By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    HIPPA compliance
    How Medical Office Staff Can Make Your Practice HIPAA Compliant
    October 29, 2021
    Everything you need to know about hyaluronic acid treatment
    Everything you need to know about hyaluronic acid treatment
    February 10, 2022
    Which Mushroom Capsules Are Good for Your Health?
    May 5, 2022
    Latest News
    Why Custom Telemedicine Apps Outperform Off‑the‑Shelf Solutions
    July 20, 2025
    How Probate Planning Shapes the Future of Your Estate and Family Care
    July 17, 2025
    Beyond Nutrition: Everyday Foods That Support Whole-Body Health
    June 15, 2025
    The Wide-Ranging Benefits of Magnesium Supplements
    June 11, 2025
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    Image
    Healthcare Pricing Transparency Gains Momentum
    June 24, 2013
    non-clinical care factors in health outcomes
    Addressing Non-Clinical Care Factors in Health Outcomes
    November 15, 2013
    e interventions
    Healthcare Progress Depends On “E Interventions”
    July 10, 2014
    Latest News
    How IT and Marketing Teams Can Collaborate to Protect Patient Trust
    July 17, 2025
    How Health Choices and Legal Actions Intersect After an Injury
    July 17, 2025
    How communities and healthcare providers can address slip and fall injuries with legal awareness
    July 17, 2025
    Let Your Lawyer Handle the Work Before You Pay Medical Costs
    July 6, 2025
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Attn, Healthcare Industry: SAS 70 is No Zombie
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Attn, Healthcare Industry: SAS 70 is No Zombie
eHealth

Attn, Healthcare Industry: SAS 70 is No Zombie

onlinetech
onlinetech
Share
4 Min Read
SAS 70 is never coming back. Unlike this zombie.
SHARE
SAS 70 is never coming back. Unlike this zombie.

SAS 70 is never coming back. Unlike this zombie. Source: wikiHow

SAS 70 is never coming back. Unlike this zombie.

SAS 70 is never coming back. Unlike this zombie. Source: wikiHow

Although SAS 70 (Statement on Auditing Standards) has been dead for quite some time now, we’ve found that those lagging in the health IT industry may still be confused about why SAS 70 is no longer the audit to look for when it comes to ensuring security with a cloud hosting provider. In fact, false information about SAS 70 as a qualifier for cloud computing security supporting the healthcare industry is still an issue.

Some suggest that SAS 70 is comparable to a HIPAA audit because they both check for an organization’s security controls. However, SAS 70 was never designed to measure data center security, but instead to measure internal controls related to financial reporting.

As major research firm Gartner stated, “SAS 70 is being misused by many vendors, and often their customers and certified public accountants (CPAs), in the hosted-application, software as a service (SaaS) and cloud computing spaces.”

So what’s better than SAS 70? Some say SSAE 16 (Statement on Standards for Attestation Engagements), which replaced the standard in 2011. But even an SSAE 16 report only reports on controls related to financial reporting, and not on controls directly related to data center privacy, security and availability.

Here’s where a SOC 2 (Service Organization Control) audit report comes in to save the day and confirm that your service provider has all of the best internal practices in place for these five controls: Security, Availability, Processing Integrity, Confidentiality and Privacy. Why choose a SOC 2 report over SOC 3? A SOC 2 report is more detailed, and affects companies that host or store large amounts of data, such as cloud hosting and data center operators.

So a SOC 2 report may suffice for most seeking an audit report that most accurately reflects a cloud hosting provider’s internal security controls. But for those in the healthcare industry dealing with patient data, there’s one step even further to ensure security with cloud hosting providers.

Look for a HIPAA compliant hosting provider that has a third-party independent audit report of their company’s controls against the OCR (Office for Civil Rights) HIPAA Audit Protocol. Ask them which requirements they can fulfill to satisfy the IT side of the HIPAA standards.

On the administrative side, ask them if and when they last completed HIPAA staff training as a business associate, and whether or not they will sign a business associate agreement (BAA) clarifying their role and responsibilities when it comes to your data security. This HIPAA Compliant Hosting white paper explains the IT infrastructure and administrative sides completely.

SAS 70 is so dead. And definitely needs to be laid to rest. Don’t let it become an audit zombie. Just let it go and embrace the future of SOC 2 and independent HIPAA audits.

References:
Gartner Says SAS 70 Is Not Proof of Security, Continuity or Privacy Compliance

 

TAGGED:healthITSAS 70
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

botox certification
Help Improve People’s Skin Health Via Botox Certification
Skin Specialties
July 22, 2025
Telemedicine Apps
Why Custom Telemedicine Apps Outperform Off‑the‑Shelf Solutions
Health
July 20, 2025
Grounded Healing: A Natural Ally for Sustainable Healthcare Systems
How IT and Marketing Teams Can Collaborate to Protect Patient Trust
Global Healthcare Policy & Law
July 17, 2025
paramedics in surgical gloves and masks
How Health Choices and Legal Actions Intersect After an Injury
Health care
July 16, 2025

You Might also Like

HealthEdge COO Desrochers on ICD-10 (transcript)

February 23, 2011
Image
Global HealthcareMobile Health

Mobile Health Around the Globe

March 12, 2012
ADA compliance
BusinesseHealth

Making a Physician Website ADA-Compliant Can Increase Your Bottom Line

March 3, 2014

ACA Success Stories Social Media Campaign: Marketing Hit or Miss?

February 2, 2014
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?