What HIPAA Actually Requires From Your Data Center in 2026

July 8, 2026 · 9 MIN READ

"HIPAA compliant data center" gets searched thousands of times a month, but most of what you'll find is marketing copy that confuses certification with compliance. Here's the direct answer: HIPAA doesn't certify data centers. It requires you to implement specific physical, technical, and administrative safeguards — and to sign a Business Associate Agreement with any vendor who touches your ePHI. Whether your facility actually supports that is what you need to verify.

What Does HIPAA Actually Regulate at the Infrastructure Layer?

The HIPAA Security Rule covers electronic protected health information (ePHI) and breaks requirements into three categories: administrative safeguards, technical safeguards, and physical safeguards. Data centers are primarily in scope for physical safeguards, but the line between physical and technical blurs fast when you're talking about colocation.

Under 45 CFR § 164.310, physical safeguards require covered entities and business associates to:

  • Implement facility access controls to limit physical access to systems containing ePHI
  • Maintain a record of hardware movements — when equipment enters or leaves the facility
  • Have policies for workstation use and device/media disposal
  • Document who has authorized access and how that access is reviewed

What the rule doesn't do is tell you exactly how to implement any of this. HIPAA is a framework of required outcomes, not a prescriptive technical standard. That's intentional — it's designed to scale from a small clinic's server closet to a multi-tenant data center. The practical implication is that "HIPAA compliance" at a facility means they've implemented controls that satisfy these requirements and can document them.

The controls auditors actually examine tend to map closely to SOC 2 Type II, NIST 800-53, and HITRUST CSF. If a facility holds those certifications, they've already gone through the control validation work that HIPAA physical safeguard requirements demand.

The BAA Is Non-Negotiable — Here's Why

This is where a lot of healthcare organizations get tripped up. A data center can have biometric access control, 24/7 guards, and a cage inside a cage — and still leave you out of HIPAA compliance if they won't sign a Business Associate Agreement.

Under HIPAA, any vendor who creates, receives, maintains, or transmits ePHI on your behalf is a business associate. A colocation provider that houses your servers running a healthcare application is receiving and maintaining ePHI. That makes them a business associate. Full stop.

The BAA defines what the business associate can do with ePHI, requires them to implement appropriate safeguards, and obligates them to report breaches. Without it, you have no contractual basis for the compliance relationship — and in an audit or breach investigation, that gap is critical.

Ask any prospective data center partner two questions before you get into technical specs:

  1. Will you sign a BAA?
  2. Have you signed BAAs with other healthcare customers?

If the answer to either is no or evasive, move on. IDACORE signs BAAs with healthcare customers at IDACORE Boise. It's part of the standard compliance engagement, not a negotiation.

What "Compliance-Ready" Infrastructure Actually Looks Like

There's a difference between a facility that's compliance-ready and one that just claims to be. Here's what the physical layer needs to deliver for a healthcare workload:

Access control and logging. Badge access at every entry point, with timestamped logs retained long enough to support audit requirements. The HIPAA Security Rule requires you to be able to produce access records. Your data center needs to be able to produce them too — and provide them to you when you need them for your own documentation.

Visitor management. Escorted access for anyone without permanent authorization. Logged entry and exit. This matters because your HIPAA risk assessment needs to account for who can physically reach systems containing ePHI.

Hardware controls. Documented procedures for equipment that enters or leaves the facility. Chain of custody for media disposal. If a drive gets decommissioned, you need evidence of secure destruction — a certificate of destruction at minimum.

Environmental reliability. This isn't a HIPAA requirement per se, but availability is. Unplanned downtime on a system containing ePHI that results in unavailability triggers breach analysis requirements under the HIPAA Security Rule's contingency plan standard (45 CFR § 164.312(a)(2)(ii)). N+1 UPS and cooling isn't just an uptime feature — it's part of your risk management posture.

IDACORE Boise runs N+1 UPS and cooling in a 1.4MW, 34,000 SF facility with seven on-net carriers. When one path goes down, traffic reroutes. That redundancy directly supports the availability requirements in your HIPAA risk assessment.

How IDACORE Boise Compares to the Alternatives

A lot of healthcare organizations default to AWS or Azure because they've heard those platforms are "HIPAA compliant." They are — partially. AWS and Azure both offer BAAs, but those BAAs only cover specific services. If you're using a service not listed in their BAA, it's not covered. And you're still responsible for every configuration decision: encryption at rest, encryption in transit, access logging, key management, network segmentation.

The shared responsibility model isn't wrong, but it adds compliance overhead. Every control you implement in a hyperscaler environment needs to be documented, validated, and re-validated when the platform updates. That's engineering time you're spending on compliance instead of product.

Factor IDACORE Boise AWS/Azure HIPAA-Eligible Services
BAA available Yes Yes (covered services only)
Physical safeguards Operator-controlled, documented Shared responsibility, AWS-managed
Certifications SOC 2 Type II, PCI DSS, NIST 800-53, HITRUST CSF SOC 2, ISO 27001, FedRAMP (varies)
Data residency Idaho, documented Region-level, not state-level
Contract term 12 months standard On-demand / variable
Pricing model Flat, no egress fees Variable, egress costs real money
Support Direct, humans who know your rack Tiered, ticket-based

The data residency point matters more than people realize. HIPAA doesn't require state-level residency, but your legal team and your customers might. Healthcare contracts increasingly include data residency clauses. "Your data stays in Idaho" is a statement we can make and document. "Your data stays in us-west-2" means it's in Oregon, Washington, or California depending on AWS's internal routing — and you don't get to audit that.

What Your Risk Assessment Needs to Cover

HIPAA requires a risk analysis under 45 CFR § 164.308(a)(1). That analysis needs to identify where ePHI lives, what threats exist, what the likelihood and impact of those threats are, and what controls you've implemented to address them. Your data center is a direct input to that document.

When HHS audits a covered entity or business associate, they ask for the risk analysis first. If your risk analysis references physical safeguards at your colocation facility, you need documentation from that facility to back it up — access logs, incident reports, the BAA, evidence of their certifications.

A facility with SOC 2 Type II and HITRUST CSF certifications gives you third-party-validated control documentation you can reference directly. That's not just a checkbox — it's audit evidence you don't have to produce yourself.

The practical checklist for evaluating a data center against HIPAA requirements:

  • Will they sign a BAA? (Required)
  • Do they hold SOC 2 Type II? (Strongly recommended)
  • Can they provide access logs on request? (Required for your risk documentation)
  • What's their incident notification process? (HIPAA breach notification requires you to notify within 60 days — your vendor needs to notify you faster)
  • What are their media disposal procedures? (Required under physical safeguards)
  • What's their uptime track record? (Relevant to availability risk in your risk analysis)

Frequently Asked Questions

Does a data center need to sign a BAA to be HIPAA compliant?
Yes. If your data center stores, processes, or transmits ePHI on your behalf, they're a business associate under HIPAA and must sign a BAA. Without one, you're out of compliance regardless of the facility's physical security. Any data center claiming HIPAA compliance that won't sign a BAA is either misrepresenting their services or doesn't understand the rule.

What physical safeguards does HIPAA require from a data center?
The HIPAA Security Rule requires facility access controls, workstation use policies, device and media controls, and a documented process for authorizing physical access. In practice, this means badge access logs, visitor escort policies, camera surveillance, and documented procedures for hardware disposal. The rule is intentionally non-prescriptive — it specifies what you must address, not exactly how.

Can I use AWS or Azure and still be HIPAA compliant?
Yes, but only for services covered under their BAA, which excludes many services by default. You're also responsible for every configuration decision — encryption, access controls, audit logging — on your end. Hyperscalers provide a compliant platform, not compliant workloads. Many healthcare organizations find the shared responsibility model adds compliance overhead that dedicated colocation avoids.

What's the difference between a HIPAA-compliant data center and a HIPAA-certified data center?
There's no official HIPAA certification — the term is marketing. What you want is a facility with SOC 2 Type II and documented HIPAA-ready controls, plus willingness to sign a BAA and support your risk assessment documentation. IDACORE Boise holds SOC 2 Type II, PCI DSS, NIST 800-53, and HITRUST CSF certifications, which together cover the control framework HIPAA auditors actually examine.

Does data residency matter for HIPAA compliance?
HIPAA doesn't mandate data residency by state, but it does require you to know where ePHI is stored and to have agreements covering it. State breach notification laws vary significantly, and some healthcare contracts require data to stay within specific jurisdictions. Keeping ePHI in Idaho means Idaho's breach notification rules apply — and you can document exactly where your data lives, which simplifies both audits and incident response.

If you're evaluating colocation for a healthcare workload and need a facility that'll sign a BAA, provide audit-ready documentation, and give you a direct line to engineers who understand what's actually in your rack — talk to us at IDACORE. IDACORE Boise is SOC 2 Type II certified, HITRUST CSF certified, and built for exactly this kind of compliance-sensitive workload.

Tags

HIPAA compliant data centerHIPAA colocationdata center HIPAA requirementshealthcare data center complianceHIPAA Security Rule physical safeguards
IDACORE

IDACORE

Senior Infrastructure Engineer

15+ years of data center operations and network engineering, including ISP founding and BGP peering at the Seattle Internet Exchange.

Ready to Implement These Strategies?

Our team of experts can help you apply these regulatory compliance techniques to your infrastructure. Contact us for personalized guidance and support.

Get Expert Help