Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Is Symantec Online Storage HIPAA Compliant?

Updated: 02 Mar 2009
Ted_Migdal's picture
0 0 Votes
Login to vote

While there is no standard HIPAA certificate of compliance for online backup services, Symantec Protection
Network (SPN) enables HIPAA defined covered entities that must store &protect electronic patient data comply with HIPAA security and privacy rules by:


  • Encrypting data at the point of origin, during the backup process, using 256-bit AES
    (approved by the NSA for encrypting U.S. classified data up to and
    including Top Secret).
  • Encryption key is private which only the originator (not even Symantec) has access
  • All information is sent through a secure 128-bit SSL tunnel to one of the
    Symantec datacenters.
  • Symantec data centers and operations are SAS-70 Type II certified.  
    Additionally SPN follows an ISO 17799 / 27002 security framework and ITIL
    Service Management framework.