4 ms·
Had to research this before. Firehost is one of the names that came up often: http://www.firehost.com/secure-hosting/hipaa http://www.firehost.com/secure-hosti
by keyist 16y ago
Had to research this before. Firehost is one of the names that came up often:
http://www.firehost.com/secure-hosting/hipaa http://www.firehost.com/secure-hosting/hipaa
Their plans start from $845 monthly.
No affiliation, just passing info along.
You can't just rely on the provider though. All the server hardening in the world wouldn't help with apps that don't comply fully. Some of the audit requirements are bound to be very specific to the nature of your app.
- thaumaturgy 16y agoI was curious what $845/month got you, so just for fun I looked. From the features part of that page: 1. Log Monitoring and Management: Not sure what they mean by this; surely it's something more complex than logrotate. Maybe rsyslog or something? 2. Continuous Vulnerability Monitoring: So, they follow the usual script sites & mailing lists. 3. Managed Anti-Virus Protection: I hope they aren't running on a Windows platform, and if they aren't, I'm not aware of very many current in-the-wild viruses for the various Linux distros. 4. 1 Gigabit Networking Infrastructure (Public and Private): Heh. 5. Two-Factor Authentication: I see this a bit, and it's usually mis-used. Unless they require you to physically submit a fingerprint, DNA sample, retinal image, or some other such thing, then it's not two-factor authentication. 6. Application and Database Server Isolation: They're running the application and the SQL instances on different servers, but if the application server gets compromised, then so does the SQL server, since the application needs automated credentials for the SQL server. 7. Managed SSL Service: Once a year they make sure your certificate is up-to-date. 8. Business Associate Agreement Friendly: What? 9. Managed Redundant Firewall Protection: Not sure what they mean by this. Either your firewall works, or it doesn't. Layering them doesn't do squat. If they mean that they have a hot spare ready to go in case of an outage, then that's a little better -- but still not that helpful if the app server or db server falls over for any reason. 10. Managed Redundant Web Application Protection (Port 80/443): What? 11. Managed Redundant DoS/DDoS Mitigation: This is nice, at least, since it requires a bit of infrastructure to do it right -- assuming that they can stand up to a multi-terabit-per-second hit, since that's what the botnets are packing these days. 12. Managed and Monitored Intrusion Detection: So, run-of-the-mill IDS + Nagios + remote logging. 13. Managed Proactive Operating System Security Patches: This is a lie unless they're personally writing and submitting patches. The most "proactive" you're likely to get otherwise is running a nightly update. 14. Managed Weekly Full Backups + Daily Differentials (Encrypted): I want to take just a moment here and toot our own horn: we do weekly fulls + daily differentials for our regular web hosting customers, for a heck of a lot less than $845 a month. They aren't currently encrypted, but that wouldn't be all that challenging to add on. 15: Highly Secure Data Center Environment: You can probably get the same "highly secure data center environment" from Rackspace, Hurricane Electric, or any of a number of other really big hosting providers. 16: VPN/SSL Provided for Server Management (RDP/SSH/FTP/SQL): Nice, but again, really not that hard to set up, especially for a turn-key environment. TL;DR: I'm really surprised both at what qualifies as "HIPAA compliant hosting" as well as at the price charged for it. I wonder if the bulk of the cost goes towards paperwork or some other kind of administrative overhead? I certainly don't see the price reflected in their technical offering.
- stoic 16y ago"Highly Secure Data Center Environment", but no SAS70 certification... hmm.
- firepowered 16y agoWe do have our SAS70 and know that SAS70 has nothing to do with real security. It's just controls that an organization sets and gets audited on. Also, the SAS70 is going away for the SSAE 16. Read more here: http://www.csoonline.com/article/622277/sas-70-replacement-ssae-16- http://www.csoonline.com/article/622277/sas-70-replacement-s...
- deleted 16y ago[deleted]
- RyanGWU82 16y agoI thought "Two-Factor Authentication" referred to an RSA SecurID or something similar. Am I wrong? Why do you say "it's usually misused"?
- thaumaturgy 16y agoA SecurID would work. ("Something you know, plus something you have or something you are.") The majority of the cases where I've seen it used so far are in websites or other services that are just asking you for a second piece of information you know -- like a challenge question, passphrase, or the like. ...it looks like Firehost is using Phone Factor (http://www.phonefactor.com/ http://www.phonefactor.com/) for their second factor authentication. I'm not sure what I think of that. On the one hand, it's marginally better than a password. On the other hand, it's only marginally better than a password. Unlike a SecurID, phones are pretty easy to compromise -- especially smart phones.
- Kadrith 16y agoThe issue I'd have with this setup is reception. In our Hospital there are a lot of places with little or no reception; Radiology and Lab are two main examples. Due to all of the lead they have around there is no signal. We had looked at iPhones for CC processing over cellular networks, but the lack of a consistent signal killed that. Which sucks because that would have been much easier and cheaper as a temporary solution than what we are doing now.
- firepowered 16y agoThis is absolutely correct. Your managed hosting company has a portion of the responsibility for HIPAA compliance which is why we say "Compliance Ready". An organization has to have their own application specific needs met, business and process controls, database table obfuscation, etc. etc. What's important is selecting a provider who has all the hosting needs met to achieve compliance with your auditor and will execute a business associate agreement as required. Best of luck with your search.