a sample only when metadata and a synthetic reproduction cannot answer the question.
If the match is benign, record the evidence and tune the custom identifier, keyword distance, ignore words, or allow list narrowly. If it is likely PHI in an unapproved location, follow the organization's incident process: preserve evidence, restrict unsafe access, identify the producing workflow and downstream copies, apply approved retention and deletion rules, and involve authorized privacy and security owners.
Macie does not move, quarantine, redact, or delete the object automatically. After remediation, rerun a scoped job and verify the S3 policy, encryption, logging, lifecycle, and application path that allowed the data to appear. Closing the finding without fixing the producer invites recurrence.
A practical Macie rollout
- Confirm the AWS BAA, HIPAA-account scope, Regions, organization structure, and responsible security and privacy owners.
- Inventory S3 buckets, data owners, expected data classes, encryption, access, lifecycle, and approved ePHI locations.
- Enable Macie in a controlled account and Region, then review the service-linked role and organization administration model.
- Use automated discovery for broad visibility and targeted jobs for defined healthcare data zones.
- Select managed identifiers, add tested custom identifiers, and maintain narrow allow lists.
- Track unsupported, encrypted, inaccessible, archived, sampled-out, over-quota, or skipped objects as coverage gaps.
- Protect findings, the discovery-results bucket, KMS keys, sample reveal, exports, CloudTrail logs, and downstream integrations.
- Define severity, ownership, investigation, containment, deletion, false-positive handling, verification, and evidence-retention workflows.
- Measure eligible-object coverage, findings age, false-positive rate, and remediation time; review new buckets, formats, identifiers, accounts, and Regions.
Where Macie earns its place
Macie is most useful when S3 is a meaningful part of the healthcare data estate and the team needs continuous visibility plus targeted investigation. It can reveal that patient or member identifiers have appeared in an unexpected export, analytics bucket, support attachment, or migration artifact.
Its value depends on what follows the finding. Assign data owners, define approved locations, automate safe routing, investigate coverage gaps, and measure remediation. A dashboard of unresolved findings is not a data-protection program.
Connect discovery to containment and data controls
Responding to Suspected PHI Exposure
Contain access, preserve evidence, reconstruct scope, and keep breach decisions with authorized owners.
Secrets and Key Management
Separate key administration, protect KMS use, rotate dependencies, and preserve recovery paths.
Production Data Outside Production
Use synthetic fixtures first and govern any production-derived data through access, expiry, and verified deletion.
Healthcare Software Development
Plan patient apps, cloud systems, data boundaries, and PHI-aware delivery controls together.
Official references: AWS HIPAA and BAA information, Macie sensitive-data discovery, automated discovery, discovery jobs, discovery results, sample retrieval, CloudTrail logging, and S3 security best practices.
Need S3 PHI discovery built into operations?
I can help connect Macie findings to bucket ownership, access review, remediation, incident evidence, and healthcare cloud architecture.
Please do not send patient information, PHI, credentials, or private system details by email.