
FTP Today serves many firms within the medical industry that fall under HIPAA regulations. We are therefore sensitive to your HIPAA compliance issues. For example, many medical transcription companies, use FTP Today to transfer voice and text files on a daily basis.
According to the Department of Health and Human Services, FTP Today is not considered a HIPAA Business Associate: See HHS website, where it states:
"Other Situations in Which a Business Associate Contract Is NOT Required.
With a person or organization that acts merely as a conduit for protected health information, for example, the US Postal Service, certain private couriers, and their electronic equivalents."
That said, FTP Today offers multiple safeguards to our HIPAA sensitive customers, including:
- Our servers are all located in highly secure data centers, thereby making it impossible for equipment (such as a hard drive containing medical data) to be stolen. In addition, as required by HIPAA regulations, our data center is SAS-70 certified.
- No copies of your files reside on any offsite or long-term storage media . Also, our backup procedures have been carefully designed with privacy in mind.
- We do not host on the Windows operating system, as Windows servers are constantly under attack and are much more vulnerable than Linux servers. In addition, we use only enterprise grade Linux operating systems.
- FTP username and password is required . Our servers do not accept Anonymous-FTP connections, a common hacker method of seeking out an FTP site for possible attack.
- We host our secure FTP sites behind highly secure firewalls.
- Passwords are hashed in our server authentication database .
Password creation and maintenance is your responsibility. We recommend that you make all passwords difficult to crack and follow reasonable standards for password security and we provide a setting for you to Require Strong Passwords.
Important Note - Since you choose your own passwords, this means that FTP Today is not responsible for disclosure of private informaton in the event your assigned username/password combinations are cracked by some third party.
See http://en.wikipedia.org/wiki/Password_cracking for more information on password cracking.
- We offer the use of up to 256-bit encryption during transfer via industry-standard methods such as FTPS and SFTP.
FTP Today gives you the ability to force 100% your users to connect via an encrypted protocols (no extra charge with encrypted services).
Disclaimers:
- FTP Today is not considered a "covered entity" nor a "HIPAA Business Associate" and is not itself subject to HIPAA regulations. The official HIPAA agency website references companies like FTP Today as NOT being business associates:
http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/businessassociates.html
- FTP Today considers its services "HIPAA Ready," and proper use of the tools we provide should meet your needs of HIPAA compliance, however you should consult your own attorney in that regard. This information is general in nature and should not be relied upon as legal advice. We also recommend a look at http://www.hipaadvisory.comAny site hosted by FTP Today is subject to the terms and conditions, acceptable use and privacy policy, as posted on this website.