HIPAA provides national minimum standards to protect an individual’s health information.
Although many vendors advertise HIPAA compliance, there is no standard "HIPAA certificate of compliance" for backup / cloud products and services. However there are guidelines and we can lay out how our governance features work within this guidelines:
General Compliance guidelines for HIPAA:
- Ensure confidentiality, integrity and availability of all electronically protected health information that the covered entity either creates, receives, maintains or transmits.
- Protect against any reasonably anticipated threats or hazards to the security or integrity of such aforementioned information.
- Protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required.
- Ensure that there is compliance by the workforce.
Ways in which the Storage Made Easy Cloud Appliance satisfies HIPAA:Data Access:
This can be controlled using access control lists, to enable data to be only accessed by authorised personnel over https. Also IP GEO-restrictions can be implemented to restrict geographic access. The actual legislative wording regarding restricted access to data is:
"Allow access only to those persons or software programs that have been granted access right.
” (Section 164.312(a)(2)(1))Remote / Offsite Access to data::
Storage Made Easy provides a service which can be configured to be part of a disaster recovery plan enabling data to be accessed in the event of fire,flood, natural disaster, inadvertent deletions, viruses, hacking, theft or any other contingency. The actual legislative wording is:
"Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information.
” (HIPAA, Section 164.308(a)(7)(i)).Physical Security of Data:
Storage Made Easy supports over 35 clouds and in our opinion the most pertinent cloud to use for storing HIPAA data is Amazon. Our Cloud Appliance
can be hosted on Amazon EC2 and HIPAA data can be stored using the Amazon S3 data cloud. Further information on Amazon and HIPAA can be found in the PDF white paper
entitled " Creating HIPAA-Compliant Medical Data Applications with Amazon Web Services"Event Logging:
HIPAA solutions should enabled audit logging and drill down of file events to enable checks on file access and change and from which IP Address these were made. Such audit and event logging is built into the Storage Made Easy solution.Encryption:
The privacy rules regulations describe ensuring data is encrypted when "in flight" and when "at rest". Storage Made Easy and Amazon directly both support AES 256 bit encryption at a file level and data can be sent over secure channels.Disclaimer
This information is not intended to constitute legal advice. You are advised to seek the advice of counsel regarding compliance with HIPAA or refer to the HIPAA section of the U.S. Department of Health and Human Services' website, which can be found at: http://www.hhs.gov/ocr/hipaa/Back to Wiki Index