LUXSCI

HIPAA-compliant Secure Hosting

HIPAA Compliance

WordPress, LAMP

WordPress, CMS—LAMP Stack

  • Solid, reliable technology for popular platforms: WordPress, Joomla, Drupal, and others
  • Linux: CentOS
  • Apache 2.4.x
  • MySQL (actually MariaDB) 10.2.x
  • PHP v7.3.x (and Perl and Python)
  • Optimized for speed! Get 4+ GB RAM on your server

SSL/TLS Transport Encryption

Multiple Firewalls

  • Hardware or network firewall
  • On-server software firewall
  • Web-based software firewall management tools
  • Account-specific access control tools
  • Server monitoring integrated with the firewall
  • Optional: CloudFlare

VPN: Virtual Private Network

  • Connect yourself to LuxSci over a direct VPN
  • Secure MySQL and other client-server connections
  • Lock down management of your critical infrastructure
  • Discover: VPN Access

Enterprise Class Servers

  • Is maximum reliability critical for you?
  • Dedicated, encrypted SAN storage
  • Dedicated hypervisor cluster
  • VMWare vMotion keeps you up when hardware fails
  • Optional: Physical hardware, dedicated firewalls and load balancers

Custom Enterprise Solutions

Custom large-scale solutions

Custom solutions can be tailored for very large numbers of web sites, amounts of web traffic, high availability, high security, and business continuity. They can include:

  • Redundant high-availability dedicated hardware firewalls
  • Redundant high-availability dedicated load balancers
  • Network-based intrusion detection systems
  • DDOS Protection up to 100 Gbps
  • Redundant, load-balanced outbound email sending servers
  • Redundant, load-balanced web/application servers
  • Dedicated databases with replication and failover
  • System isolation and capacity scaling
  • Encrypted SAN storage arrays
  • Database replication
  • An additional disaster recovery footprint in a different data center

If a custom solution might be right for you, talk to a LuxSci Expert.

FAQs: Perhaps you were wondering...?

No. LuxSci provides managed Linux-based dedicated servers for web hosting.

Yes. It is common for customers to run WordPress on LuxSci servers. Note that you do need to choose a server with a minimum of 2 GB of RAM to run WordPress, or any other database-driven CMS. 4 GB servers will have great performance.

LuxSci does not currently provide a WordPress migration service. We will install a fresh version of WordPress for you. We would suggest that you have your web designer (i.e. the one in charge of designing and maintaining your current WordPress site) assist you in any migrations. S/he may find the WordPress Duplicator plugin very useful for quickly migrating WordPress sites between providers.

Yes, LuxSci will provide non-root SSH access to your server. This is granted only upon request, for security reasons. You can make this request via a Support Ticket.

LuxSci web hosting is a managed service. For security reasons, we do not grant root or sudo-root access to customers.

While you can not edit this file directly, LuxSci support can make requested modifications to it upon request. These modifications are first vetted to ensure that they do not hurt your server's security level.

LuxSci provides custom web site and database management tools (not cPanel) for this purpose. LuxSci also provides a server management tool where you can edit your iptables firewall and view current and historical reports on CPU, RAM, and Disk usage.

Enterprise Class servers have their data stored on a private SAN where all disk partitions are always encrypted. Regular AWS-based Business Class servers also use full-disk encryption. Old-style (RackSpace-based) Business Class servers can not have their main operating system disk encrypted; however, if you purchase additional disks and request it, these additional disks can be encrypted and all of your data can be stored on them. See: Enterprise vs Business Class.

Yes. See Standard Backups. We can also set up custom backup and retention schedules for you.

Yes. You would submit your cron job to support for review and they would configure it for you on your server.

LuxSci will review each request for custom software installation and determine if it will be permitted. For things that you can download yourself, build yourself, and install in your own directory tree -- you are welcome to do that. For things that need to be installed server-wide, these will need to be approved by operations and then installed by operations. Things that require manual installations (i.e., which are not in the standard CentOS YUM repositories) way incur a consulting fee to install. If you want to be sure about specific packages, please inquire.

NOTE: LuxSci does not support and will not install: nginx, node.js, PostgreSQL, JAVA servlets, .NET, Mongodb, and ruby on rails. Our web hosting platform is strictly a CentOS Linux-based Apache, MySQL/MariaDB (including NoSQL), PHP/Perl/CGI system.

Other questions? Call Sales

Dedicated, managed Linux Web hosting

Unfortunately, unsecured web servers are intriguing and accessible to determined hackers. So when it comes to managing the large amounts of traffic your site receives, you must make security a top priority. LuxSci's dedicated web site hosting ensures the protection of your online presence with maximized security and capacity. A dedicated server provides space and resources just for you, as opposed to the watering hole of a traditional shared server.

In addition to increased privacy, dedicated web site hosting also offers increased security. For instance, if another users' server is attacked or hacked, you're much less likely to experience collateral damage. Increased reliability arises from the fact that you don't have to share memory, CPU, network, disk space, or other resources. And, dedicated servers are best for accounts that need large amounts of storage or other resources. Does this sound like the type of infrastructure that's right for your business?

HIPAA-compliant Web Sites

LuxSci dedicated secure web hosting services, in conjunction with a HIPAA-compliant account, provides a HIPAA-compliant infrastructure where you can host HIPAA-compliant web sites.

HIPAA-compliant web hosting provides:

  1. Dedicated - dedicated virtual private servers for enhanced security and flexibility.
  2. Forced Secure Connections - Your connections to FTP and MySQL (to manage your data) are forced to always be secure.
  3. Web Site SSL/TLS Support - SSL for your web site so that, if you are transmitting ePHI, you can do that securely. This includes NIST-recommended ciphers, HSTS support, SNI, and more.
  4. Databases - Storage of ePHI on our hosted databases is permitted and compliant.
  5. Reporting - Access and auditing reports of your access to our system and management of your web sites are available. Raw web site logs are also available for your analysis.
  6. Firewalls - Multiple levels of firewalls included with all servers.
  7. Intrusion Protection - Our Intrusion Protection system alerts LuxSci staff to any issue on your server.
  8. HIPAA Infrastructure Requirements - LuxSci takes care of the HIPAA infrastructure requirements regarding media disposal, backups, restores, and related things for you.
  9. Business Associate Agreement

Does the nature of your business call for HIPAA compliance? LuxSci's dedicated web hosting servers provide a HIPAA-compliant web infrastructure where you can host HIPAA web sites. The isolated nature of the dedicated server provides enhanced security and flexibility from hackers. You can use TLS to ensure a secure connection between your website and its visitors. We also offer auditing reports for your web sites and your access to our system. With highly secure redundant firewalls and our intrusion protection system, you can rest assured that if there is an issue on your server, we will be alerted.

LuxSci's dedicated HIPAA-compliant web hosting services provide you with your own protected island on the web. You have the ability to host and share information on a secure and isolated platform. Be sure to check out our dedicated server package and to look into our helpful HIPAA-compliant information to make sure you're always protected.

Your Role in HIPAA Compliance

Like any HIPAA web hosting solution where you have the ability to design your web site and upload your own scripts and programs, LuxSci provides a compliant environment and you are responsible for ensuring that your web site is designed and implemented in a secure and compliant fashion. I.e., this includes proper use of TLS when appropriate, access auditing and unique identity verification for visitors to your web site that acces ePHI, proper encryption of ePHI at-rest, etc. For further information, please see the following documents.

Learn more

eBook: HIPAA-compliant Website Basics

What healthcare organizations need to know about HIPAA-compliant web sites

Book 2 in the LuxSci Internet Security Series.

Created by Erik Kangas, PhD

Get the HIPAA eBook