Atlantic.Net is a cloud hosting and managed infrastructure provider offering cloud servers, dedicated hosting, data storage, backup, disaster recovery, and compliance-focused hosting environments.
With Atlantic.Net, healthcare organizations can host applications and systems that store, process, or transmit electronic protected health information (ePHI).
Is Atlantic.Net HIPAA compliant? Yes, Atlantic.Net can be HIPAA compliant.
What changed this year?
As of July 2026, our review did not identify any publicly disclosed changes to Atlantic.Net’s HIPAA-related policies or business associate agreement (BAA) terms.
Will Atlantic.Net sign a BAA?
Yes, Atlantic.Net will sign a BAA. Its public BAA overview can be reviewed here, while a copy of the agreement must be requested from Atlantic.Net’s sales department.
Atlantic.Net states that a BAA is available as a standard part of its HIPAA hosting offering.
What does the Atlantic.Net BAA cover?
The Atlantic.Net BAA covers the company’s responsibilities when it stores, manages, processes, or otherwise handles PHI on behalf of a healthcare customer.
Its BAA overview states that Atlantic.Net agrees to “[n]ot disclose PHI, except as permitted by law.”
According to Atlantic.Net, its BAA covers:
- Compliance with applicable HIPAA Privacy and Security Rule requirements
- A HITECH-compliant hosting environment
- Permitted uses and disclosures of PHI
- Documentation of the PHI Atlantic.Net transfers, processes, or archives
- Technical safeguards such as encryption, VPNs, firewalls, and disaster recovery
- Escalation procedures for ePHI breach notifications
- Access to relevant policies and logs when requested by HHS
- Return or destruction of ePHI when the relationship ends, when feasible
- Appropriate agreements with subcontractors providing in-scope services
What does the Atlantic.Net BAA exclude?
Atlantic.Net does not publish its complete BAA online, so customers should review the executed agreement for service-specific exclusions.
However, the company’s public materials make clear that HIPAA coverage does not automatically apply to every standard hosting plan. Its cloud platform page states, “These plans do not include HIPAA Compliant Hosting.”
The BAA also does not transfer every compliance responsibility to Atlantic.Net. The company states, “A HIPAA server alone does not make you HIPAA-compliant.” Customers remain responsible for areas such as application security, user access, workforce policies, risk assessments, and the appropriate use of PHI.
Conclusion
Atlantic.Net may be HIPAA compliant, but only when an organization uses an eligible HIPAA hosting plan, signs a BAA, and properly secures the applications and operations under its control.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information, known as PHI.
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
