• Platform
    • Product
      • Platform Overview
      • Directories
      • Why Low Code
      • Case Studies
      • App Marketplace
      • AI Capability
    • Industries
      • Healthcare
      • Education
      • Government
      • Financial Services
      • Energy and Utilities
      • Nonprofits
      • Media
      • Consulting
    • Get Started
      • Free Trial
      • Get a Custom Demo
      • Contact Sales
  • Ways to Build
    • testing
  • Resources
    • Resources
      • Resource Center
      • App Marketplace
      • Blog
      • Events
    • Plan for Success
      • Free Training
      • Onboarding
      • Professional Services
      • Partner Directory
  • Pricing
  • search
  • Contact Sales
  • Support
    • Online Help
    • Community Forum
    • Contact Support
  • Log in
Get a Demo Try Free
High Contrast
Caspio logo Try Free
  • Platform

    The Caspio Low-Code Platform

    • platform-overview-icon
      Product
      • Platform Overview
      • Directories
      • Why Low Code
      • Case Studies
      • App Marketplace
      • AI Capability
    • industries-icon
      Industries
      • Healthcare
      • Education
      • Government
      • Financial Services
      • Energy and Utilities
      • Nonprofits
      • Media
      • Consulting
    • get-started-icon
      Get Started
      • Free Trial
      • Get a Custom Demo
      • Contact Sales
  • Ways to Build
    • testing
  • Resources

    All the Tools and Support You Need

    • resources-icon
      Resources
      • Resource Center
      • App Marketplace
      • Blog
      • Events
    • plan-for-success-icon
      Plan for Success
      • Free Training
      • Onboarding
      • Professional Services
      • Partner Directory
  • Pricing
  • High Contrast
  • search
  • Contact Sales
  • Support
    • Online Help
    • Community Forum
    • Contact Support
  • Log in
Get a Demo Try Free

How to Choose HIPAA-Compliant Cloud Services for Healthcare

December 13, 2016

  • Tech Tips
  • Customer Spotlight
  • News Articles
Try Free
  • Home
  • Blog
  • Current Article
10549
December 13, 2016
How to Choose HIPAA-Compliant Cloud Services for Healthcare

Last quarter, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a guidance on HIPAA and cloud computing. The guidance confirms that cloud service providers (CSPs) that create, receive, maintain, or transmit protected health information (PHI) are business associates under HIPAA and therefore their services must comply with HIPAA requirements.

The guidance also points out that covered entities and their CSPs need to have a properly executed business associate contract or agreement (BAA) in place to avoid possible cloud computing legal issues in the future. Case in point: In July 2016, a health and science university in Oregon entered into a settlement with the OCR amounting to $2.7 million in total violations. One of these violations includes the storage of the PHI of more than 3,000 individuals on a cloud-based server without a business associate agreement.

Below is a summary of other key concerns for choosing HIPAA-compliant cloud services for healthcare:

Can HIPAA data be stored outside the USA?
A HIPAA-covered entity or business associate can use a CSP that stores PHI on servers outside of the United States. The guidance reiterates that covered entities must still enter into a BAA with the CSP and should comply with the applicable requirements of the HIPAA rules. Moreover, the OCR notes that in these cases, covered entities need to be aware that data security and privacy risks may vary greatly depending on the geographic location of the PHI, and should employ the necessary preventive measures in their respective security analyses when choosing CSPs. For example, in countries where ransomware attacks are common, covered entities should focus on what technical safeguards to put in place so that if a malware gets into the system, the damage can be contained. Read the Ransomware and HIPAA Fact Sheet for more information.

How important is reporting of security incidents?
If a CSP experiences a security incident, it must report the incident to the covered entity or business associate. As many know, HIPAA requires business associates to identify and respond to attempted or successful security incidents. Reporting a security incident is bad enough given the costs and administrative tasks involved, but even more worrisome are the consequences for failing to do otherwise. If discovered, such failure would likely constitute willful neglect, mandatory penalties, and civil lawsuits, thereby subjecting the covered entity or CSP to penalties that could go up to $250,000 fine and ten years in prison.

Can HIPAA data be accessed via mobile phones?
Healthcare providers or business associates are allowed to use mobile devices to access PHI stored in the cloud. This is deemed acceptable as long as appropriate physical, administrative, and technical safeguards are in place. Among other guidelines to protect the confidentiality, integrity, and availability of PHI, the OCR issued guidance on the use of mobile devices and tips for securing PHI on mobile devices for further reference.

Is a BAA required if a CSP does not have decryption key to encrypted data?
A CSP that stores only encrypted PHI and does not have a decryption key is still considered a HIPAA business associate. Therefore, under the HIPAA rules, a CSP is not exempt from business associate status, even if it lacks a decryption key, since the CSP still receives and maintains PHI for a covered entity or another business associate. The guidance also notes that even though encryption may provide “safe harbor” from breach notification obligations, CSPs must not rely solely on encryption to fulfill their responsibilities. For instance, encryption alone does not address how the CSP will maintain the integrity of the PHI from malware attacks, neither does it ensure the availability of PHI in case of a catastrophe. In this case, the OCR suggests CSPs to have administrative safeguards to analyze risks to the PHI, as well as physical safeguards for systems and servers that may house the PHI.

With a BAA in place, is a SLA still required?
Yes, and the terms of the SLA should be consistent with the BAA and the HIPAA Rules. Taking the guidance into account, the OCR points out that a Service Level Agreement can be used to address more specific business expectations between covered entities and CSPs as they relate to HIPAA concerns, such as:

1. System availability and reliability
2. Back-up and data recovery
3. How the PHI will be returned or destroyed after ending the service
4. Responsibility for specific security controls (e.g. user authentication and authorization to PHI)
5. Limitations on use, disclosure, and retention of the PHI

Ensuring HIPAA best practices
Healthcare providers and professionals are well-aware that protecting patients’ health information is an essential component in building patient trust. Therefore, covered entities and business associates who are looking to use cloud computing solutions should conduct their own thorough analysis to ensure that their CSPs are capable of protecting PHI in a manner that conforms with HIPAA rules and regulations.

Caspio’s HIPAA-Compliant Edition provides all the required HIPAA safeguards to help you build healthcare-related cloud applications while protecting the confidentiality, integrity, and availability of PHI. All PHI are encrypted both at rest and in transit, access to data is logged and archived according to HIPAA requirements, and Caspio maintains BAAs with its vendors and offers BAAs to its customers.

How Caspio is used by the healthcare industry
As an open platform for creating custom business applications, Caspio is used to create variety of data management applications. For healthcare, some examples include:

  • Patient registration and check-in
  • Health insurance exchanges
  • Online patient portals
  • Medical billing
  • Medical device tracking
  • Clinical research
  • Resource and knowledge management

To learn more, request a free consultation with a Caspio product expert.

Call to Action Block Call to Action Block

Share this post:

Previous Post:
Caspio 9.5 Release: New and Improved Charts
Next Post:
Mobile App Vs. Web App: Which Should You Build for Your Business?

Recommended Articles

Low Code for Consultants: Adapt to the Changing Digital Landscape

How Consulting Firms Can Accelerate Digital Transformation With Low Code

READ STORY
How to Create Personalized Customer Experiences With No-Code

Create Personalized Customer Experiences With No-Code

READ STORY
How No-Code Bridges the Digital Talent Gap in Academic Institutions

No-Code App Ideas for the Education Sector

READ STORY
How to Embed YouTube, TikTok and Instagram Videos in Your Caspio Apps

Embed YouTube, Instagram and TikTok Videos in Your Web Apps

READ STORY
Top 10 Most Requested Caspio Apps of 2022

Top 10 Most Requested Apps of 2022

READ STORY
Improve Security Across Your Apps With Caspio Directories

Improve Security Across Your Apps With Caspio Directories

READ STORY
Automate Workflows: How to Use Triggered Actions and Tasks in Your Caspio Applications

How to Use Triggered Actions and Tasks in Your Custom Apps

READ STORY
How to Leverage Low Code in Your Healthcare Business

Ways to Leverage Low Code in Your Healthcare Business

READ STORY
7 Surefire Ways to Uplevel Your Web Forms

7 Surefire Ways to Upgrade Your Custom Web Forms

READ STORY
HR Solutions Firm Builds Entirely New Business on Caspio

HR Solutions Firm in Spain Builds Entire Business Model on Caspio | Caspio

READ STORY
Build and Extend Your Online Calendars With Caspio

Build and Extend Your Online Calendars With Caspio

READ STORY
Supercharge Webflow With Caspio Database Applications

Supercharge Webflow With Caspio Database Applications

READ STORY
Subscribe for More Updates
  • PRODUCT

  • Platform Overview
  • Why Low Code
  • Case Studies
  • App Marketplace
  • Pricing
  • Get a Custom Demo
  • Free Trial
  • SOLUTIONS

  • Healthcare
  • Education
  • Government
  • Financial Services
  • Energy and Utilities
  • Nonprofits
  • Media
  • Consulting
  • RESOURCES

  • Resource Center
  • Caspio Blog
  • Free Training
  • Online Help
  • Onboarding
  • Get Certified
  • Professional Services
  • Support Center
  • COMPANY

  • Our Story
  • Careers
  • Leadership
  • News
  • Partner Programs
  • Referral Program
  • Academic Program
  • Discount Programs
  • Contact Us
  • TRENDING

  • HIPAA Compliance
  • Build Custom CRM
  • Create Web Dashboards
  • Best Online Database
  • Convert Excel to Web
  • Migrate MS Access Online
  • HIPAA Compliant Database
  • Create a Patient Portal
Caspio Logo

Caspio is the world’s leading cloud platform for building online database applications without coding.
Start a free trial today and experience the power of no-code.

Footer Partners

© 2025 Caspio, Inc. Sunnyvale, California. All rights reserved.

  • Privacy Statement
  • Terms of Use
  • Report Abuse
  • Sitemap
  • Feedback