Requirement: Protect Data Privacy and Confidentiality of ePHI
All data is encrypted before being transmitted in any way, and is only stored or transmitted by NLS Backup in its encrypted form.
The encryption key (pass phrase) is only known to the covered entity and/or the NLS Backup partner. NLS Backup will never ask for, receive, or record the encryption key or pass phrase. This ensures that the data received and stored by NLS Backup cannot be decrypted, preventing disclosure of ePHI.
The data is encrypted using the AES-256-bit algorithm, which has been approved by the NSA for encrypting TOP SECRET data.
All data transmissions are encrypted with 128-bit AES using the standard TLS/SSL protocol. The identity of the receiving party (the NLS Backup data center) is authenticated using the public key of NLS Backup’s private certificate authority.
All access to NLS Backup accounts and their stored data are protected through password authentication. Passwords are only known to the customer and/or the NLS Backup partner.
All access to the account is recorded in an audit log. All actions that modify an account (uploading or destroying data) are recorded in the audit log.
Requirement: Protect Data Integrity of ePHI
NLS Backup is uniquely positioned to help companies comply with the data integrity requirement within their HIPAA contingency plans. Additional details of the below provisions are in our data integrity whitepaper.
Each data block is digitally signed with an HMAC [HMAC-SHA-256] to allow for automatic validation during restores that the data has not been altered or tampered with.
NLS Backup uses checksums on the data as it moves across the network, inside the NLS Backup servers and server software, through the operating system and device drivers, and all the way down to the final storage medium to ensure that the data remains perfectly intact and did not change while being transmitted from the client computer to the storage devices in our data centers.
NLS Backup uses high levels of data redundancy with redundant checksums to ensure that any silent data corruption is automatically detected and repaired using the redundant information.
The integrity of the data is checked when files change as well as through scheduled checks.
Requirement: Protect ePHI from Reasonably Anticipated Threats/Hazards
Physical Security: Our data centers are protected by 24/7/365 guards and CC surveillance, card-key access, biometrics, partitioned floor space with access control, and secure locking cabinets.
Network Security: We use multi-level firewalls and intrusion detection systems to filter/analyze all traffic. Access controls uniquely identify users and log all access.
NLS Backup’s infrastructure is fully fault tolerant. Measures include backup generators and UPS systems, redundant power feeds, fire detection and suppression, multi-homed connectivity, environmental monitoring, redundant storage controllers and connections, redundant server power supplies, stocked spare-parts, and 2-hour hardware replacement service contracts.
NLS Backup empowers partners to implement HIPAA contingency plans, without compromises.