選取您的 Cookie 偏好設定

我們使用提供自身網站和服務所需的基本 Cookie 和類似工具。我們使用效能 Cookie 收集匿名統計資料,以便了解客戶如何使用我們的網站並進行改進。基本 Cookie 無法停用,但可以按一下「自訂」或「拒絕」以拒絕效能 Cookie。

如果您同意,AWS 與經核准的第三方也會使用 Cookie 提供實用的網站功能、記住您的偏好設定,並顯示相關內容,包括相關廣告。若要接受或拒絕所有非必要 Cookie,請按一下「接受」或「拒絕」。若要進行更詳細的選擇,請按一下「自訂」。

Data retention - Healthcare Industry Lens
此頁面尚未翻譯為您的語言。 請求翻譯

Data retention

HCL_COST1. How do you define and enforce data retention policies?

Determine applicable regulatory frameworks and controls as it pertains to data retention

Healthcare organizations may be subject to regulatory and company requirements dictating how long they must store both health data as well as logs detailing access to that data. Over time, storage requirements can reach petabyte scale for an individual organization. New imaging modalities, such as digital pathology, have the potential to push data volumes even higher. Developing strategies for data retention is imperative to maintain compliance while minimizing cost.

Healthcare organizations should establish a data retention policy identifying the types and duration that data should be retained in accordance with internal and external requirements.

Implement data lifecycle policies

As healthcare data ages, its access frequency declines. Implement lifecycle policies that transition infrequently-accessed data to lower-cost storage tiers. When designing your policies for each type of data, be sure to factor the size of the data, the frequency of access, and expectations for retrieval time; these are the three predominant cost-drivers. For example, use Amazon S3 Lifecycle configurations to archive infrequently accessed data after some period of time, automatically reducing storage costs. Alternatively, use Amazon S3 Intelligent-Tiering to shift the archival policies to focus on time of last access instead of time the object has been in Amazon S3.

Centralize automated policy enforcement

Adopting infrastructure as code, as discussed in the operational excellence pillar, enables you to define and test your data retention policies before they make it into production. For example, if regulatory requirements specify that you must retain certain medical images for 10 years, you can verify that no Amazon S3 lifecycle policy expires an object before that time. Additionally, consider AWS Backup for centralized backup management, which enables you to back up application data in a consistent and compliant manner.

Validate lifecycle policies are enforced

Because the cloud is API-driven, you can monitor changes to your environment as described in the operational excellence and security tiers. Set up alerts for when an API action alters a data retention policy so you can quickly review the change to make sure it was authorized and operating correctly. If using AWS Backup, use AWS Backup Audit Manager to automatically detect when your AWS Backup policies violate your data retention requirements.

隱私權網站條款Cookie 偏好設定
© 2025, Amazon Web Services, Inc.或其附屬公司。保留所有權利。