Questions IT security teams ask about HIPAA-compliant cloud backup
IT security leads often find themselves tasked with finding a backup solution, only to realize that "HIPAA-compliant" doesn't mean what they thought. This confusion arises because cloud backup intersects with three compliance areas: the Security Rule's administrative safeguards, the Privacy Rule's disclosure limitations, and the Breach Notification Rule's breach definitions. Here's what your team needs to know.
What's the difference between cloud storage and cloud backup?
Cloud storage is a file-sharing tool. You manually select files, upload them to a service like Dropbox or Google Drive, and share them. It's designed for collaboration, not disaster recovery.
Cloud backup, however, is software that runs continuously, automatically copying designated files to an off-site server. If your server crashes or ransomware encrypts your files, you can restore everything from the backup.
For a covered entity managing Electronic Protected Health Information (ePHI), using cloud storage as a backup strategy can lead to a potential breach if you can't produce records when required under the HIPAA Privacy Rule.
Does my backup vendor count as a Business Associate?
Yes, if they're storing Protected Health Information (PHI) on your behalf. Once a vendor has access to PHI, even if encrypted, they meet the regulatory definition of a Business Associate under 45 CFR § 160.103.
You need a signed Business Associate Agreement (BAA) with any cloud backup vendor handling PHI. Without a BAA, you're out of compliance with the HIPAA Privacy Rule's requirements for Business Associate contracts (45 CFR § 164.502(e)). If that vendor experiences a breach, you're liable for the penalty.
Some vendors won't sign a BAA. This indicates they're unwilling to accept the compliance obligations that come with handling PHI. Move on.
What encryption standard should I require?
The HIPAA Security Rule doesn't mandate a specific encryption standard. It's an Addressable Specification under 45 CFR § 164.312(a)(2)(iv). If you choose not to encrypt, you need documented evidence that you considered it and selected an equivalent safeguard.
Require 256-bit AES encryption at rest and in transit. Some vendors offer 128-bit encryption, which is outdated. The encryption must apply to data in three states: during transmission, while stored, and during retrieval.
Verify vendor claims about encryption. Ask: Is the data encrypted before it leaves our network? Who holds the encryption keys? Can the vendor access our unencrypted data? You want the answers to be yes, you, and no.
How do I compare vendors when they all claim to be "HIPAA-compliant"?
Ignore the marketing claim. "HIPAA-compliant" is not a certification; it's a set of obligations the vendor agrees to meet when they sign your BAA.
Evaluate vendors on these criteria:
- Backup scope and automation: Can the solution protect all systems where you store ePHI? Does it run automatically?
- Recovery capabilities: Can you restore individual files or only full system images? How many previous versions does the system retain?
- Deduplication and efficiency: Does the system use incremental backups or re-upload entire files every time?
- Access controls and audit logging: Can you restrict access? Does the system generate audit logs?
What happens during the first backup?
Expect it to take hours or days, depending on data volume and network bandwidth. The initial backup copies everything you've designated. After that, it backs up only what's changed.
Plan the first backup during a maintenance window. Some vendors offer a "seed" option where you copy data to a physical drive and ship it to them, avoiding network saturation.
Once the initial backup completes, ongoing backups should be invisible to users. If users complain about network slowdowns, the vendor's incremental backup process isn't efficient enough.
Can I just use external hard drives instead?
Technically yes, but you're trading one risk for another. External drives are cheaper but require manual processes that can fail. Someone must remember to run the backup, rotate the drives, and store them securely off-site.
External drives often don't meet the HIPAA Security Rule's requirement for off-site storage. If the drive is in the same building as your server, a disaster could destroy both.
If you use external drives, treat them as ePHI storage devices: encrypt them, track them in an asset inventory, and document secure destruction when you retire them.
What about hybrid solutions?
Many organizations use a hybrid model: local servers for fast access, with automated cloud backup for disaster recovery. This combines local storage performance with off-site backup protection.
The compliance obligation remains. You still need a BAA with the cloud backup vendor, encrypt data, and include both local servers and cloud backup in your HIPAA Security Rule risk analysis.
Document the data flow in your system security plan: where ePHI lives, how it moves, who can access it, and what safeguards protect it. When the Office for Civil Rights (OCR) asks how you protect ePHI, "we use cloud backup" isn't enough. They want to see risk assessments and controls.
Where to go for more
Review your current backup vendor contracts and confirm you have a signed BAA on file. If not, address this immediately. Then audit what data is actually being backed up. Many organizations find they're either backing up more ePHI than they realized or missing critical systems.
Your next risk analysis under 45 CFR § 164.308(a)(1)(ii)(A) should include an evaluation of your backup and recovery capabilities. Test your restore process at least annually. A backup you can't restore is just expensive storage.



