Insight

The Importance of Data Center Compliance to Your Business

February 07, 2025 · Data center

In late 2018, Marriott disclosed a breach of its Starwood reservation database that had gone undetected since 2014. The initial disclosure put it at up to 500 million guests; Marriott later revised the figure to roughly 383 million records. Either way the striking number is the smaller one — four years undetected. Their information needed to be more secure and not as easily accessible. Other massive data breaches have affected millions of people and cost companies millions of dollars in lawsuits, all because they had a weakness in their security that hackers were able to exploit. One way to help prevent data breaches is by selecting a secure data center to store your data.

When you’re searching for a data center to house your business’s critical information, make sure the data center is compliant with your industry. You alone are responsible for ensuring your business data is secure at all times, so it’s vital to be discerning when choosing where that data is stored.

If you’re in Florida areas such as Orlando, Space Coast, Tampa, or Daytona Beach, here are reasons why you should be searching for a data center that meets compliance standards.

What Exactly Is Compliance & Why Is it Important

Compliance standards, also referred to as data center security standards, help ensure that data centers are using best practices for data protection. Standards vary between the different types, but there are several types of compliance that data centers can be audited and assessed for to prove that they are secure enough to store various types of data.

Different Types of Compliance Apply to Various Industries

Certain customers and/or certain types of data must meet legal requirements with regard to security and protection, and those customers and data require data centers that provide that security and meet other operational requirements for these customers to meet their legal requirements. At Colo Solutions, we have different types of compliance, such as:

  • SOC 1 Type 2 and SOC 2 Type 2, examined by 360 Advanced

  • An examination of controls against the HIPAA Security Rule, by the same firm

We do not hold a PCI DSS attestation, and we say so plainly — see the PCI section below for what a colocation provider actually contributes to your PCI scope.

What Does SOC 2 Type II Mean?

SOC stands for System and Organization Controls. A SOC 2 is an examination that produces a report — not a certification, and no body issues a “SOC 2 certificate”. A Type 2 report covers whether controls operated effectively throughout a period, rather than at a single moment.

There are five trust services categories, and an examination may cover any subset of them:

  1. Privacy

  2. Confidentiality

  3. Security

  4. Processing Integrity

  5. Availability

Ours covers two of the five: Security and Availability. It does not cover Confidentiality, Processing Integrity or Privacy. That matters when you are reading someone’s report, because “SOC 2” unqualified is widely assumed to mean all five — always ask which categories are in scope, and over what period.

We Follow HIPAA Best Practices

The Health Insurance Portability and Accountability Act (HIPAA) is set up to protect healthcare data, and we follow all HIPAA best practices. Healthcare data is sensitive and must be safe from hacker attacks since it contains medical history and patient information. HIPAA also regulates the type of technology used to store that data, as outdated technology can be a weakness that hackers can easily exploit. To protect electronic health records (EHRs), there are technical, physical, and administrative safeguards required for HIPAA compliance:

  • Access control

  • Audit control

  • Integrity control

  • Transmission security

  • Limited facility access

  • Device security

  • Security management process

  • Security personnel

  • Information access management system

  • Employee training and management

  • Evaluation of policies and procedures

HIPAA applies to health insurance providers, billing services, healthcare providers, and business associates. One caution worth carrying into any vendor conversation: there is no such thing as HIPAA certification. No body issues one. What exists is an independent examination of a provider’s controls against the HIPAA Security Rule, with a named examiner, a stated scope and a date — ours was performed by 360 Advanced as of September 30, 2025. A provider advertising itself as “HIPAA certified” is describing something that does not exist.

PCI DSS — whose responsibility it actually is

PCI DSS stands for Payment Card Industry Data Security Standard, developed by a council whose members include American Express, Visa and Mastercard. The standard is revised over time; version 4.0 superseded the 3.2.x line, which was retired in March 2024. If a provider’s marketing still cites a 3.x version, that tells you when the page was last checked.

Colo Solutions holds no PCI DSS attestation and does not claim one. We are not a payment processor, and cardholder data does not reach us in the ordinary course of business.

That is usually the wrong question anyway. If your own cardholder data environment is hosted in a cabinet here, what you need from the facility is Requirement 9 — restricting physical access to cardholder data. Dual-factor access at every door, a mantrap, uniquely keyed cabinets, recorded video with 90-day retention and access records all speak to that requirement, and they sit inside the scope of our SOC 2 examination. For your assessor, an examined control is better evidence than a provider’s self-assessment. The rest of PCI scope — your systems, segmentation, key management and logging — stays yours to validate.

Are you looking for a data center in central Florida that adheres to strict compliance standards? Call us today.

If you are evaluating data centers in central Florida, ask each one for the same three things: the examiner’s name, the exact scope and period of each report, and a written statement of what remains your responsibility. We publish ours — see what each report covers, and what it does not. Call [(407) 210-2480](tel:(407) 210-2480) and we will send the current reports under NDA.