If I require a data center to be hippa certified but instead they show me their sas70; is that also valid, meaning does SAS70 make up for hippa now days?
Spudstr replied: there is no HIPPA certification for a datacenter, your solution itself needs to be HIPPA compliant. The datacenters role is to simply show you the procedures for security, maintenance of UPS/gensets etc/related.
SAS70 is basically an audit of controls and procedures that are put in place on its operations. So yes sure. Parts of SAS70 can be used since most of the information is or should be already documented.
Kusai replied: Most facilities you will see as "compliant" and not certified as the standards keep changing frequently.
KarlZimmer replied: And because there is no such thing as a HIPAA certification for data centers…
For more information click
here.
- Tags: audit, certification, click, compliant, datacenter, gensets, HIPPA, information, Kusai, maintenance, now days, role, SAS, sas70, security, solution, Spudstr, ups