Health systems, practice groups, and healthcare technology vendors across Southeast Michigan are under growing pressure to modernize their infrastructure without compromising patient data protection. For many, that means moving servers out of an undersized closet or an aging on-site room and into a purpose-built colocation facility. But healthcare data isn’t like other workloads. Choosing where it lives is a decision with real regulatory weight behind it.
If your organization is a HIPAA covered entity or business associate, the responsibility for protecting electronic protected health information (ePHI) doesn’t disappear when you move infrastructure off-site. It shifts into a shared responsibility model, and the facility you choose becomes part of your compliance posture. Here’s what to evaluate before signing a colocation agreement.
A colocation provider is not automatically “HIPAA compliant” simply by hosting healthcare workloads, and no data center can make that claim on your behalf. HIPAA compliance is an organizational responsibility that covers your policies, your access controls, your workforce training, and your business associate agreements (BAAs), in addition to physical infrastructure. What a colocation facility can do is provide the physical and environmental safeguards your compliance program depends on, and sign a BAA acknowledging its role in protecting ePHI that resides in its space.
When evaluating a colocation partner, the right question isn’t “are you HIPAA certified” (no such blanket certification exists), it’s “can you support the physical, administrative, and audit requirements my compliance program needs, and will you sign a BAA that reflects that.”
The HIPAA Security Rule requires physical safeguards for any facility housing systems that store or transmit ePHI. When touring or evaluating a colocation facility, look for:
If a colocation provider has the ability to access, view, or maintain systems that store ePHI, even indirectly through facility staff with data hall access, they meet the definition of a business associate under HIPAA and need a signed BAA in place. A colocation partner that hesitates to sign one, or doesn’t understand why you’re asking, is a signal to look elsewhere. Ask specifically what the BAA covers: physical access, incident notification timelines, and how the facility supports your own breach notification obligations under HITECH.
The HITECH Act strengthened HIPAA’s enforcement teeth and introduced breach notification requirements that put a clock on how quickly incidents must be reported. If your colocation facility experiences a physical security incident, unauthorized access, or environmental event that could affect your systems, you need contractual assurance that you’ll be notified fast enough to meet your own downstream reporting obligations to patients, HHS, and in some cases the media. Ask prospective partners for their incident notification SLA in writing, not as a verbal assurance during a sales call.
Organizations evaluating colocation partners right now should be aware that HHS has proposed the first major overhaul of the HIPAA Security Rule since 2013. The proposed changes would eliminate the current distinction between “required” and “addressable” safeguards, making protections like encryption and multi-factor authentication mandatory rather than optional, and would introduce stricter incident notification and technical testing requirements. As of this writing, the rule remains proposed and has not been finalized, but the direction is clear enough that healthcare organizations and their infrastructure partners should be planning for stricter, more standardized security expectations regardless of the exact final compliance date.
This makes facility due diligence more important, not less. A colocation partner that already operates with strong physical access controls, audit logging, and documented security practices will make your organization’s transition to any updated Security Rule requirements considerably smoother than one you have to push to catch up.
Beyond the compliance checklist, healthcare organizations benefit from colocation facilities that offer carrier-neutral connectivity (so you’re not locked into a single network provider for systems that need to stay online), Tier III-grade power redundancy, and proximity that supports low-latency access for clinical applications and disaster recovery scenarios. A facility in Southeast Michigan serving the Detroit, Ann Arbor, and greater Oakland and Wayne County markets gives regional health systems and healthcare technology vendors a local option that reduces latency and simplifies site visits and audits, compared to hosting infrastructure with an out-of-state provider.
Choosing a colocation partner for healthcare data is ultimately about finding a facility that treats physical security and documentation with the same seriousness your compliance team does. Ask direct questions, get commitments in writing, and make sure a BAA is on the table before you move a single server.