Save 40% for 3 Mos. with Code SAVENOW (new customers only)

HIPAA Compliant Data Centers & Solutions

Hosting Management and Security Take the Headache Out of HIPAA Compliance

HIPAA (Health Insurance Portability and Accountability Act of 1996) requires businesses that process, store or transmit electronic protected health information (ePHI or PHI) to comply with strict administrative, physical and technical safeguards. Liquid Web offers managed dedicated, VPS, and cloud dedicated solutions compliant with HIPAA guidelines. A third-party audit confirms that Liquid Web is HITECH Certified.

Often, the consequences of the loss or compromise of protected health information could cause irreparable damage to a client's reputation, if not even more serious legal penalties. In order to ensure our clients are protected, we have crafted compliant hosting solutions, making sure technical controls, backup management, safeguards and physical security policies are in place, all to verify that your data is secured to industry standards.

Secure Your Healthcare Data

  • Wholly owned Core Data Centers
  • Fully Managed Servers
  • Locked Server Cabinets Included
  • Business Associate Agreement (BAA) Available
  • 24/7/365 On-Site Support
  • Offsite Backup Available
  • High Availability Infrastructure
  • Extensive Administrative, Physical & Administrative Safeguards

Recommended HIPAA Compliant Hosting Plans

Purchase a pre-configured HIPAA Package (shown below) or work with our team to build a custom hosting solution.

hippa-single
Single Server HIPAA Hosting
  • Single Dedicated Server for Web & Database Use
  • Cisco Firewall
  • Fully Managed by the Most Helpful Humans in Hosting®
Starting at $343
Starting at $383
hippa-multiple
Multiple Server HIPAA Hosting
  • Web Server(s) with Separate Database Server
  • Cisco Firewall
  • Fully Managed by the Most Helpful Humans in Hosting®
Starting at $687
Starting at $847
serversecure

HIPAA Compliance: Security & Solutions

Data Center Physical System Security

Minimize Risk of Loss and Theft

  • 24/7/365 Manned Facility
  • Closed Circuit TV Security Cameras
  • Monitored 24/7/365 by 3rd Party Security Company
  • Site Entrance Controlled by Electronic Perimeter Access Card System

Minimize Risk of Damage

  • High Security Facilities
  • Data Centers Privately Owned and Operated
  • Durable, Poured Concrete External Walls
  • Disaster Neutral Geographic Locations

Advanced Fire Prevention Infrastructure

  • Dry Pipe Preaction, Double Interlock System
  • NFPA 13 Compliant

Security Zones

  • Office Space Separate from Data Center Space
  • Advanced Proximity Credentials Required to Access Data Center
  • All Employees Receive Full Background Check
  • Key Locked Physical Server Rack Enclosures Available
  • Component Level Redundancy Available for Hard Drives
  • Hot and Cold Spare On-site Servers Available

Entry Security - Access Controls

  • Exterior Entrances Secured by Mantraps with Interlocking Doors
  • Access to the Data Center Space Requires Secure Credentials

Uninterruptible Power Supplies (UPS)

  • Multiple N+1 MPS Generators
  • Multiple Fuel Contracts Ensure Fuel Availability for Generators
  • Multiple N+1 UPS Systems with 30 Minute Minimum Runtime.
  • Server Chassis Feature Redundant Power Supplies (Available)
  • Server Chassis Have A/B Power Configurations (Available)
  • Redundant ASCO Closed Transition Bypass Isolation Transfer Switches
  • Capability to Provide Tier-4 Power
  • Four 10 Megawatt Feeds Available
  • Diverse Paths from Substation
  • 2N Power Available

SSAE-16 (formerly SAS70) & Safe Harbor Compliant

Network Configuration and Technical Security

Network Device Management

  • Hardware Cisco Firewall Devices Available with Full Management
  • Qualified Engineers Available 24/7/365
  • Assistance with Hardware Firewall Configuration
  • Outbound and Inbound Traffic Filtering Available
  • Intrusion Detection/Intrusion Prevention Modules Available
  • Network Redundancy Ensures Failover
  • Diverse Connectivity Fiber Paths Into Building
  • Dedicated Meet-Me Room
  • Bandwidth Co-Op solutions
  • Carrier Neutral
  • On-net transport to most major global cities

Remote VPN

  • Remote Secure VPN Implementations and Management Available
  • Encryption (Triple DES or AES)
  • Authentication (Site-to-Site VPN Tunnels) with Strong Passwords, Pre-Shared Key and Certificate
  • DMZ Implementations
  • Assistance with Log Management and Monitoring

Backup Management

Protect your data with Acronis Cyber Backup, our fully managed, robust backup solution for Linux and Windows Managed Dedicated Servers. Acronis is a fully customizable backup solution that can capture your entire system configuration or just specific files, saving them all to an external storage system or to the Acronis cloud. You can recover single files or your exact server configuration in the case of a catastrophic event. Liquid Web’s partnership with Acronis gives every client full access to the Acronis interface so you have control. You can set up schedules, change what’s backed up, or restore files without contacting Liquid Web. When you pair Acronis Cyber Backup with our state-of-the-art, secure Data Centers - featuring SSAE-16, PCI compliance, Safe Harbor Certification, and 24x7x365 on-site support - we can ensure unparalleled uptime and safeguard against data loss in even the most extreme circumstances.

Features
  • Continuous Backups
  • Incremental Snapshots
  • Bare-Metal Disaster Recovery
  • High Performance, Low System Impact
  • cPanel Administration Plugin
  • MySQL Database Plugin
  • Disk Safe Data Encryption Available
How It Works
  1. By default, Acronis directly reads your hard disk volumes at the sector level, bypassing the file system for the ultimate in performance and recovery. The disk sector synchronization is performed while the server is online and causes no interruption to I/O requests, even on a busy server.
  2. Acronis can also be configured to read at a file-by-file level if there are specific files you’d like tracked at a different cadence.
  3. By reading the disk at the lowest possible level, Acronis captures incremental recovery images, containing your files and all the required information for consistent point-in-time system-wide backup images.
  4. These sector-based backups increase throughput and reduce overhead so that servers can be fully operational with minimal performance impact while the backup is taking place. Backups can usually be performed at any time, even on busy servers.
  5. All data is safely stored on off-server backup nodes, ensuring data continuity even in case of catastrophic failure. Customers can choose to store their data on Liquid Web’s cloud storage or on the Acronis cloud, currently hosted in Phoenix, AZ.
  6. Clients can also choose to encrypt their data. With a click of a button, Acronis Cyber Backup can encrypt data before its stored, perfect for maintaining extra security and for any imposed compliance requirements.
  7. When necessary, you can restore servers directly from your disk-based backups. Unlike traditional backup software, there is NO need to first partition your drive and install the operating system. In addition, our bare metal recovery greatly increases the speed of complete system recovery from a catastrophic failure.
  8. Recovery, management, scheduling, and configuration are all available at your fingertips with the Acronis backup interface, available via a single-sign-on link in your My Liquid Web interface. Customers can make any changes, start a recovery, or just check on available backups.
  9. Our Managed Dedicated Server customers who are running Linux can also manage their backups through the Acronis cPanel Plugin, accessible directly from your cPanel interface. The plugin grants server-level or user-level access to backups and restores all conveniently from the users cPanel interface.
  10. The cPanel plugin is available to all cPanel users and included with new servers. If you have an existing server and would like the plugin, just open a ticket! Our Helpful Humans can install it with no issues.

Security Services

ServerSecurePLUS™

We have innovated on top of our exclusive ServerSecure™ installation service. A setup option available for our dedicated servers, ServerSecure™ ensures optimal compatibility, paramount integrity and the most efficient usage of your server/servers. We have upgraded this service to iron-clad standards by adding daily Malware scans and a multitude of server hardening features available exclusively to those opting for ServerSecurePLUS™. What would have taken hours of installation work and the help of an outside system administrator, is now at your fingertips with the help of ServerSecure™ and ServerSecurePLUS™.

  • Brute Force Detection and Evasion
  • Apache DOS Prevention/Protection
  • E-Mail Virus Filtering
Exclusive to ServerSecurePLUS™
  • Daily Malware Scan
  • SSH/cPanel/FTP Hardening
  • Webserver & PHP Hardening
  • Monthly Nessus® Vulnerability Scans
  • DDOS Attack Protection/Mitigation
  • Detect and Block Emerging Application-Layer DDoS Attacks
  • Deploy a Turnkey Solution to Stop Threats
  • Accelerate Responses to DDoS Attacks
  • Prevent Illegitimate Botnet Communications
  • Leverage Real-time Security Intelligence
  • Mitigate Volumetric Attacks
  • Block Illegitimate traffic from Costing you Money in Bandwidth Charges

We Specialize in Custom Hosting Solutions

If you're working on a complex project, don't go it alone. Our hosting advisors can work with you to build the ideal solution for your client.
Get started today, we're available 24/7.

Resources for HIPAA Compliant Hosting

Man looking at portfolio site

If you’re a small business in the healthcare market, or a company that serves small businesses in healthcare, chances are that you are struggling to understand how healthcare […]

Download Now

generations homecare system case study recap

Generations Homecare System is a best-in-class software application used by home health providers to manage their business operations. […]

Download Now

common web security problems

You do not have to look very far to find discussions about privacy. No matter how you consume news and other content, privacy and data protection are at the forefront of the conversation. With over 22 years as a managed […]

Read Blog

Server

HIPAA Hosting FAQ for SMBs

It’s not uncommon for healthcare businesses like yours to have a lot of questions when it comes to hosting your HIPAA workloads. We’ve assembled some of the most common questions that customers have asked us about our HIPAA hosting solutions, along with the answers, in this handy FAQ.