is the icloud Hipaa compliant?

is the icloud Hipaa compliant?

iCloud-OTHER, iOS 5

Posted on Nov 9, 2011 12:02 PM

Reply
3 replies

Nov 9, 2011 1:28 PM in response to stephaniefromtucson

You will probably want to consult with your lawyer on this, but my take on it is no.


To be specific, while I generally trust that Apple and most cloud services will do their best to protect the privacy of the info stored on their system, in general, you want to have a "HIPAA Business Associate Agreement" with any vendor you do business with that will have access to Personal Health Information. (PHI) This is to ensure that the vendor will assume some or all of the liability in case of a "fault" on their end. For a "consumer" (non-enterprise) type of system like iCloud, this might not be possible. And per the iCloud Term and Conditions, Apple has left open the possibility that your data may get stored on a server that is not physically in the USA. So that complicates the liability depending on the laws of the other country.


What my company has generally been told is that without the HIPAA Business Associate Agreement, then you (or your company) will assume all liability, rather than the cloud vendor. But we could use a service like this without the agreement as long we take care of the HIPAA compliance on our own. For example, if we were to rent a car to transport a flash drive with PHI on it, we don't need a Business Associate Agreement with the rental ageny if we encrypt the data on the flash drive. Thus we took care of the security of the data (and thus be HIPAA compliant,) rather than having the car rental agency be responsible for the security of the data. Again, you'll want to consult with your lawyers.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

is the icloud Hipaa compliant?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.