Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before placing electronic protected health information (ePHI) with a cloud host, confirm that the exact service and support activities are covered by a business associate agreement (BAA), document who is responsible for each safeguard, and assess the arrangement in your own risk analysis. Then compare the providers’ written terms for security incidents, backups and recovery, availability, subcontractors, and data return or destruction. A provider’s “HIPAA compliant” claim is not a certification: the U.S. Department of Health and Human Services Office for Civil Rights (OCR) says it “does not endorse, certify, or recommend specific technology or products.”

Does HIPAA certify cloud hosting providers?

No. OCR does not certify or endorse particular hosting products. A marketing label therefore cannot establish that a service, its configuration, your contract, and your organization’s practices meet your obligations. HHS’s Guidance on HIPAA & Cloud Computing, last reviewed December 23, 2022, explains that compliance depends on the responsibilities and safeguards of both the cloud provider and the customer.

Use the checklist below to evaluate a specific workload and its contract, not to treat a vendor label, security feature, or report as a stand-alone compliance determination.

What to verify before signing

1. Confirm the provider’s role and the BAA’s scope

A cloud provider that creates, receives, maintains, or transmits ePHI on behalf of a regulated organization generally acts as a business associate. A BAA is required for that relationship. This can apply even if the data is encrypted and the provider does not have the key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
WatchGuard Trade up to WatchGuard Firebox M290 with 3-yr Basic Security Suite
  • Enterprise-grade prevention, detection, correlation and response from the perimeter to the endpoint with our Total Security Suite.
  • Gain critical insights about network security, from anywhere and at any time, with WatchGuard Cloud.
  • Built-in compliance reports, including PCI and HIPAA, mean one-click access to the data you need to ensure compliance requirements are met.
  • Up to 18 Gbps firewall throughput. Turn on all additional security services and still see up to 2.4 Gbps throughput.
  • List the exact hosting services, environments, and support functions that may touch ePHI, including storage, administration, troubleshooting, and backups.
  • Get written confirmation that the BAA covers those services and functions before putting ePHI in them.
  • Review permitted and required uses and disclosures, safeguards, incident and breach reporting, and what happens to ePHI when the agreement ends.
  • Ask which subcontractors may handle ePHI. Confirm that the provider’s contracting chain requires downstream business associates to have appropriate BAAs before receiving PHI for their work.

HHS’s OCR Business Associates guidance explains the BAA and subcontractor obligations. Do not infer that encryption or lack of access to the decryption key removes the provider’s business-associate obligations.

2. Put the security responsibility split in writing

Ask for a responsibility matrix for the specific service and deployment you plan to use. It should identify what the provider operates and what your organization must configure, monitor, or document. Avoid broad statements such as “security is shared” unless the contract or related documentation makes each party’s tasks clear.

  • Assign responsibility for identity and access settings, encryption and key management, logging, administrative access, patching, and incident response.
  • Identify provider controls for its infrastructure and administrative tools as well as customer-controlled settings. Customer authentication controls do not replace the provider’s need for appropriate internal controls over administrative tools.
  • Connect the allocation to your risk-management plan and keep a record of the controls your team must maintain.

A BAA does not perform your risk analysis or configure your safeguards. HHS’s Guidance on Risk Analysis describes risk analysis as foundational and specific to the organization and its environment; assess the actual service arrangement rather than relying on a generic provider description.

3. Assess confidentiality, integrity, and availability

Evaluate how the arrangement protects ePHI against unauthorized access or disclosure, improper alteration, and loss of access. Encryption can help protect confidentiality, but encryption alone does not establish integrity or availability, demonstrate recovery readiness, or replace appropriate administrative and physical safeguards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Ask where encryption is applied and who controls the keys. Record the answer as one part of the broader safeguard assessment.
  • Identify threats and vulnerabilities introduced by the selected architecture, deployment model, and data locations, including any overseas storage. HHS says overseas storage is permitted when the parties use a BAA and comply with HIPAA; location can still affect risks and enforcement considerations.
  • Check who owns and operates backups, how restoration works, and whether your organization can access backups and recover usable data and systems after an incident.
  • Include contingency planning for emergencies such as ransomware. Determine how your recovery approach will be tested and who will carry it out.

HHS’s Guidance on HIPAA & Cloud Computing states that encryption does not by itself maintain integrity or availability or replace contingency planning.

4. Read the BAA, service-level agreement, and exit terms together

Compare the written commitments across the BAA, service-level agreement (SLA), and any related service documents. They should be consistent with one another and should not impede your access to ePHI or your ability to meet applicable obligations.

Rank #4
BUSlink CipherShield DSE-2TSDG1K1M1 2TB SSD Mode 1 Encrypted Slim Drive – Single Key Special, 256-bit AES Hardware Encryption, FIPS 140-2, USB 3.0, Bus-Powered, HIPAA, HITECH, FERPA, TAA-Compliant
  • PHYSICAL KEY AUTHENTICATION – NO PASSWORDS: Access is controlled by a unique hardware CipherKey—no key, no access. Removing the key or cutting power instantly locks and encrypts all data, preventing unauthorized use if the drive is lost or stolen. Bundled with 1 key.
  • AES 256-BIT HARDWARE ENCRYPTION (FIPS 140-2 LEVEL 2): Real-time, NIST-certified Full Disk Encryption is handled entirely at the hardware level—immune to malware, OS attacks, and SATA bypass attempts.
  • SMART INSERT KEY OPERATION OPTION: Mode 0 requires the key to remain inserted for continuous access; Mode 1 Hot-Plug (select models) allows key removal after authentication for uninterrupted backups and large transfers.
  • HIGH-SPEED, PLUG-AND-PLAY PERFORMANCE: USB 3.2 Gen 1 (USB 3.0) delivers speeds up to 5 Gbps. Bus-powered design requires no external power, drivers, or software. Available in SSD or HDD configurations.
  • COMPLIANCE-READY & CROSS-PLATFORM: Meets HIPAA, HITECH, FERPA, and SOX requirements. Compatible with Windows, macOS, and Linux, plus Windows Server editions.
  • Availability and reliability: Check the provider’s stated commitments and how service interruptions are handled.
  • Backups and recovery: Establish the provider’s commitments and how they fit your own recovery plan, including in an emergency.
  • Incident communication: Identify how security incidents and breaches are reported, to whom, and under what contractual timelines. Confirm contacts and responsibilities.
  • Access during transition: Determine how and when ePHI will be made available to you, including while you move to another service.
  • Return, destruction, and retained copies: Specify how ePHI is returned or destroyed at termination, how any retained copies are handled, and what applies if return or destruction is infeasible.
  • Use and disclosure limits: Check restrictions on the provider’s use, retention, and disclosure of ePHI.

HHS advises that SLA provisions be consistent with the BAA and HIPAA Rules, including not preventing access to ePHI. The BAA should explain how the provider makes ePHI available for relevant customer obligations.

5. Ask for evidence suited to your risks

The HIPAA Rules do not expressly require a cloud provider to supply security documentation or permit customer audits. You can negotiate for documentation, audit information, or other assurances in the BAA, SLA, or related documents based on your risk analysis and compliance activities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
ClevX SecureData SecureUSB KP 128GB Hardware Encrypted USB 3.0 Flash Drive FIPS 140-2 Level 3 Unlock via Keypad TAA Compliant, CJIS, HIPAA, CMMC, GDPR Compliant, Works with Mac and Win Free AV
  • The Encrypted Drive includes both USB-C and USB-A Adapters to make your out-of-box experience great. Ready for any USB-C or USB-A ports on your computer, laptop, phone, or other systems with USB support. Full USB 3.2 Speeds up to 5MBs. TAA Compliant, CJIS, HIPAA, CMMC, GDPR Compliant.
  • The Secure Stick (Encrypted USB) does not require any software or drivers to validate or unlock the drive. The built-in battery allows unlocking the drive before insertion making it easy to insert into hard-to-reach USB ports.
  • USB 3.2/3.1./3.0/2.0 is compatible with all systems and Operating systems. The USB Flash Drive comes formatted FAT32, but you can easily reformat it for Win, Mac, or Linux.
  • Protect your files on the wireless flash drive with the Antivirus SW included on the drive. AV runs from the drive and scans all files written to it. This is a subscription service and the first year is included. Go online to activate the license.
  • Military Grade, XTS-AES 256-bit Hardware Encryption and made with aircraft grade crush-proof aluminum sleeve keeps the data and the drive safe. Rated IP68 to protect the drive from water or dust when the sleeve is on.
  • Ask what evidence the provider will make available for the specific service and controls in scope.
  • Decide what documentation or audit rights your organization needs to support its own assessment and oversight.
  • Confirm that evidence applies to the relevant services and responsibilities, rather than assuming a general report covers every part of your arrangement.

Do not treat a particular report, audit right, or certification as a universal HIPAA requirement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to compare hosting options fairly

Evaluate each candidate against the same workload and the same questions. Record contractual answers, not just sales assurances.

Comparison area What to compare
BAA scope Whether the exact services and support functions that touch ePHI are covered, including permitted uses and disclosures and downstream contractors.
Responsibility split Which party configures and operates identity and access controls, encryption, logging, administrative access, patching, and incident response; obtain the allocation in writing.
Risk fit Whether the service architecture, deployment model, and data locations address risks identified in your organization’s analysis.
Resilience Availability commitments, backup ownership, recovery processes, and your ability to access restored ePHI.
Incident handling Security incident and breach reporting terms, contacts, responsibilities, and timelines.
Evidence and assurance Documentation, audit information, or other assurances available under contract and proportionate to your risk analysis.
Exit and portability How ePHI is returned or destroyed, how retained copies are handled, and whether access continues during transition.
Overall fit Whether the service scope, operational commitments, and contractual obligations suit the workload; do not substitute a generic “HIPAA-certified” label for these checks.

How to interpret proposed Security Rule changes

HHS OCR issued a Security Rule Notice of Proposed Rulemaking on December 27, 2024. The accompanying factsheet describes proposals that include more specific risk-analysis and asset-inventory expectations, recurring audits and verification, encryption, multifactor authentication, scanning and penetration testing, network segmentation, and backup and recovery provisions. The factsheet presents these as proposed changes; do not treat each item as an effective requirement based on the proposal alone. Check the current rule and its effective date when making a decision.

What this checklist can and cannot establish

This is a federal HIPAA-focused buying checklist, not a determination that a particular organization, service configuration, or contract is compliant. State law, other contractual requirements, and your organization’s circumstances may add obligations. Provider offerings and applicable rulemaking can change, so verify the current BAA scope and service terms for the specific option you are considering.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.