Signed Business Associates’ Agreement (BAA): Healthcare vendors must sign a business associates’ agreement (BAA) with the public cloud provider. This agreement dictates how HIPAA security responsibilities are managed by the cloud provider and the cloud customers.
Access Control: Any databases that will be used with protected health information (PHI) must have necessary access control security implemented. This means that user authentication and roles must be in place.
Backup and Disaster Recovery (DR): HIPAA requires that organizations implement backup and around disaster recovery (DR) procedures in-case of service outage.
Audit Logging: HIPAA compliant databases must log queries and access to PHI to detect potential malicious activity.
Encryption: PHI must be encrypted both at-rest and in-transit. This means that data must be stored on encrypted volumes and transmitted over TLS/SSL.
Staff Training: Organizations set compliance roles and provide HIPAA training for staff members.