A healthcare organization needs to securely store patient consent forms that remain immutable for a period of five years. During this time, the documents must not be deleted or modified under any circumstances. Additionally, the organization wants to ensure the documents are encrypted at rest and that encryption keys are automatically rotated every 12 months. Which combination of actions should a solutions architect recommend to meet these requirements while minimizing administrative effort?