Ditch Microsoft & Google Today!

HIPAA Compliant Hosting: 5 Questions to Ask Before You Sign

HIPAA compliant hosting is hosting that is configured, contracted and documented so electronic protected health information stays protected under the HIPAA Security Rule. In practice that means three things together: technical safeguards on the server, a signed Business Associate Agreement with the host, and documentation you can actually produce if a regulator asks.

What it does not mean is a certificate. There is no government HIPAA certification for hosting providers, and any host implying otherwise is describing marketing rather than law. This guide covers what the rule actually requires, what is changing in 2027, and the questions worth asking before you sign anything.

What is HIPAA compliant hosting?

HIPAA compliant hosting is a hosting environment where the provider has implemented the safeguards required by the HIPAA Security Rule and has contractually accepted responsibility for protecting your patient data. Compliance is a property of the whole arrangement, not a feature of the server.

Three terms matter here:

  • PHI and ePHI — protected health information is any health information that can be tied to an individual. Add an “e” and it is that same information in electronic form: records in a database, an appointment reminder in an inbox, a scan sitting in a backup.
  • Covered entity — the healthcare provider, health plan or clearinghouse that holds the data and carries the legal obligation.
  • Business associate — any vendor that creates, receives, maintains or transmits ePHI on the covered entity’s behalf. A hosting provider storing your patient data is a business associate, and the Security Rule applies to them directly.

That last point surprises people. A host does not escape the rules by saying the data is encrypted and they cannot read it. If your ePHI lives on their hardware, they are in scope.

Is there such a thing as HIPAA certified hosting, or only HIPAA compliant hosting?

No. There is no official HIPAA certification, and the Department of Health and Human Services says so directly. In its own guidance, HHS states that it “does not endorse or otherwise recognize private organizations’ ‘certifications’ regarding the Security Rule.”

HHS goes further. Third-party certifications “do not absolve covered entities of their legal obligations under the Security Rule,” and obtaining one “does not preclude HHS from subsequently finding a security violation.”

So when a host advertises itself as “HIPAA certified,” the honest translation is that it paid a private firm for an audit. That audit may well be useful evidence. It is not a shield, and the legal responsibility stays with you.

What the rule does require is a periodic technical and non-technical evaluation establishing how far your security policies and procedures meet the requirements. You can run that internally or hire someone. Either way it is your evaluation, not a badge you buy.

What safeguards does the HIPAA Security Rule require?

HIPAA compliant hosting shared responsibility diagram showing infrastructure safeguards provided by the host versus administrative safeguards that remain with the medical practice
HIPAA Compliant Hosting: 5 Questions to Ask Before You Sign 1

The Security Rule requires administrative, physical and technical safeguards that protect the confidentiality, integrity and availability of ePHI. They are set out in 45 CFR Part 164, Subpart C, and they bind covered entities and business associates alike.

Diagram titled The Three HIPAA Security Rule Safeguards, showing the three categories of safeguards required under 45 CFR Part 164 Subpart C of the HIPAA Security Rule for covered entities and business associates. Administrative safeguards: risk analysis and risk management, workforce training and access policy, periodic security evaluation, and Business Associate Agreements. Physical safeguards: facility access controls, workstation use and security, device and media controls, and secure disposal of electronic protected health information. Technical safeguards: access control with unique user IDs, audit controls and logging, integrity controls, and transmission security including encryption. A highlighted note states that the proposed 2025 update would make encryption, multifactor authentication and network segmentation mandatory, remove the addressable category, and that the final rule is now expected in July 2027 after being postponed on 8 July 2026. Sourced from HHS.gov. Published by Liberation Technology Services, liberationtek.com.
The three categories of safeguards required by the HIPAA Security Rule. Source: HHS.gov.
Safeguard category What it covers What it looks like in hosting
Administrative Risk analysis, risk management, workforce training, access policy, periodic evaluation, Business Associate Agreements A signed BAA, documented access policy, a named person responsible, an evaluation you can show
Physical Facility access controls, workstation use and security, device and media controls, secure disposal Who can physically reach the hardware, how drives are wiped or destroyed when they are retired
Technical Access control and unique user IDs, audit controls and logging, integrity controls, transmission security Encryption in transit and at rest, no shared logins, audit logs you can actually retrieve

Two of those are easy to overlook when comparing hosts. Unique user IDs means shared admin logins are a problem, however convenient they are. Audit controls means the logs need to exist and be retrievable, not merely rotate away after a week.

Do you need a Business Associate Agreement?

Yes. If a hosting provider stores or transmits your ePHI, you need a signed Business Associate Agreement before that data reaches their servers. Without one you have a compliance gap regardless of how good the technology is.

A BAA is a contract that sets out what the vendor may do with your data, the safeguards they will maintain, what happens if there is a breach, and what happens to the data when the relationship ends. It converts a technical promise into a legal obligation.

The practical test when you are shopping is simple: ask whether they will sign one, and ask whether it costs extra. Some providers restrict BAAs to their highest tiers, which quietly turns a compliance requirement into an upsell.

What is changing in the HIPAA Security Rule?

A significant update to the Security Rule is coming, and the final rule is now expected in July 2027. HHS Office for Civil Rights issued a Notice of Proposed Rulemaking in December 2024, published in the Federal Register on 6 January 2025. The final rule was originally targeted for May 2026, then postponed on 8 July 2026 and pushed back a year.

The most consequential change is structural. The current rule splits requirements into “required” and “addressable,” where addressable items can be met with a documented alternative. The proposal removes the addressable category, making the controls mandatory.

Specific measures in the proposal include:

  • Encryption of ePHI and multifactor authentication as mandatory rather than addressable
  • Network segmentation to limit the blast radius of an attack
  • Anti-malware protection
  • Vulnerability scanning every six months and penetration testing annually
  • An annual Security Rule compliance audit
  • Risk analysis at least annually, built on a full technology asset inventory and network map
  • Dedicated backup and recovery controls for ePHI

The delay is not a reason to wait. Every item on that list is already defensible security practice, several are already required in some form, and a host that cannot do them in 2026 will not suddenly be able to in 2027.

HIPAA compliant hosting: what to ask a host before you sign

HIPAA compliant hosting checklist of five questions to ask a provider: will you sign a business associate agreement, where are servers and backups located, who can access the machine, is data encrypted in transit and at rest, and what are the breach notification timelines
HIPAA Compliant Hosting: 5 Questions to Ask Before You Sign 2

Eight questions separate a genuine healthcare host from one that has simply added the word HIPAA to a pricing page:

  1. Will you sign a BAA, and does it cost extra? If the answer is a higher tier, that is a pricing decision dressed as a compliance one.
  2. Where is the hardware, and who operates it? Resold infrastructure means more parties touching your data.
  3. Is ePHI encrypted in transit and at rest? Both, not one.
  4. Who on your staff can access my server, and is that access logged? Named accounts, retrievable logs.
  5. Are backups encrypted, and are they stored away from the primary system? A backup on the same box is not a backup.
  6. Is multifactor authentication enforced on all administrative access? Available is not the same as enforced.
  7. How quickly can you restore, and when did you last test it? Untested restores fail when it matters.
  8. What happens to my data when I leave? Export format, deletion timeline, written confirmation.

How LiberationTek approaches HIPAA compliant hosting

We built our healthcare hosting around the answers above rather than around a badge. We sign a Business Associate Agreement, and we do not gate it behind a premium plan.

The environment includes a HIPAA compliant firewall, encrypted Zero Trust and VPN access, encrypted off-site backups, SSL certificates, multifactor authentication, and ongoing monitoring and patching. The hardware is U.S.-owned and we operate it ourselves, so there is no chain of resellers between you and your patient records. Alongside hosting we build the pieces that touch ePHI day to day: patient portals, intake forms, secure messaging, appointment scheduling and billing pages with tokenised payment processing.

One thing we will say plainly, because it matters more than any marketing claim: compliance is a floor, not a guarantee. It means specific safeguards are in place. It does not mean a breach can never happen, and any vendor promising otherwise is overselling.

If you want to talk it through, book a consultation and we will walk your setup honestly, including the parts we are not the right fit for.

What HIPAA compliant hosting costs, and where practices overspend

Pricing is where this subject gets murky, because “HIPAA” in a product name is often worth a premium that the underlying infrastructure does not justify. It is worth separating the parts you genuinely have to pay for from the parts that are ordinary hosting with a compliance label attached.

What legitimately costs more. Dedicated or private resources rather than a crowded shared server. Encrypted backups retained for a defined period and stored separately. Access logging that is actually retained and reviewable. A provider willing to sign a business associate agreement and to stand behind it, which carries real legal exposure for them. These are reasonable reasons for HIPAA compliant hosting to cost more than a five-dollar shared plan.

What usually does not. The words themselves. There is no certification body, no audit that confers a badge, and no technical component called “HIPAA” that gets installed on a server. If a quote is three times the market rate for equivalent resources and the only difference is the label, ask what specifically is included that the standard plan lacks. A provider doing this properly can answer in detail; one selling a label will talk in generalities.

Where practices overspend. The commonest pattern is paying for enterprise-grade HIPAA compliant hosting while patient data continues to move through ordinary email attachments, staff laptops with no disk encryption, and a scanner writing to an unsecured network folder. The hosting is rarely the weakest link. Spend proportionally: a secure portal, multi-factor authentication and encrypted devices usually do more for a small practice’s actual risk than upgrading the server tier.

Where practices underspend. Backups they have never restored, and a business associate agreement they never asked for. Both are cheap to fix and both are among the first things examined after an incident. The U.S. Department of Health and Human Services publishes its Security Rule guidance material free of charge, and it is written for practices rather than for lawyers – an hour with it will tell you more than most vendor comparison pages.

The honest summary: HIPAA compliant hosting is necessary and not sufficient. Buy infrastructure from someone who will sign the agreement and tell you where the data lives, then spend the rest of the budget on the parts of the risk that sit inside your own office.

Frequently asked questions

Is there an official HIPAA certification for hosting providers?

No. HHS does not endorse or recognize private HIPAA certifications, and holding one does not prevent HHS from finding a violation. What the rule requires is a periodic evaluation of your own security policies and procedures.

Does my hosting provider need to sign a BAA?

Yes, if they store or transmit ePHI on your behalf. A hosting provider handling patient data is a business associate under HIPAA, even if the data is encrypted and they cannot read it.

Is encryption required under HIPAA?

Under the current Security Rule, encryption is an addressable implementation specification, meaning you must implement it or document an equivalent alternative. The proposed update removes the addressable category and makes encryption mandatory.

When does the new HIPAA Security Rule take effect?

The final rule is now expected in July 2027. It was proposed in December 2024, published in the Federal Register on 6 January 2025, and postponed on 8 July 2026 from its original May 2026 target.

Can I use ordinary shared hosting for patient data?

Generally no. Shared hosting rarely offers a BAA, dedicated resources, enforced MFA on administrative access, or retrievable audit logs. Healthcare workloads usually need a dedicated or managed environment.

This article is general information about hosting requirements, not legal advice. HIPAA obligations depend on your organization and how you handle ePHI; consult a qualified professional for your specific situation.

Related reading