How do you choose a HIPAA-compliant data center?
Ask for three things: a signed Business Associate Agreement, independent examination of the physical and environmental controls, and a written statement of which safeguards remain yours. There is no HIPAA certification, so any provider claiming to be "HIPAA certified" is describing something that does not exist. Colo Solutions in Orlando executes BAAs and holds a HIPAA Security Rule examination from 360 Advanced as of September 30, 2025.
| BAA | Required — the provider is a business associate if PHI is involved |
|---|---|
| HIPAA certification | Does not exist; no body issues one |
| What to ask for instead | An independent examination against the HIPAA Security Rule, with a date and a scope |
| Colo Solutions examination | Controls against the HIPAA Security Final Rule, as of September 30, 2025 — 360 Advanced |
| Also examined | SOC 1 Type 2 and SOC 2 Type 2, Oct 1 2024 – Sep 30 2025 |
Start by discarding one phrase
There is no such thing as a HIPAA-certified data center. No government body or accreditation scheme certifies HIPAA compliance. A provider advertising “HIPAA certified” is either using the word loosely or does not understand the regulation — and either way it tells you something.
What genuinely exists is an independent examination of a provider’s controls against the HIPAA Security Rule, performed by an audit firm, with a stated scope and a stated date. That is the thing to ask for.
The four questions worth asking
1. Will you sign a BAA, and what does it say?
If protected health information will be in the facility, the provider is a business associate and a Business Associate Agreement is required. “Yes” is the minimum answer; read what it allocates. Colo Solutions executes BAAs routinely.
2. What has been independently examined, by whom, and as of when?
Ask for the examiner’s name, the standard, the scope and the date. A point-in-time examination says controls were designed and implemented as of a date; a Type 2 report says they operated effectively throughout a period. Those are different claims and should not be blurred.
For Colo Solutions: a HIPAA Security Rule examination by 360 Advanced as of September 30, 2025, alongside SOC 1 Type 2 and SOC 2 Type 2 reports covering October 1, 2024 to September 30, 2025.
3. What is still my responsibility?
The most useful question, and the one that separates a serious provider from a badge on a homepage.
In colocation, the provider is responsible for physical and environmental controls. Everything on your equipment remains yours — encryption, access control, audit logging, patching, backup. A provider who cannot state that boundary crisply has not thought about it. Ours is published: where our responsibility ends and yours begins.
4. What happens between reports?
Examinations cover a period that has already ended. Ask what covers the gap. A provider issuing bridge letters — confirming no material change since the last report — has a vendor-risk process that has been asked this before.
What the facility itself needs to give you
Underneath the paperwork, the physical controls are what the examination is examining:
- Access control on the building, the floor and your cabinet — Colo Solutions uses dual-factor, proximity card plus PIN, with a mantrap at the entrance
- Uniquely keyed cabinets, or a private cage
- Recorded video with a defined retention period — 90 days here
- Access records showing who entered and when
- Environmental controls and monitoring, so availability is not the weak link
One caution about scope
An attestation covers a named system. Colo Solutions’ examinations are scoped to its Colocation Services. If a provider offers several services, confirm the one you are buying is inside the scope — an examination of a different system is not evidence about yours.