“HIPAA compliant” shows up on a lot of vendor proposals. It is one of the most repeated phrases in healthcare IT, and one of the least checked. Most of the time, what it is actually describing is the datacenter the vendor rents space in, not the vendor itself.
Those are two different things, and the difference matters the day something goes wrong.
A datacenter’s compliance is not your vendor’s compliance
A datacenter can hold real certifications for its physical security, its power redundancy, and its network infrastructure. That is a legitimate, checkable fact. What it does not cover is how the vendor sitting inside that datacenter actually handles your patient data day to day: who has access, how backups are tested, what happens when an employee leaves, and how quickly a problem gets reported if one happens.
A vendor can host everything in a fully compliant datacenter and still have no real process for any of that. The datacenter’s certification does not transfer to them automatically, and it is not a substitute for their own practices.
The questions that expose the gap
- Will you sign a Business Associate Agreement, in writing, before any data changes hands
- Who on your team can access our patient data, and how is that access reviewed
- What is your actual process the day a breach or a suspected breach happens
- How often are backups tested, not just scheduled
- What happens to our data and our access the day we stop being a client
A vendor with real practices in place answers these quickly and specifically. A vendor leaning on their datacenter’s certification tends to answer in general terms, or points back to the datacenter’s paperwork instead of their own.
What good actually looks like
A vendor that takes this seriously treats it as an ongoing responsibility, not a one-time checkbox. Access gets reviewed on a schedule. Backups get tested, not just run. There is a real, written incident response plan, and someone can tell you what it is without pulling up a document they have not looked at in a year.
None of that is exotic. It is just the difference between a vendor who built their process around handling patient data, and one who is hoping the datacenter’s certification covers for them if anyone ever asks.