As of April 2005, HIPAA's security standards mandate that all health care providers establish a contingency plan to respond to any type of computer disaster involving potential data loss. Storage Guardian's technology complies with the following HIPAA requirements:
Storage Guardian's Internet Vaulting solution is completely secure and can protect your organization in the case of any type of data loss. Please refer to the table below for a more detailed look into how Storage Guardian's secure remote backup solution enables business to instantly comply with HIPAA regulations:
HIPAA Privacy Rule | Storage Guardian | Covered Entity |
Safeguards: §164.530 (c) (1) |
||
* Administrative §164.308 |
YES | Enabled by Storage Guardian |
* Technical 12 |
YES | Enabled by Storage Guardian |
* Physical §164.310 |
YES | Enabled by Storage Guardian |
Access to PHI §164.524 |
NO - Covered Entity has the only encryption key | YES |
Amendment to PHI §164.526 |
NO - Covered Entity has the only encryption key | YES |
Encryption of PHI §164.312 |
YES | YES |
HIPAA Security Standards Matrix | Storage Guardian | Covered Entity |
Assigned Security Officer §164.308(a)(2) |
YES | ... |
Access Authorization §164.308(a)(4) |
NO - Only covered entity has access to PHI |
YES |
Security Incident Reporting §164.308(a)(6) |
YES | ... |
Contingency Plan: Data Back-up §164.308(a)(7) |
YES | YES |
Contingency Plan: Disaster Recovery §164.308(a)(7) |
YES | YES |
Business Associate Agreement §164.308(b)(1), 106.103 |
YES | ... |
Facility Access Controls §164.310(a)(1) |
YES | ... |
Device & Media Controls §164.308(d)(1) |
YES | YES |
Access Control §164.312(a)(1) |
YES | YES |
Transmission Security §164.312(e)(1) |
YES | YES |
Storage Guardian's technology and services are SSAE 16 Type II compliant in accordance with the AICPA (SOC) framework.
SSAE 16 is the professional standard used for issuing SOC 1 reports, which consists of SOC 1 (SSAE 16) along with SOC 2 and SOC 3 (AT 101) reporting. The SSAE 16 standard effectively replaces the aging and antiquated SAS 70 auditing standard that has been in use for approximately twenty years.
You can find out more about this new standard of compliance here.
Storage Guardian’s SSAE Type II compliance means that we have undergone attest procedures in accordance with the AICPA professional standard. You can have complete confidence that your data resides within a facility which employs stringent internal business processes and IT controls for the services provided.
Modules validated as conforming to FIPS 140-1 and FIPS 140-2 are accepted by the Federal Agencies of both the United States and Canada for the protection of sensitive information. The National Institute of Standards and Technology (NIST) established the Cryptographic Module Validation Program (CMVP) that validates cryptographic modules to Federal Information Processing Standards (FIPS)140-1 Security Requirements for Cryptographic Modules, and other FIPS cryptography based standards.
It means we have passed rigorous security standards using independent, accredited Cryptographic and Security Testing (CST) laboratories to test our modules against requirements found in FIPS PUB 140-2, Security Requirements for Cryptographic Modules. These requirements cover 11 areas related to the design and implementation of a cryptographic module. NIST's Computer Security Division (CSD) and CSEC jointly serve as the Validation Authorities for the program, validating the test results and issuing certificates.
Storage Guardian is CICA 5970 Type B certified by SAS 70 International.
Storage Guardian’s Network Operations Centre and File Sync 'n Share services are protected by Comodo Instant SSL.
Recognized by 99.9% of all browsers and mobile devices, Comodo is a leading supplier of SSL certificates guaranteeing a high level of encryption for online transactions.
Instant SSL by Comodo provides the strongest levels of encryption available, featuring 2048-bit signatures with 256 bit encryption.
This means that Storage Guardian and Comodo are hard at work protecting your data, and you may rest assured that your online transactions with us are securely encrypted.
Play a video overview of our top features.