Back to HIPAA

HIPAA Compliant Data Center: How to Choose a Colocation or Hosting Provider for ePHI

HIPAA compliant data center illustration: rows of server racks behind a locked cage door with a health record icon

Short answer: There is no official HIPAA certification for data centers. A "HIPAA compliant data center" is a facility that signs a business associate agreement with you, runs the physical safeguards in 45 CFR 164.310 and can prove it with independent evidence such as a SOC 2 Type 2 report. Administrative and technical safeguards for your systems remain your responsibility.

Related guides:

Key takeaways

  • HHS does not certify data centers, hosting providers or products. Any "HIPAA certified" badge is a marketing claim, not a regulatory status.
  • A facility that stores or houses ePHI on your behalf is generally treated as a business associate, even if it cannot read encrypted data. The conduit exception covers transmission only.
  • You need a signed BAA that meets 45 CFR 164.504(e) and 164.314(a) before ePHI goes into the facility.
  • The facility covers most physical safeguards. Risk analysis, access control, encryption, audit logging and your contingency plan stay with you.
  • Ask for a SOC 2 Type 2 report, an ISO 27001 certificate or a HITRUST assessment, then check that the scope actually includes the site you are buying.

Is there such a thing as a HIPAA certified data center?

No. HHS has no certification program for facilities, and its cloud guidance states that "OCR does not endorse, certify, or recommend specific technology or products". When a colocation or hosting provider calls itself HIPAA compliant, it usually means three things:

  1. It will sign a business associate agreement (BAA).
  2. It has implemented the HIPAA safeguards that apply to the services it provides, mainly physical ones.
  3. It has independent evidence of those controls, such as an audit report or certification.

None of that makes your use of the facility compliant. HIPAA compliance belongs to the organization, not the building. Treat the facility as one vendor in your HIPAA program and evaluate it like one.

Is your data center a business associate?

Usually yes, if it stores or houses ePHI for you. HHS guidance on cloud services says that "an entity that maintains ePHI on behalf of a covered entity (or another business associate) is a business associate, even if the entity cannot actually view the ePHI".

The conduit exception is narrow. HHS describes it as limited to transmission-only services, where any access to PHI is transient. A provider that stores ePHI has more persistent access and does not qualify.

HHS guidance is written for cloud service providers, and it does not address colocation by name. Some colocation operators argue that renting space, power and cooling for your own locked racks is not "maintaining" ePHI. Get legal advice if a provider refuses a BAA, and document the decision either way.

If you are a business associate yourself (for example, a HealthTech SaaS company), the facility is your subcontractor, and the same BAA rules apply between you and it under 45 CFR 164.314(a)(2)(iii).

What must a data center BAA include?

The BAA must meet both the Privacy Rule contract requirements and the Security Rule organizational requirements. Under 45 CFR 164.314(a)(2)(i), the provider must agree to comply with the applicable Security Rule requirements, flow the same terms down to its own subcontractors, and report security incidents, including breaches of unsecured PHI. 45 CFR 164.504(e)(2) adds the core contract terms.

Check that the facility's BAA covers:

  • Permitted uses and disclosures limited to providing the contracted service
  • Appropriate safeguards and compliance with the Security Rule for ePHI
  • Reporting of security incidents and breaches of unsecured PHI, with a defined path to your team
  • Subcontractors (remote hands contractors, security guard firms, disposal vendors) bound to the same terms
  • Access to internal practices, books and records for HHS
  • Return or destruction of PHI at termination, including media in decommissioned hardware
  • Your right to terminate for material breach

Read the BAA alongside the master agreement and SLA. HHS recommends checking that SLA terms on availability, backup, data return and retention do not prevent you from accessing your own ePHI. For a full clause-by-clause walkthrough, see our guide to what a HIPAA business associate agreement is.

Which HIPAA physical safeguards does the facility cover?

The facility covers most of the physical safeguards in 45 CFR 164.310 for the space it controls. Use this table to turn each standard into a question for the provider.

164.310 standard Implementation specification What to ask the facility
(a) Facility access controls Facility security plan (addressable) Perimeter controls, mantraps, cameras, guard coverage and how long video is retained
Access control and validation (addressable) How access is granted and revoked, badge plus biometric at the cage, visitor escort and logging
Maintenance records (addressable) Records of repairs to doors, locks, cameras and other security components
Contingency operations (addressable) How your staff get in during an emergency to restore data
(b) Workstation use Standard Rules for shared crash carts, KVM consoles and customer lounges
(c) Workstation security Standard How provider staff workstations with access to your systems are restricted (mainly managed hosting)
(d) Device and media controls Disposal (required) Drive destruction process and certificates of destruction
Media re-use (required) How ePHI is removed before drives or servers are reused
Accountability (addressable) Logs of hardware entering and leaving, including remote hands shipments
Data backup and storage (addressable) Whether an exact copy is made before equipment is moved

"Addressable" does not mean optional. Under 45 CFR 164.306(d)(3), you assess whether the specification is reasonable and appropriate and, if it is not, document why and implement an equivalent alternative where reasonable. Ask the provider for its documented approach to each line.

Your own offices and laptops are still covered by 164.310(b) and (c).

Who is responsible for what: colocation, managed hosting or cloud?

The more of the stack the provider runs, the more safeguards move to it, but the risk analysis and overall compliance always stay with you. The Security Rule requires an accurate and thorough risk analysis of risks to ePHI, and HHS expects both you and the provider to run your own risk analyses.

Safeguard area Colocation Managed hosting Public cloud (IaaS)
Building, power, cooling, perimeter Provider Provider Provider
Cage and rack access Shared: provider badges, you approve the list Provider Provider
Hardware and media disposal You, unless you buy provider destruction Provider Provider
Operating system and patching You Usually provider, check the contract You
Network firewalls and segmentation You Shared Shared
Encryption and key management You Shared You configure, provider supplies tools
User access, MFA, audit logs for ePHI You Shared You
Backups and disaster recovery You Often provider, check the SLA You configure
Risk analysis, policies, training, BAAs You You You

If you are on public cloud rather than a physical facility, the cloud guide linked above covers that model. For database-level controls inside any of these environments, see our HIPAA compliant database checklist.

What evidence should you request before you sign?

Ask for a signed BAA and at least one independent assessment whose scope includes the specific site you will use. A marketing page or a self-completed questionnaire is not evidence.

  1. Signed BAA. Executed before any ePHI arrives, not "available on request."
  2. SOC 2 Type 2 report. A SOC 2 examination reports on controls relevant to security, availability, processing integrity, confidentiality or privacy. Check the review period dates, confirm your facility is in the system description, read any exceptions, and list the complementary user entity controls you must operate yourself.
  3. ISO/IEC 27001 certificate. ISO 27001 sets requirements for an information security management system, and certification is done by independent certification bodies, not ISO. Check the certificate's scope statement names the site and that it is current.
  4. HITRUST assessment. HITRUST offers e1, i1 and r2 assessments, with e1 and i1 valid for one year and r2 for two. Confirm which one the provider holds and what it covers.
  5. Facility specifics. Recent access logs for your cage (on request), a sample certificate of destruction, the incident reporting contact and the subcontractor list.

In our experience, the most common gap is scope: a multi-site provider may have a report covering only some sites. Ask in writing.

How does the data center fit your contingency plan?

The facility supports your contingency plan, but it does not replace it. 45 CFR 164.308(a)(7) requires a data backup plan, a disaster recovery plan and an emergency mode operation plan, with testing and an applications and data criticality analysis as addressable specifications.

Map each requirement to the provider:

  • Data backup plan. Where do backups live? A copy in the same building does not protect you from a site-wide outage.
  • Disaster recovery plan. What is the provider's commitment for power, cooling and network restoration, and what do you do yourself to restore systems?
  • Emergency mode operation. How do your engineers get physical or remote access during a disaster (this is also the 164.310(a) contingency operations specification)?
  • Testing. Can you run a failover test, and will the provider take part?

HHS also notes that storing ePHI offshore is permitted but may increase risk, so include the location of every primary and backup site in your HIPAA risk assessment.

Will the proposed Security Rule update change this?

Possibly, but it is still only a proposal. HHS published a notice of proposed rulemaking on January 6, 2025, with comments due March 7, 2025. Among other changes, it proposes that regulated entities obtain verification from business associates that they have deployed required technical safeguards.

As of October 2026, no final rule has been published, and the HHS NPRM page states that "the current Security Rule remains in effect." Collecting evidence from your data center now makes any future verification requirement easier.

How SecureSlate helps

SecureSlate helps HealthTech teams manage a data center the same way as any other PHI vendor:

  • Vendor risk management to track each facility, its BAA status, SOC 2 reports, ISO 27001 certificates and review dates.
  • Built-in HIPAA framework with multi-framework control mapping, so facility controls you rely on also map to SOC 2, ISO 27001 and HITRUST.
  • Custom controls for provider-specific items such as cage access reviews or certificates of destruction.
  • Risk management to record facility risks, including site location and single-site backups, in your risk register.
  • Access reviews, audit management, a trust center and security questionnaire automation for when your own healthcare customers ask how you host ePHI.

Start your free SecureSlate trial

FAQ

Can a data center be HIPAA certified?

No. HHS does not certify data centers or any other vendor. A provider can sign a BAA, implement the relevant safeguards and hold independent assessments such as SOC 2, ISO 27001 or HITRUST, but none of these is a HIPAA certification.

Does a colocation provider need to sign a BAA if our servers are encrypted?

In most cases you should expect one. HHS guidance treats an entity that maintains ePHI as a business associate even if it cannot view the data, and the conduit exception only covers transmission. HHS has not addressed colocation by name, so get legal advice if a provider refuses.

Is a SOC 2 report enough to choose a HIPAA compliant data center?

It is strong evidence but not enough on its own. You also need a signed BAA, confirmation that the report's scope includes your site, and a plan for the complementary user entity controls the report says you must run.

What is the difference between HIPAA compliant colocation and managed hosting?

With colocation you rent space, power and physical security, and you run almost everything else. With managed hosting the provider also runs servers and often patching and backups, so more safeguards move to it and the BAA and SLA need to say so.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

Keep reading

Oct 6, 2026 · HIPAA

HIPAA Compliant Database: Requirements and Configuration Checklist for Storing PHI

Oct 2, 2026 · HIPAA

HIPAA Compliant Texting: When You Can Text Patients and How to Do It Safely

Oct 2, 2026 · HIPAA

HIPAA Permitted Uses and Disclosures: When PHI Can Be Shared Without Authorization

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?