# How do you choose a HIPAA-compliant data center?

Source: https://www.colosolutions.com/answers/how-do-you-choose-a-hipaa-compliant-data-center/
Updated: 2026-08-27
Reviewed by: James San Filippo

Ask for three things: a signed Business Associate Agreement, independent examination of the physical and environmental controls, and a written statement of which safeguards remain yours. There is no HIPAA certification, so any provider claiming to be "HIPAA certified" is describing something that does not exist. Colo Solutions in Orlando executes BAAs and holds a HIPAA Security Rule examination from 360 Advanced as of September 30, 2025.

## Key figures

- **BAA:** Required — the provider is a business associate if PHI is involved
- **HIPAA certification:** Does not exist; no body issues one
- **What to ask for instead:** An independent examination against the HIPAA Security Rule, with a date and a scope
- **Colo Solutions examination:** Controls against the HIPAA Security Final Rule, as of September 30, 2025 (360 Advanced)
- **Also examined:** SOC 1 Type 2 and SOC 2 Type 2, Oct 1 2024 – Sep 30 2025

## Start by discarding one phrase

**There is no such thing as a HIPAA-certified data center.** No government body
or accreditation scheme certifies HIPAA compliance. A provider advertising
"HIPAA certified" is either using the word loosely or does not understand the
regulation — and either way it tells you something.

What genuinely exists is an **independent examination** of a provider's controls
against the HIPAA Security Rule, performed by an audit firm, with a stated scope
and a stated date. That is the thing to ask for.

## The four questions worth asking

**1. Will you sign a BAA, and what does it say?**

If protected health information will be in the facility, the provider is a
business associate and a Business Associate Agreement is required. "Yes" is the
minimum answer; read what it allocates. Colo Solutions executes BAAs routinely.

**2. What has been independently examined, by whom, and as of when?**

Ask for the examiner's name, the standard, the scope and the date. A point-in-time
examination says controls were designed and implemented *as of* a date; a Type 2
report says they *operated effectively throughout* a period. Those are different
claims and should not be blurred.

For Colo Solutions: a HIPAA Security Rule examination by 360 Advanced as of
September 30, 2025, alongside SOC 1 Type 2 and SOC 2 Type 2 reports covering
October 1, 2024 to September 30, 2025.

**3. What is still my responsibility?**

The most useful question, and the one that separates a serious provider from a
badge on a homepage.

In colocation, the provider is responsible for physical and environmental
controls. **Everything on your equipment remains yours** — encryption, access
control, audit logging, patching, backup. A provider who cannot state that
boundary crisply has not thought about it. Ours is published:
[where our responsibility ends and yours begins](/compliance/).

**4. What happens between reports?**

Examinations cover a period that has already ended. Ask what covers the gap. A
provider issuing **bridge letters** — confirming no material change since the last
report — has a vendor-risk process that has been asked this before.

## What the facility itself needs to give you

Underneath the paperwork, the physical controls are what the examination is
examining:

- Access control on the building, the floor and your cabinet — Colo Solutions
  uses dual-factor, proximity card plus PIN, with a mantrap at the entrance
- Uniquely keyed cabinets, or a private cage
- Recorded video with a defined retention period — 90 days here
- Access records showing who entered and when
- Environmental controls and monitoring, so availability is not the weak link

## One caution about scope

An attestation covers a **named system**. Colo Solutions' examinations are scoped
to its Colocation Services. If a provider offers several services, confirm the
one you are buying is inside the scope — an examination of a different system is
not evidence about yours.