Explore our Topics:

“HIPAA compliant” is a claim. “Audit-defensible” is a storage capability. Here’s the difference.

OCR auditors want evidence from systems, not contracts. Five questions that test your provider's HIPAA-compliant hosting claims.
Sponsored
By admin
Aug 7, 2026, 2:12 PM

This article is part of a series, sponsored by Nexcess, examining the risks specialty practices face when AI and other IT implementations sit on infrastructure nobody is actively managing for compliance, security, or performance. This series names that gap, frames what it costs, and teaches leaders how to close it.

Your hosting contract probably says the environment supports HIPAA-regulated workloads. An auditor from the Office for Civil Rights won’t argue with that line, and won’t spend much time on it either. What they want is narrower and harder to produce: what a specific system held on a specific date, and who touched it along the way. A contract can’t answer that, so the answer has to come from the systems underneath it. 

That gap is hard to see during evaluation and procurement, because the compliance language on a vendor’s website rarely maps to anything an examiner can inspect. OCR wants evidence from the systems themselves, not from the paperwork describing them. 

OCR’s audit protocol is organized by rule and provision, and every document request covers the version in use on the date of the audit notice. That reaches the Business Associate Agreement, the record of who held access to which system, and proof that the control was operating at the time. The Security Rule’s contingency plan standard goes further, requiring retrievable exact copies of ePHI and procedures for testing the plan that produces them. 

Moving from legal shield to operational proof 

Many specialty networks treat a signed agreement with a hosting vendor as a legal shield that sits in a procurement file until something goes wrong. 

The practices that clear compliance reviews without drama treat the BAA as a baseline, backed by a matrix that says, system by system, who restores the patient portal database, who holds credentials to the digital intake storage, who rotates keys on the analytics warehouse, and who gets called when any of it fails on a Saturday night. 

During a review, a BAA without that matrix leaves a practice reconstructing ownership on the fly. The agreement allocates liability after a failure, but it can’t pull a verified system-state backup out of an unmanaged cloud environment when an examiner asks what the scheduling database held on the day of an incident. 

Audit defensibility lives in the storage architecture and in whether the recovery workflow has been tested recently enough to trust. 

The shift toward active documentation standards 

That expectation has widened as PHI has spread into patient portals, digital intake platforms, online scheduling, and remote monitoring tools sitting outside the clinical platform. When OCR settled four ransomware investigations in April 2026, covering more than 427,000 individuals and $1,165,000 in payments, the first item on its list of recommendations was identifying where ePHI sits, including how it enters, flows through, and leaves an organization’s systems. 

A policy manual describes intent, while the Security Rule’s audit controls standard requires mechanisms that record and examine activity in the systems holding ePHI. On the ground that means knowing which identity accessed protected health information, when, from which network, and what they did with it once they had it. 

Producing those logs gets difficult on standard cloud hosting, where secondary storage and automated backups for every application land in the same pool. A practice in that arrangement can restore a server, but it can’t isolate what the intake form database held at 4:15 p.m. on the Tuesday an examiner is asking about, and that timestamp is usually the entire question. 

Five diagnostic questions to test your infrastructure foundation 

Five questions separate a hosting environment that supports HIPAA-regulated workloads from one that only says so in the contract. The same answers do double duty in a first SOC 2 or HITRUST review, where the assessor wants the operating artifact rather than the policy describing it. 

  1. Responsibility Matrix Clarity: Does the provider explicitly state where their infrastructure management ends and your application security begins, including who’s responsible for configuring and verifying the daily backups of your edge databases? 
  2. Access Log Retention: How long are access logs from patient-facing intake systems retained, in what format do they export, and can a single date range be pulled for an examiner without a support ticket? 
  3. Operational BAA Depth: Does the agreement extend protections directly to the localized databases and backup environments orbiting the clinical platform?  
  4. Audit-Season Support: Is there a dedicated team available to assist with technical documentation and to rapidly execute data restoration tests when an active review occurs? 
  5. System Portability: Can your compliance records and historical backup archives be migrated or reviewed without forcing a full clinical platform outage?  

Providers answer these five differently, which is the reason to ask them. Nexcess describes their managed environments as infrastructure that supports HIPAA-regulated workloads, and that phrasing deserves the same test as any other vendor’s: ask which of the five they can demonstrate rather than describe. 

Most practices learn these answers during the review itself, on a timeline the examiner sets. The alternative costs an ordinary Tuesday: run a restoration test against the systems holding PHI outside the clinical platform, time it, and write down what came back. That one test tells you what no contract can: whether a backup that exists is also a backup that works. 


Michael Ohayon is a technology executive with 15+ years of experience scaling organizations from founder-led roots to mid-market enterprises in regulated industries. Known for operational discipline, he aligns mission-critical infrastructure with complex risk management and compliance frameworks. His background spans cloud infrastructure, cybersecurity, data resilience, and M&A integration, guiding teams to optimize efficiency, compliance, and secure customer outcomes. 


Show Your Support

Subscribe

Newsletter Logo

Subscribe to our topic-centric newsletters to get the latest insights delivered to your inbox weekly.

Enter your information below

By submitting this form, you are agreeing to DHI’s Privacy Policy and Terms of Use.