# "Our auditor wants proof of S3 compliance, what do we give them?" Automating HIPAA S3 evidence for your auditor

> Source: <https://dev.to/bala_paranj_059d338e44e7e/our-auditor-wants-proof-of-s3-compliance-what-do-we-give-them-automating-hipaa-s3-evidence-for-34hk>
> Published: 2026-10-04 12:35:16+00:00

✓ Human-authored analysis; AI used for formatting and proofreading.

The thread on r/aws: "Our auditor wants proof of S3 HIPAA compliance. We have AWS Config and SecurityHub, but they want something more structured. What do we give them?"

The usual answers such as console screenshots, CSV exports, GRC platform PDFs are not what auditors need.

Auditors want **evidence**: deterministic, reproducible artifacts traceable to specific HIPAA requirements.

[Stave](https://github.com/sufield/stave) produces deterministic, machine-readable compliance evidence with HIPAA section citations in every finding:

```
stave evaluate \
  --controls controls/s3/ \
  --observations observations/ \
  --eval-time 2026-04-08T00:00:00Z \
  --format json
```

The JSON output follows the `out.v0.1` schema:

```
{
  "schema": "out.v0.1",
  "evaluated_at": "2026-04-08T00:00:00Z",
  "summary": {
    "total_controls": 12,
    "total_assets": 5,
    "compliant": 4,
    "non_compliant": 1
  },
  "security_state": "NON_COMPLIANT",
  "findings": [
    {
      "asset": "phi-reports-bucket",
      "control": "CTL.S3.PRESIGNED.001",
      "severity": "MEDIUM",
      "status": "UNSAFE",
      "compliance": {
        "hipaa": "164.312(a)(1)"
      },
      "message": "Presigned URL access unrestricted",
      "remediation": "Add s3:signatureAge or s3:authType condition"
    }
  ],
  "risk_signals": [
    {
      "asset": "phi-logs-bucket",
      "control": "CTL.S3.LOCK.003",
      "signal": "approaching-threshold",
      "detail": "Retention period 2200 days, minimum 2190 days"
    }
  ]
}
```

Every finding includes the HIPAA section citation. The auditor can trace each finding to the regulatory requirement it maps to.

The real power is running Stave in CI on every deployment. Exit codes make this straightforward:

```
# .github/workflows/hipaa-compliance.yml
name: HIPAA S3 Compliance Check
on:
  push:
    paths:
      - 'terraform/s3/**'
      - 'observations/**'

jobs:
  compliance:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Build Stave
        run: cd stave && make build

      - name: Evaluate S3 compliance
        run: |
          stave evaluate \
            --controls controls/s3/ \
            --observations observations/ \
            --eval-time "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \
            --format json \
            > compliance-report.json

      - name: Upload evidence artifact
        if: always()
        uses: actions/upload-artifact@v4
        with:
          name: hipaa-compliance-${{ github.sha }}
          path: compliance-report.json
          retention-days: 2190  # 6 years per HIPAA
```

Exit codes drive the pipeline:

| Exit Code | Meaning | Pipeline Action | 
|---|---|---|
| 0 | All controls pass | Deploy proceeds | 
| 3 | Violations found | Deploy blocked | 
| 2 | Input error | Pipeline fails, investigate | 
| 4 | Internal error | Pipeline fails, investigate | 

Every CI run produces a compliance artifact tied to a specific commit SHA. Over time, this creates a continuous compliance trail of evidence for every deployment.

Stop giving auditors screenshots. Give them JSON reports with HIPAA section citations, produced by a deterministic tool, run on every deployment, stored as build artifacts with 6-year retention. Stave makes compliance evidence a CI artifact that is reproducible, traceable, and machine-readable. When the auditor asks "prove this bucket was compliant on March 15th," you pull the artifact from that date's deployment and hand them the JSON.

For the HIPAA dashboard the auditor will recognize on sight — control-family layout, pass/fail per requirement, framework section labels matching their workpaper — [`turbot/steampipe-mod-aws-compliance`](https://hub.powerpipe.io/mods/turbot/aws_compliance) ships a dedicated HIPAA Security Rule benchmark with the framework's section IDs already mapped to controls. That's the auditor-facing dashboard half of the evidence story. The snapshot-anchored, commit-SHA-tied, 6-year-retention CI artifact this article describes is the *machine-readable proof* half — deterministic JSON the auditor can re-run, not a dashboard screenshot they have to take on faith. Both halves serve the same auditor; both halves should ship in the same compliance pipeline. Framework benchmark on the dashboard surface for recognizability, snapshot-anchored verdicts in the artifact store for reproducibility. The two-tool decision matrix: [aws-compliance-mod](https://github.com/sufield/stave/blob/main/docs/comparison/aws-compliance-mod.md).
