Is Protect Data's Remote Backup HIPAA Compliant?
First, it is important to understand that because remote backup
services do not involve the use or disclosure of Private Health
Information, and any access to PHI by a remote backup service
provider would be incidental, if even possible. Remote backup
service providers are not considered to be Business Associates,
and are therefore not covered by the HIPAA Privacy Rule. However,
some Covered Entities may wish to have a Business Associate Contract
in place regardless. Protect Data has several medical and insurance
organizations as clients and can provide a Business Associate
Contract if needed.
Remote backup services do clearly fall within the requirements
of the HIPAA Security Rule. Covered Entities must be compliant
with the Security Rule by April 21, 2005. Backup Services backup
software and services are compliant today, and can, more importantly
provide a foundation for overall compliance.
Protect Data's remote backup software complies with the Final
Security Rule.
Protect Data's software compresses and encrypts (using 448 bit
“Blowfish”encryption which is the most secure encryption
available) data before it is sent to the Protect Data's Server.
The Encryption Key is known only to the customer, and is never
transmitted to the server. Data is stored on the Protect Data's
server in compressed and encrypted archives that are not accessible
by the Protect Data's service provider.
Protect Data's remote backup software is adequate for helping
companies comply with the Final Security Rule. Protect Data also
complies with the Privacy section, even though Protect Data as
a provider is not a "Covered Entity" as defined by the
current rules, and thus is not required to comply with it.
In addition, Protect Data can help customers comply with other
provisions of the rules as part of a larger data protection and
disaster recovery plan. At the time of this writing there is no
"HIPAA Compliance" certification for backup software,
and it is important to note that under the current rules, no software
is truly "HIPAA compliant," because there are no regulations
that specifically address backup and privacy software.
Most small businesses don't have a backup
plan that fully protects them.
Don't become a statistic!
Let us help you protect your most valuable asset,
your computer data!