{hubspot_owner_id=}

A Guide to HIPAA & PCI Compliant Hosting

Which Web host is right for your site containing PHI or credit cards? The easy answer is the hosting service that best suits your site’s needs for the best price. Finding the right Web host begins by asking the right questions. So, which Web host will best meet your site’s needs?

Click here to download our Guide to HIPAA Complaint Hosting.

Identify Your Needs:

  • How many visitors does your current website have? If you don’t have a website yet, how many visitors do do you anticipate it having?
  • Is your website simple and static or does it have a lot of pictures, videos, and features?

Hosting Rules for PCI and HIPAA Compliance:

  • Your site cannot be hosted on a shared server.
  • Elements on the servers and your application must be locked down.
  • Ongoing maintenance and intrusion detection are required.

Local or National:

While some tend to be skeptical of smaller hosting companies, a good hosting company will be easy to vet. The advantage of hosting with a HIPAA/PCI certified host is that they already know your obligations and have the experience. Vetting a national hosting company may have more road blocks. When vetting a Web hosting company, be sure to ask:

  • What is the stability?
  • What is the platform?
  • Do you have local servers onsite or is it hosted virtually?
  • How will you secure my data?
  • What other companies do you provide HIPAA/PCI Hosting for?

With basic packages offered on national sites, “They are only offering a garage for your website, not the mechanic.” said Chris Kostelec, CWS Web Developer. Yet, if your site is basic (no e-commerce, PHI, etc), fairly static, and you plan to update and maintain it yourself, a national host may be the right answer. It may be cheaper and just as stable overall.

Keep in mind that base packages offered by large, national companies may have hundreds of websites or more on a single shared server. If your site has excessive content or traffic, it may go down due to lack of bandwidth. “Unlimited” storage limits may be reached fast. Large companies also tend to have greater security vulnerabilities.

Identifying your needs and what type of company can best meet them is the challenging part. All there is to do now is to find the best value that offers the level of service you want. If you have questions about the requirements for HIPAA hosting or PCI compliant hosting, feel free to contact us!

 Downl