By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    photo of hands with blue veins
    8 Proven Tips on Finding Difficult Veins
    November 12, 2021
    tips for getting over the pandemic blues
    4 Proven Ways to Get Over the Pandemic Blues
    February 22, 2022
    medical industry innovations
    How is CNC Machining Transforming the Medical Industry?
    June 2, 2022
    Latest News
    The Wide-Ranging Benefits of Magnesium Supplements
    June 11, 2025
    The Best Home Remedies for Migraines
    June 5, 2025
    The Hidden Impact Of Stress On Your Body’s Alignment And Balance
    May 22, 2025
    Chewing Matters More Than You Think: Why Proper Chewing Supports Better Health
    May 22, 2025
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    Transformational and Disruptive Changes Are Coming to the Delivery System
    July 22, 2012
    Telemedicine and the PCP Cliff
    November 30, 2012
    Engaging Specialty Practices in the Patient Centered Medical Neighborhood
    March 24, 2013
    Latest News
    Streamlining Healthcare Operations: How Our Consultants Drive Efficiency and Overall Improvement
    June 11, 2025
    Building Smarter Care Teams: Aligning Roles, Structure, and Clinical Expertise
    May 18, 2025
    The Critical Role of Healthcare in Personal Injury Recovery: A Comprehensive Guide for Victims
    May 14, 2025
    The Backbone of Successful Trials: Clinical Data Management
    April 28, 2025
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Attn, Healthcare Industry: SAS 70 is No Zombie
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Attn, Healthcare Industry: SAS 70 is No Zombie
eHealth

Attn, Healthcare Industry: SAS 70 is No Zombie

onlinetech
Last updated: September 18, 2013 8:00 am
onlinetech
Share
4 Min Read
SAS 70 is never coming back. Unlike this zombie.
SHARE
SAS 70 is never coming back. Unlike this zombie.

SAS 70 is never coming back. Unlike this zombie. Source: wikiHow

SAS 70 is never coming back. Unlike this zombie.

SAS 70 is never coming back. Unlike this zombie. Source: wikiHow

Although SAS 70 (Statement on Auditing Standards) has been dead for quite some time now, we’ve found that those lagging in the health IT industry may still be confused about why SAS 70 is no longer the audit to look for when it comes to ensuring security with a cloud hosting provider. In fact, false information about SAS 70 as a qualifier for cloud computing security supporting the healthcare industry is still an issue.

Some suggest that SAS 70 is comparable to a HIPAA audit because they both check for an organization’s security controls. However, SAS 70 was never designed to measure data center security, but instead to measure internal controls related to financial reporting.

As major research firm Gartner stated, “SAS 70 is being misused by many vendors, and often their customers and certified public accountants (CPAs), in the hosted-application, software as a service (SaaS) and cloud computing spaces.”

So what’s better than SAS 70? Some say SSAE 16 (Statement on Standards for Attestation Engagements), which replaced the standard in 2011. But even an SSAE 16 report only reports on controls related to financial reporting, and not on controls directly related to data center privacy, security and availability.

Here’s where a SOC 2 (Service Organization Control) audit report comes in to save the day and confirm that your service provider has all of the best internal practices in place for these five controls: Security, Availability, Processing Integrity, Confidentiality and Privacy. Why choose a SOC 2 report over SOC 3? A SOC 2 report is more detailed, and affects companies that host or store large amounts of data, such as cloud hosting and data center operators.

So a SOC 2 report may suffice for most seeking an audit report that most accurately reflects a cloud hosting provider’s internal security controls. But for those in the healthcare industry dealing with patient data, there’s one step even further to ensure security with cloud hosting providers.

Look for a HIPAA compliant hosting provider that has a third-party independent audit report of their company’s controls against the OCR (Office for Civil Rights) HIPAA Audit Protocol. Ask them which requirements they can fulfill to satisfy the IT side of the HIPAA standards.

On the administrative side, ask them if and when they last completed HIPAA staff training as a business associate, and whether or not they will sign a business associate agreement (BAA) clarifying their role and responsibilities when it comes to your data security. This HIPAA Compliant Hosting white paper explains the IT infrastructure and administrative sides completely.

SAS 70 is so dead. And definitely needs to be laid to rest. Don’t let it become an audit zombie. Just let it go and embrace the future of SOC 2 and independent HIPAA audits.

References:
Gartner Says SAS 70 Is Not Proof of Security, Continuity or Privacy Compliance

 

TAGGED:healthITSAS 70
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

Streamlining Healthcare Operations: How Our Consultants Drive Efficiency and Overall Improvement
Global Healthcare Policy & Law
June 11, 2025
magnesium supplements
The Wide-Ranging Benefits of Magnesium Supplements
Health
June 11, 2025
Preparing for the Next Pandemic: How Technology is Changing the Game
Technology
June 6, 2025
migraine home remedies and-devices
The Best Home Remedies for Migraines
Health Mental Health
June 5, 2025

You Might also Like

Harmful Drug Reactions Get Help from Automated Follow-Ups

February 14, 2013
Image
eHealth

‘Luddite Approach’ to Telemedicine

June 14, 2012
medicare fraud
Health ReformHome HealthHospital AdministrationMedical EthicsMedical RecordsNewsPolicy & LawPublic Health

Keeping an Eye Out for Medical Fraud

December 16, 2013
social media healthcare
eHealthMobile HealthPolicy & LawPublic HealthSocial MediaSpecialtiesTechnology

Diabetes and Oncology at Doctors 2.0 & You

April 30, 2013
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?