Where your patient data is stored and why we chose AWS

"Where are my patients' data?" It's probably the most important question you can ask any clinical software. And the answer should be clear, concrete and verifiable.
In Brauni, the answer is simple: Amazon Web Services (AWS), the largest, most used and most secure cloud platform on the planet.
In this article we explain exactly where your patients' clinical information lives, why we choose AWS and what makes this infrastructure the gold standard for health data.
What is "cloud" in simple terms?
When we say your data is "in the cloud," it doesn't mean they float on the internet without control. It means they're stored in physical data centers - real buildings, with real servers, guarded the 24 hours of the day, the 365 days of the year.
The difference is that instead of being on a hard disk under your desk (vulnerable to theft, fire, or mechanical failure), they are in facilities specifically designed to protect critical information.
Why AWS?
The largest cloud in the world
AWS is no longer a cloud. It is the largest cloud infrastructure:
- 34 geographical regions with 108 areas of availability worldwide
- Millions of active customers, including startups, governments and the largest companies on the planet
- More than 31% of the global cloud market - more than Microsoft Azure and Google Cloud combined
- Infrastructure used by organizations such as NASA, the US Department of Defense and thousands of hospitals
Note
AWS was the world’s first public cloud platform (launched in 2006) and has been perfecting its infrastructure for almost two decades. That time advantage translates into maturity, stability and an unmatched security ecosystem.
The Safest Cloud in the World
The security of AWS is not marketing. It is engineering supported by more than 140 security certifications and accreditations, including:
- SOC 1, SOC 2 and SOC 3 - independent audits of security controls
- ISO 27001, 27017, 27018 - International standards for information security management
- HIPAA - U. S. federal law for health data protection (with BAA signed)
- FedRAMP - U. S. federal government authorization for government data
- PCI DSS Level 1 - the highest standard for payment processing
- HITRUST CSF - the most rigorous safety framework in the health sector
Designed for health data
AWS offers health sector-specific services that other providers simply do not have at the same level:
- AWS HealthLake for FHIR format clinical data storage
- Automatic AES-128 encryption on all storage services
- AWS Key Management Service (KMS) for centralized encryption key management
- AWS CloudTrail for immutable recording of all data activity
- AWS Config for continuous monitoring of compliance with security policies
Where exactly do your data live?
Your patients' clinical data on Brauni reside in AWS data centers in the United States, within regions with signed HIPAA and BAA certification.
What's inside an AWS data center?
We are not talking about a room with servers. AWS data centers are world-class facilities with:
- Perimetral physical security: fences, guards 24/7, intruder detection and continuous video surveillance
- Biometric Access Control: Only authorized personnel can enter, with multiple layers of verification
- Electrical re-boot: backup generators and UPS systems that ensure power outage performance
- Fire systems: Early detection and automatic suppression
- Physical destruction of disks: when a hard drive is removed, it is physically destroyed following DoD 5220.22-M standard protocols
Important
If your current clinical software stores data on a local server or generic hosting without health certifications, your patients' information is exposed to risks that an AWS data center eliminates by design.
Redundancy: Your data is never in one place
One of the most important advantages of AWS is automatic redundancy. This means that the data does not live on a single server or in a single building:
Availability areas
Each region of AWS has multiple areas of availability (minimum 3). Each area is an independent data center, with its own power supply, cooling and network connectivity. If one area fails, the others continue to operate.
Automatic replication
In Brauni we set up data replication so that each clinical record exists in multiple copies distributed in different areas. If a complete data center is out of service (something extremely unlikely), your data remains available from another location.
Encrypted backups
In addition to real-time replication, we perform automatic and encrypted backups that are stored independently. This protects against human errors, ransomware attacks or any catastrophic scenario.
How do you travel your data?
When you open Brauni from your computer or cell phone, information travels between your device and AWS servers. That path is also protected:
- TLS 1.3 encrypts all communication between your browser and our servers
- Transfer between services: even within AWS, communication between our databases and application servers is encrypted
- Managed SSL Certificates and automatically renewed
No one can intercept the data while travelling. Neither your internet provider, nor an attacker on a public Wi-Fi network.
AWS vs. other alternatives: numbers speak
| Characteristic | AWS | Generic Hosting | Local server |
|---|---|---|---|
| Safety certifications | 140+ | Few or none | None |
| HIPAA Compliance | Yeah, with BAA. | Usually not. | Not applicable |
| Geographical Redundancy | Automatic | Manual or non-existent | No such thing |
| Uptime | 99.99% | Variable | Depends on the hardware |
| Automatic Encryption | AES-128 at rest and transit | Manual Configuration | Own responsibility |
| Physical security | Military class | Variable | A locked door |
| Automatic backups | Multiregion, encryption | Depends on the plan. | Own responsibility |
| Safe destruction of data | DoD Protocol | No guarantee | No guarantee |
Who else trusts AWS for sensitive data?
We are not the only ones who chose AWS to protect critical information:
- Epic Systems - the largest electronic medical records system in the U. S.
- Pfizer - for pharmaceutical research and clinical trials
- Modern - for vaccine development during the pandemic
- GE Healthcare - for medical imaging
- United States Government - including the Department of Defense and the CIA
If AWS is safe enough for the defense secrets of the world's greatest power, it's safe enough for your patients' session notes.
Majily LLC is part of the AWS Startups program
Brauni is developed by Majily LLC, and we are proud to be part of the official program AWS Startups. This is not just a label: it means that AWS evaluated our infrastructure, our business model and our technical architecture, and accepted us within its verified startup ecosystem.
What does being in AWS Startups mean?
- Access to AWS solution architects who review and optimize our infrastructure
- Credits and technical resources to scale with AWS best practices
- Technical validation that our architecture meets AWS standards for health applications
- Visibility in the official AWS showcase, where anyone can verify our participation
Note
You can see the Majily LLC profile directly in the AWS Startups showcase. It is public and verifiable.
Being part of this program reinforces our commitment: not only do we use AWS, but we work directly with them to ensure that the infrastructure where your patients live is the best possible.
Our responsibility for AWS
Using AWS does not mean we delegate security. AWS provides infrastructure; we build additional protections:
- field by field: before a data reaches AWS, we already encrypt it with our own keys
- BAA signed with AWS: legal contract that obliges AWS to comply with HIPAA on our data
- strict access control: Not even our technical team can read clinical data in plain text
- Continuous monitoring: Automatic alerts to any unusual activity
- No AI Training Policy: Your data never feeds artificial intelligence models
What does all this mean to you?
It means that when you save a session note in Brauni:
- Encrypted in your browser before leaving your device
- Travel through a channel encrypted with TLS 1.3
- Reaches AWS servers protected with military-class physical security
- It is stored with AES-128 encryption in multiple redundant locations
- Automatically backed up in encrypted and independent backups
- It is protected by legal contract (BAA) under the standards of HIPAA
All this happens in milliseconds, you don't have to do anything.
Your only responsibility is to care for your patients. Infrastructure security is ours.
Do you have questions about where your patients' data live? Write to soporte@brauni.io. We are here to give you the peace of mind you need to focus on what matters: your clinical practice.
Free Brauni test for 30 days, no card
Automatic session notes, digital medical records and more.
Start for freeBrauni uses Amazon Web Services (AWS) as the main provider of infrastructure, with BAA signed under HIPAA. We comply with the principles of Argentina's Personal Data Protection Act 25.326 and align ourselves with the most demanding international standards for the management of protected health information (PHI).
Related articles

Privacy and Security
What is a BAA HIPAA and why Brauni signed one with Google Cloud and AWS
We explain what is a Business Associate Agreement (BAA) under HIPAA and why Brauni signed this agreement with Google Cloud and AWS to protect your patients' clinical data.

Privacy and Security
Security and privacy in Brauni: how we protect your patients' data
Meet the 15+ safety layers that Brauni uses to protect your patients' clinical information: military encryption, multifactor authentication, and more.

Privacy and Security
What is Patient Privacy Monitoring and why any health app should have it
Encrypting clinical data is not enough. We explain what Patient Privacy Monitoring is (UEBA applied to health), why HIPAA demands it, and how Brauni detects suspicious access to medical records in real time.