🟡 🤝 Agents Published: · 3 min read ·

AWS: Nova Act receives HIPAA eligibility — agentic ePHI automation for healthcare workflows

Editorial illustration: Nova Act receives HIPAA eligibility — agentic ePHI automation for healthcare workflows

AWS announced on 21 May 2026 that Amazon Nova Act, the agentic AI service for automating browser and UI workflows, has received formal HIPAA-eligible status. Healthcare organisations can now use Nova Act to work with protected health information (ePHI) — authorising prior authorisations, verifying insurance, and submitting referrals through vendor web portals. The service integrates with Amazon Bedrock AgentCore and the Strand Agents framework, requires a signed BAA agreement and AWS KMS encryption, and currently operates only in the US East (N. Virginia) region.

🤖

This article was generated using artificial intelligence from primary sources.

AWS announced on 21 May 2026 that Amazon Nova Act — their agentic AI service for automating browser and UI workflows — has received formal HIPAA-eligible status. This is a significant development as it opens a large segment of the healthcare market to agentic AI use cases that had previously been blocked by regulatory restrictions around protected health information (ePHI).

What can Nova Act now do in healthcare?

Nova Act is designed for UI-driven automation — an agent that can open a webpage, fill in a form, click links, and navigate complex portals just as a human would. In the healthcare context, this opens several high-value use cases:

Prior authorization — submitting requests to insurers for pre-authorisation of complex medical procedures. This is currently one of the largest sources of administrative burden in the American healthcare system — employees spend hours navigating through different insurer portals. An agent that does this autonomously could significantly reduce operational costs and accelerate patient care.

Insurance verification — checking benefits, deductibles, and copays for each patient prior to scheduling a procedure. Typically done manually or through fragmented integrations; agentic AI can process all of this through the same portals used by a human operator.

Referral submission — transferring a patient from primary care to a specialist with complete paperwork.

What is the technical architecture?

Nova Act integrates with several AWS layers:

  • Amazon Bedrock AgentCore — runtime for agent execution with built-in safety guardrails
  • Strand Agents framework — Amazon’s agent orchestration framework released earlier this year
  • AWS KMS — encryption-at-rest for all ePHI data the agent processes
  • IAM + CloudTrail — access control and complete audit log of all agent actions

For HIPAA compliance, organisations must have a signed BAA (Business Associate Agreement) with AWS — the standard document establishing AWS as a processor of protected data.

What are the geographic limitations?

The service is currently available only in US East (N. Virginia). This is a typical AWS pattern for new regulated services — first introduced in the main US region, then gradually expanded to other countries as local compliance certifications are achieved.

European users (GDPR, EU AI Act) cannot currently use Nova Act for healthcare workflows. AWS has not published a timeline for EU expansion, but the growing regulatory pressure of the EU AI Act on high-risk AI systems in healthcare could slow that expansion.

What does this mean for the healthcare AI sector?

HIPAA eligibility is the threshold without which agentic AI cannot access clinical use cases in the United States. AWS now gains first-mover advantage in this segment — Microsoft (through Azure and Nuance integration), Google Cloud (Med-PaLM, Vertex AI), and Anthropic Claude are currently either HIPAA-eligible for chat use cases or working on agentic equivalents.

The value of agentic AI in healthcare is dramatically greater than in a standard chat use case — administrative costs account for 25-30% of total healthcare expenditure in the United States (over 1 trillion USD annually). Automating prior auth and insurance verification could save tens of billions annually.

Frequently Asked Questions

What is Amazon Nova Act?
Nova Act is an AWS agentic AI service that automates browser and UI workflows — it can fill out forms, click links, and navigate web portals on behalf of the user.
Which healthcare workflows does Nova Act support?
Prior authorization, health insurance verification, referral submission, and other UI-driven tasks through healthcare provider web portals.
What is required for a HIPAA-compliant Nova Act deployment?
A signed BAA (Business Associate Agreement) with AWS, AWS KMS data encryption, IAM access control, and CloudTrail audit logging.