
It is not so important for the exam I assume, but HIPAA is not a compliance AWS achieve, that is to say AWS market an AWS Service as being HIPAA ‘eligible’ and there are no AoC (Attestations of compliance) on AWS itself for HIPAA.
A customer must do a complete HIPAA compliance audit.
This is entrely different from PCI, SOC, ISO ect where AWS achieved an AoC and a customer wishing to also attain compliance are required only to have the gap audit, with HIPAA (and others) this is not the case at all.