Understand how data centers can help your health company meet its HIPAA compliance requirements

What HIPAA Compliant Means for Data Centers?

HIPAA is an acronym for Health Insurance Portability and Accountability Act of 1996. It is a U.S. law that protects medical information moving electronically. A HIPAA compliant data center is a facility approved to store, transmit and process those records for a covered healthcare entity. The law began as a way to help patients keep insurance if they lose their job or change jobs. HIPAA also reduces medical costs, because administrators can use electronic records instead of paper. The U.S. Department of Health and Human Services regulates the law, so enforcement sits with the federal government.

The Health Information Technology for Economic and Clinical Health Act (HITECH ACT) is another relevant patient protection act. HITECH is part of the American Recovery and Reinvestment Act of 2009, which Congress passed in response to the 2008 recession. The HITECH Act expanded the scope of HIPAA privacy and security protections and expanded the legal liability for non-compliance.

Covered entities, and the businesses working with them, must notify patients of any data breach. Covered organizations include healthcare providers, health plans and healthcare clearinghouses, so the net is wide. Entities that work with covered organizations may also need to comply with the HIPAA privacy requirements. The privacy requirements cover:

  •       The patient’s identity, including Social Security number
  •       The patient’s diagnosis and condition
  •       The record of any care provided to the patient
  •       Any payment information that could be used to identify the patient

Penalties for breaching ePHI records

Entities who fail to disclose breaches and who fail to secure the privacy of the records can be subject to substantial fines and penalties. Penalties include:

  •       Unknowing violations are $100 for each violation up to $25,000 each year for subsequent violations
  •       Willful neglect of HIPAA that is corrected within a reasonable time frame can be $10,000 for each violation up to a quarter-million dollars yearly
  •       Willful neglect that is not corrected is $50,000 per violation up to $1.5 million

Additionally, individuals and entities who intentionally disclose (or obtain) protected information can be sentenced to prison in addition to having to pay substantial fines.

What a HIPAA Compliant Data Center Must Provide

Many healthcare companies now store patient records in offsite data centers, which is where compliance gets complicated. Data centers can store, send, and process large amounts of electronically protected health information (ePHI). But storing ePHI comes with a price, since the obligations transfer to the facility. Data centers that contract with qualified HIPAA medical entities must comply with HITECH and HIPAA compliance requirements or run the risk of substantial penalties and even imprisonment.

Deciding where ePHI records live, at the healthcare center or the data center, is a delicate balance. The healthcare provider can monitor the information and train staff directly. A professional data center, meanwhile, usually has stronger security and better redundancy.

So HIPAA compliance means satisfying the following two rules.

  •       The HIPAA Privacy Rule is a national set of security standards for protecting health information.
  •       The HIPAA Security Rule covers the technical and the non-technical standards the covered organizations must have in place.

Covered entities must protect the integrity, confidentiality and availability of ePHI records. That duty covers any threat, improper disclosure or security violation they can reasonably anticipate.

HIPAA Privacy and Security Safeguards

Some of the compliance protocols data centers who are business associates of medical companies must meet are:

  •       Administrative safeguards. These requirements include identifying security risks, implementing security measures and designating a responsible security official. They also cover access procedures, workforce training, and periodic evaluation of how well the policies work.
  •       Physical safeguards. These safety needs include limiting access to data to authorized personnel and creating policies for the transfer, removal, and re-use of digital media.
  •       Technical Safeguards. These protocols include procedures that limit access to the ePHI records, audit controls to record and examine software and hardware, integrity controls, and security transmission controls.

HIPAA Certification

The HHS Department inspects data centers directly. Its review decides whether the facility qualifies as a business associate, and whether it meets the two HIPAA rules on privacy and security. HIPAA will prepare a report on compliance sometimes called an HROC (HIPAA Report on Compliance). Since there is no formal certification, the outcome is binary. The data center is basically HIPAA compliant or it is non-compliant.

Related reading

Understand how data centers can help your health company meet its HIPAA compliance requirements

Experienced data centers understand how to implement these requirements, because they do it every day. These centers track changes to the law and advise clients on the in-house protocols they should adopt. Because they also implement the technical changes, the risk of a medical data breach drops.

Discover how Volico can help you with your Compliance & Security needs.

Share this blog

About cookies on Volico.com

Volico Data Centers use cookies to collect and analyse information on site performance and usage. This site uses essential cookies which are required for functionality.  More detail is available in our privacy policy. Learn more