Amazon Nova Act is now HIPAA compliant

Health and life sciences (HCLS) organizations rely on repetitive, manual browser-based tasks for critical workflows such as claims processing and referral communication. Although agent AI can automate this workflow, compliance requirements under the Health Insurance Portability and Accountability Act (HIPAA) have limited detection where electronic protected health information (ePHI) may exist. Amazon Nova Act now qualifies as a HIPAA-eligible service, so you can use independent, browser-based AI agents to automate the eIPH connection to care in health.
In this post, you'll learn what the Nova Act provides, how HIPAA eligibility applies to agent AI, and how to get started.
About the Amazon Nova Act
Amazon Nova Act is available as an AWS service for building and managing a fleet of reliable AI agents to automate UI workflows at scale. Nova Act eliminates repetitive UI workflows in the browser and escalates to a human operator when appropriate. Nova Act also integrates with external tools through API calls, Model Control Protocol (MCP), or agent frameworks, such as Strand Agents. You can define workflows by combining natural language variables with Python code.
Amazon Nova Act helps you automate real-world browser tasks that previously required effort. A model can navigate websites, fill out forms, extract information, and complete multi-step workflows on your behalf. For HCLS organizations, this translates into reduced administrative burden, faster claims turnaround, and more consistent execution of routine procedures.
Why HIPAA compliance is important for an AI agent
Unlike text-only models, agent AI systems interact with live systems, access data, and implement workflows that may include Protected Health Information (PHI). Under the AWS Shared Responsibility Model, we manage the security of the underlying infrastructure, and you remain responsible for setting up controls to achieve HIPAA compliance throughout your deployment.
Health utility cases
With HIPAA eligibility, you can now automate appointment scheduling, insurance verification, and pre-authorization across provider and payer portals. You can check claim status, submit complaints, and track refunds on payer websites without manual intervention. You can also send and track transfers between suppliers and collect data from multiple systems for compliance reporting.
Getting started
To begin implementing the Nova Act in your HIPAA eligible environment, complete the following steps:
- Use the AWS BAA through the self-service process in the AWS Management Console and designate your account as a HIPAA account.
- Review the Nova Act documentation for service-specific security settings.
- Implement security controls including AWS Identity and Access Management (IAM) access policies, AWS Key Management Service (AWS KMS) encryption, and AWS CloudTrail logging.
- Perform a design review using the AWS Well-Designed Tool before deploying workloads that include ePHI.
For detailed implementation guidance, consider engaging AWS Professional Services or a productive AWS AI Competency partner.
Things you should know
- HIPAA Eligibility – Amazon Nova Act is included in the reference list of HIPAA eligible services. If you have a signed AWS BAA, you can use Nova Act to process ePHI.
- Integration – Nova Act works with the Strands Agents framework and integrates with Amazon Bedrock AgentCore, Amazon CloudWatch, and IAM.
- Availability – Amazon Nova Act is available in the US East (N. Virginia) AWS Region. For a list of services available in each region, see the AWS Capacity by Region page.
- The price – Visit the Amazon Nova Act pricing page for details.
- A note of compatibility – HIPAA eligibility means that the service is designed for use in accordance with HIPAA requirements. You are responsible for configuring the Service to meet your specific compliance obligations. This announcement is not intended to provide legal or compliance advice.
The conclusion
With HIPAA eligibility, you can now bring agent AI into regulated healthcare environments. Deploy your AWS BAA today and explore the Nova Act documentation to implement your first compliant AI workflow.
For more information, visit AWS Cloud Security — HIPAA Compliance and HIPAA Eligible Services Reference.
Read more
About the writers



