View
 

Is Syncplicity Business Edition HIPPA compliant

There is no standard "HIPAA certificate of compliance" for backup and file management software and services. Syncplicity Business Edition helps you comply with HIPPA security and privacy rules however with the following features:

 

Encryption of data during transfer: All data is transmitted only through a secure SSL tunnel secured with the highest level of SSL encryption available.

 

  • Security of stored data: All stored data is stored securely “at rest” with the highest level of military-grade 256bit AES encryption. All data on retired servers is destroyed according to the techniques detailed in DoD 5220.22-M (“National Industrial Security Program Operating Manual”) or NIST 800-88 (“Guidelines for Media Sanitation”) to destroy the encrypted customer files as part of the decommissioning process.
  • Secure Datacenters: Syncplicity servers are located in secured data centers that have passed SAS 70 Type II auditing as defined by Developed by the American Institute of Certified Public Accountants. A SAS 70 Type II certification is the result of a 3rd party formal audit and extensive testing to validate security controls, safeguards, and processes. SAS 70 certifies that each data center has met rigorous requirements around physical security, physical access, and internal controls.
  • Two Data Center Policy: Syncplicity Business Edition is built around a unique Two Data Center Policy. For an additional layer of security, Syncplicity maintains all servers responsible for authentication and encryption key management in a separate data center from the data centers housing the encrypted file data. The encrypted file data and proper file version encryption key are brought together only on an as-needed basis and in a tracked manner. By keeping the encryption key completely separate from the file vault, Business Edition provides a higher level of security by not having a single point of compromise.
  • Offsite Backup with Versioning: Syncplicity Business Edition provides offsite backup and full versioning and audit trail capabilities to protect against hardware failures, theft, viruses, accidental or malicious changes and deletions, and natural disaster. Instant restores and access to previous versions and version information are included to reduce downtime in case of an incident. All files are stored multiple times in multiple data centers to ensure continued availability without any single point of failure.
  • Access Controls: Permissions can be set differently per user. Files managed by Business Edition are accessible via a protected website accessible through any computer or device using proper passwords. Administrative policy controls enable administrators to provide a locked-down or more permissive environment depending upon organizational requirements.
  • Written contingency plan: The HIPAA Security rule requires that covered entities have a written contingency plan for responding to system emergencies, including a detailed plan concerning the data backup and recovery process in the event of a disaster. Syncplicity Business Edition can help to fulfill this requirement.

 

If you have additional questions on HIPAA and HIPAA compliance, please refer to the HIPAA section of the U.S. Department of Health and Human Services' website: http://www.hhs.gov/ocr/hipaa/