How do you choose a HIPAA-compliant data center?

Last updated August 27, 2026 · Reviewed by James San Filippo

Ask for three things: a signed Business Associate Agreement, independent examination of the physical and environmental controls, and a written statement of which safeguards remain yours. There is no HIPAA certification, so any provider claiming to be "HIPAA certified" is describing something that does not exist. Colo Solutions in Orlando executes BAAs and holds a HIPAA Security Rule examination from 360 Advanced as of September 30, 2025.

Key figures
BAA Required — the provider is a business associate if PHI is involved
HIPAA certification Does not exist; no body issues one
What to ask for instead An independent examination against the HIPAA Security Rule, with a date and a scope
Colo Solutions examination Controls against the HIPAA Security Final Rule, as of September 30, 2025 — 360 Advanced
Also examined SOC 1 Type 2 and SOC 2 Type 2, Oct 1 2024 – Sep 30 2025

Start by discarding one phrase

There is no such thing as a HIPAA-certified data center. No government body or accreditation scheme certifies HIPAA compliance. A provider advertising “HIPAA certified” is either using the word loosely or does not understand the regulation — and either way it tells you something.

What genuinely exists is an independent examination of a provider’s controls against the HIPAA Security Rule, performed by an audit firm, with a stated scope and a stated date. That is the thing to ask for.

The four questions worth asking

1. Will you sign a BAA, and what does it say?

If protected health information will be in the facility, the provider is a business associate and a Business Associate Agreement is required. “Yes” is the minimum answer; read what it allocates. Colo Solutions executes BAAs routinely.

2. What has been independently examined, by whom, and as of when?

Ask for the examiner’s name, the standard, the scope and the date. A point-in-time examination says controls were designed and implemented as of a date; a Type 2 report says they operated effectively throughout a period. Those are different claims and should not be blurred.

For Colo Solutions: a HIPAA Security Rule examination by 360 Advanced as of September 30, 2025, alongside SOC 1 Type 2 and SOC 2 Type 2 reports covering October 1, 2024 to September 30, 2025.

3. What is still my responsibility?

The most useful question, and the one that separates a serious provider from a badge on a homepage.

In colocation, the provider is responsible for physical and environmental controls. Everything on your equipment remains yours — encryption, access control, audit logging, patching, backup. A provider who cannot state that boundary crisply has not thought about it. Ours is published: where our responsibility ends and yours begins.

4. What happens between reports?

Examinations cover a period that has already ended. Ask what covers the gap. A provider issuing bridge letters — confirming no material change since the last report — has a vendor-risk process that has been asked this before.

What the facility itself needs to give you

Underneath the paperwork, the physical controls are what the examination is examining:

  • Access control on the building, the floor and your cabinet — Colo Solutions uses dual-factor, proximity card plus PIN, with a mantrap at the entrance
  • Uniquely keyed cabinets, or a private cage
  • Recorded video with a defined retention period — 90 days here
  • Access records showing who entered and when
  • Environmental controls and monitoring, so availability is not the weak link

One caution about scope

An attestation covers a named system. Colo Solutions’ examinations are scoped to its Colocation Services. If a provider offers several services, confirm the one you are buying is inside the scope — an examination of a different system is not evidence about yours.