Preservica Logo

Hello, how can we help?

Menu

Blogs & News

Preservica strengthens HIPAA compliance program with independent assessment

Martyn Simpson • October 8, 2026

Martyn Simpson, Preservica CISO shares the latest updates on our HIPAA compliance program.

With growing demand from our government and private Healthcare customers in the US, we have further strengthened our HIPAA compliance program with an independent assessment of Preservica’s HIPAA Security and Privacy safeguards conducted by a leading cyber security and compliance firm.

The assessment provides an additional layer of confidence to healthcare organizations, university medical centers, state health and human services departments and research teams storing or wanting to store electronic Protected Health Information (ePHI) in Preservica. HIPAA compliance is also subject to both the customer and Preservica signing a Business Associate Agreement (BAA).

HIPAA-Ready Archiving and Active Digital Preservation

Preservica’s HIPAA-Ready Archiving and Active Digital Preservation platform goes beyond conventional archiving by ensuring that long-term ePHI, research and business records are not only securely protected in line with HIPAA technical, administrative and physical safeguards but also automatically maintained in readable and actionable file formats over decades. 

This ensures a fast and trusted response to Release of Information requests, malpractice claims, regulatory audits, continuity of care, major investigations, and leveraging information for long-term research value.

The Preservica platform is also enabling healthcare organizations to: 

  • Decommission legacy systems while keeping patient records accessible over decades for continuity of care and malpractice defence
  • Reduce cost and clutter in operational records systems by moving inactive patient records and larger files to lower cost preservation storage
  • Securely retain ePHI for research and long-term value
  • Speed up Release of Information requests - cut manual multi-day retrievals to easy one-click search and instant viewing of trusted records

You can access a detailed summary of our HIPAA safeguards on the Preservica Trust Center  (along with our Security reports and certifications for ISO 27001, SOC 2 and HECVAT, ISO 9001 Quality certification and our alignment with the ISO 14721 OAIS (Open Archival Information System) standard). 

I have also included a summary of Preservica’s core HIPAA safeguards below:

  • Data encryption: at rest and in transit 
  • Data immutability & integrity: once ingested, files cannot be altered or deleted (without two-stage authorization). Every file is fixity checked and regular integrity reports run to prevent file corruption or tampering  
  • Access controls:  support for MFA (Multi-Factor Authentication) and granular, role-based access permissions ensure only authorized individuals can view ePHI
  • Audit logging: The software maintains customer immutable audit trails of who has viewed which folders and assets and when - for Entity Access Reporting 
  • Retention Management & Legal Hold: consistent enforcement of records governance across the archive including defensible disposition actions
  • Long-term data accessibility: files are automatically maintained in readable and actionable formats over decades to ensure rapid response to Release of Information requests, malpractice claims, regulatory audits, investigations or for research value
  • Administrative: Preservica runs an active program of HIPAA specific staff training, policies and risk assessments

Learn more:

Start preserving your digital content today

Upload, preserve, organize and share your content and records online - in minutes.