Many major providers offer HIPAA-compliant tiers, but you must ensure you are using a supported version and have signed their BAA.
: Solutions must ensure high uptime and include robust backup and disaster recovery plans. ☁️ Common HIPAA-Compliant Cloud Providers
: This is a mandatory legal contract. Without a signed BAA, you cannot legally store PHI on a platform, even if the service has high-level encryption.
10 Best HIPAA-compliant Cloud Storage Providers In 2024 - Fortinet
: PHI must be encrypted both at rest (while stored) and in transit (while being sent).
A cloud provider is considered a (BA) if it handles ePHI, even if it cannot access the encrypted data. To be compliant, the following must be in place: