By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    improving patient experience
    6 Ways to Improve Patient Satisfaction Within Hospitals
    December 1, 2021
    degree for healthcare job
    What Are The Health Benefits Of Having A Degree?
    March 9, 2022
    custom software development is changing healthcare
    Digital Customer Journey Mapping and its Importance for Healthcare
    July 21, 2022
    Latest News
    Grounded Healing: A Natural Ally for Sustainable Healthcare Systems
    May 16, 2025
    Learn how to Renew your Medical Card in West Virginia
    May 16, 2025
    Choosing the Right Supplement Manufacturer for Your Brand
    May 1, 2025
    Engineering Temporary Hospitals for Extreme Weather
    April 24, 2025
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    healthcare elderly
    The Human Side of the Sequestration
    June 19, 2013
    Contagion Is Real
    October 7, 2011
    Is Patient Privacy Endangered by Online Search?
    July 12, 2013
    Latest News
    The Critical Role of Healthcare in Personal Injury Recovery: A Comprehensive Guide for Victims
    May 14, 2025
    The Backbone of Successful Trials: Clinical Data Management
    April 28, 2025
    Advancing Your Healthcare Career through Education and Specialization
    April 16, 2025
    Do Abuse Reporting Systems in Assisted Living Protect Residents’ Health?
    April 15, 2025
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Attn, Healthcare Industry: SAS 70 is No Zombie
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Attn, Healthcare Industry: SAS 70 is No Zombie
eHealth

Attn, Healthcare Industry: SAS 70 is No Zombie

onlinetech
Last updated: September 18, 2013 8:00 am
onlinetech
Share
4 Min Read
SAS 70 is never coming back. Unlike this zombie.
SHARE
SAS 70 is never coming back. Unlike this zombie.

SAS 70 is never coming back. Unlike this zombie. Source: wikiHow

SAS 70 is never coming back. Unlike this zombie.

SAS 70 is never coming back. Unlike this zombie. Source: wikiHow

Although SAS 70 (Statement on Auditing Standards) has been dead for quite some time now, we’ve found that those lagging in the health IT industry may still be confused about why SAS 70 is no longer the audit to look for when it comes to ensuring security with a cloud hosting provider. In fact, false information about SAS 70 as a qualifier for cloud computing security supporting the healthcare industry is still an issue.

Some suggest that SAS 70 is comparable to a HIPAA audit because they both check for an organization’s security controls. However, SAS 70 was never designed to measure data center security, but instead to measure internal controls related to financial reporting.

As major research firm Gartner stated, “SAS 70 is being misused by many vendors, and often their customers and certified public accountants (CPAs), in the hosted-application, software as a service (SaaS) and cloud computing spaces.”

So what’s better than SAS 70? Some say SSAE 16 (Statement on Standards for Attestation Engagements), which replaced the standard in 2011. But even an SSAE 16 report only reports on controls related to financial reporting, and not on controls directly related to data center privacy, security and availability.

Here’s where a SOC 2 (Service Organization Control) audit report comes in to save the day and confirm that your service provider has all of the best internal practices in place for these five controls: Security, Availability, Processing Integrity, Confidentiality and Privacy. Why choose a SOC 2 report over SOC 3? A SOC 2 report is more detailed, and affects companies that host or store large amounts of data, such as cloud hosting and data center operators.

So a SOC 2 report may suffice for most seeking an audit report that most accurately reflects a cloud hosting provider’s internal security controls. But for those in the healthcare industry dealing with patient data, there’s one step even further to ensure security with cloud hosting providers.

Look for a HIPAA compliant hosting provider that has a third-party independent audit report of their company’s controls against the OCR (Office for Civil Rights) HIPAA Audit Protocol. Ask them which requirements they can fulfill to satisfy the IT side of the HIPAA standards.

On the administrative side, ask them if and when they last completed HIPAA staff training as a business associate, and whether or not they will sign a business associate agreement (BAA) clarifying their role and responsibilities when it comes to your data security. This HIPAA Compliant Hosting white paper explains the IT infrastructure and administrative sides completely.

SAS 70 is so dead. And definitely needs to be laid to rest. Don’t let it become an audit zombie. Just let it go and embrace the future of SOC 2 and independent HIPAA audits.

References:
Gartner Says SAS 70 Is Not Proof of Security, Continuity or Privacy Compliance

 

TAGGED:healthITSAS 70
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

Grounded Healing: A Natural Ally for Sustainable Healthcare Systems
Grounded Healing: A Natural Ally for Sustainable Healthcare Systems
Health
May 15, 2025
Learn how to Renew your Medical Card in West Virginia
Learn how to Renew your Medical Card in West Virginia
Health
May 15, 2025
Dr. Klaus Rentrop Shares Acute Myocardial Infarction heart treatment
Dr. Klaus Rentrop Shares Acute Myocardial Infarction
Cardiology
May 13, 2025
The Critical Role of Healthcare in Personal Injury Recovery: A Comprehensive Guide for Victims
The Critical Role of Healthcare in Personal Injury Recovery: A Comprehensive Guide for Victims
Health care
May 13, 2025

You Might also Like

American Telemedicine Association Criticizes the FCC

August 21, 2012
eHealthHealth ReformMedical InnovationsMedical RecordsTechnology

Can Big Data Analytics Make Telemedicine More Functional?

December 13, 2017
TEDMED Great Challenges Barbara Ficarra YouTube Improving Medical Communication
eHealthSocial Media

TEDMED Great Challenges: Improving Medical Communication-Sound Bites for Twitter

March 6, 2013
health and technology
eHealthMedical DevicesMedical InnovationsTechnology

Technology and Healthcare Efficiency: Not Always the Perfect Match

June 21, 2014
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?