• Beth Isreal Lahey Health
  • Delta Dental
  • AthenaHealth
  • Lucerna Health
  • Hinge Health
  • VRL Eurofins
  • CityBlock Health
  • Benefits Express
  • Gannett
  • Solution Health

HIPAA Compliance

WordPress, LAMP

WordPress, CMS—LAMP Stack

  • Solid, reliable technology for popular platforms: WordPress, Joomla, Drupal, and others
  • Linux: Oracle Linux
  • Apache
  • MySQL (actually MariaDB)
  • PHP (and Perl and Python)
  • Optimized for speed! Get 4+ GB RAM on your server

SSL/TLS Transport Encryption


Multiple Firewalls

  • Network firewall
  • On-server software firewall
  • Web-based software firewall management tools
  • Account-specific access control tools
  • Server monitoring integrated with the firewall
  • Optional: Web-application Firewall

Segmentation & Isolation

  • Zero Trust-aligned
  • Dedicated, micro-segmented Trust Zone
  • Get dedicated network firewalls
  • Segment your servers from everyone else
  • Lower your risk

High Availability (optional)

  • HA Network Firewalls
  • HA Network Load Balancers
  • HA Server Clusters
  • HA MySQL Database Clusters
  • HA Storage
  • Ensure your site can survive a data center failure.
  • Read more

Better Security through Isolation

Unlike other SaaS solutions that place all client data in a shared cloud, LuxSci is unique in that it provides each client with their own dedicated server, cluster, or unique custom deployment. This can be compared to having one's property secured in a moated castle versus a communal camping site. The solution is more reliable, ensures consistency, and vastly improves the overall security of your data.

Dedicated environments are better than shared clouds

Custom Zero Trust-aligned Solutions

Custom large-scale solutions

Custom cluster solutions provide a dedicated, micro-segmented trust zone that can be tailored for very large numbers of web sites, amounts of web traffic, high availability, high security, and business continuity. They are designed to be Zero Trust-aligned, resilient to data center failure, and can include:

  • High-availability network firewalls
  • High-availability network load balancers
  • High-availability, high-capacity outbound email sending servers
  • High-availability web/application servers
  • High-availability replicated MySQL clusters
  • High-availability storage
  • System isolation and capacity scaling
  • Dedicated network segments
  • DDOS Protection
  • An additional disaster recovery footprint in a distant geographic location

If a custom solution might be right for you, talk to a LuxSci Expert.

FAQs: Perhaps you were wondering...?

No. LuxSci provides managed Linux-based dedicated servers for web hosting.

Yes. It is common for customers to run WordPress on LuxSci servers. Note that you do need to choose a server with a minimum of 2 GB of RAM to run WordPress, or any other database-driven CMS. 4 GB servers will have great performance.

LuxSci does not currently provide a WordPress migration service. We will install a fresh version of WordPress for you. We would suggest that you have your web designer (i.e. the one in charge of designing and maintaining your current WordPress site) assist you in any migrations. S/he may find the WordPress Duplicator plugin very useful for quickly migrating WordPress sites between providers.

Yes, LuxSci will provide non-root SSH access to your server. This is granted only upon request, for security reasons. You can make this request via a Support Ticket.

LuxSci web hosting is a managed service. For security reasons, we do not grant root or sudo-root access to customers.

While you can not edit this file directly, LuxSci support can make requested modifications to it upon request. These modifications are first vetted to ensure that they do not hurt your server's security level.

LuxSci provides custom web site and database management tools (not cPanel) for this purpose. LuxSci also provides a server management tool where you can edit your iptables firewall and view current and historical reports on CPU, RAM, and Disk usage.

Yes. See Standard Backups. We can also set up custom backup and retention schedules for you.

Yes. You would submit your cron job to support for review and they would configure it for you on your server.

LuxSci will review each request for custom software installation and determine if it will be permitted. For things that you can download yourself, build yourself, and install in your own directory tree -- you are welcome to do that. For things that need to be installed server-wide, these will need to be approved by operations and then installed by operations. Things that require manual installations (i.e., which are not in the standard Linux YUM repositories) way incur a consulting fee to install. If you want to be sure about specific packages, please inquire.

NOTE: LuxSci does not support and will not install: nginx, node.js, PostgreSQL, JAVA servlets, .NET, Mongodb, and ruby on rails. Our web hosting platform is strictly a Linux-based Apache, MySQL/MariaDB (including NoSQL), PHP/Perl/CGI system.

Other questions? Call Sales

Dedicated, managed Linux Web hosting

Unfortunately, unsecured web servers are intriguing and accessible to determined hackers. So when it comes to managing the large amounts of traffic your site receives, you must make security a top priority. LuxSci's dedicated web site hosting ensures the protection of your online presence with maximized security and capacity. A dedicated server provides space and resources just for you, as opposed to the watering hole of a traditional shared server.

In addition to increased privacy, dedicated web site hosting also offers increased security. For instance, if another users' server is attacked or hacked, you're much less likely to experience collateral damage. Increased reliability arises from the fact that you don't have to share memory, CPU, network, disk space, or other resources. And, dedicated servers are best for accounts that need large amounts of storage or other resources. Does this sound like the type of infrastructure that's right for your business?

HIPAA-compliant Web Sites

LuxSci dedicated secure web hosting services, in conjunction with a HIPAA-compliant account, provides a HIPAA-compliant infrastructure where you can host HIPAA-compliant web sites.

HIPAA-compliant web hosting provides:

  1. Dedicated - dedicated virtual private servers for enhanced security and flexibility.
  2. Forced Secure Connections - Your connections to FTP and MySQL (to manage your data) are forced to always be secure.
  3. Web Site SSL/TLS Support - SSL for your web site so that, if you are transmitting ePHI, you can do that securely. This includes NIST-recommended ciphers, HSTS support, SNI, and more.
  4. Databases - Storage of ePHI on our hosted databases is permitted and compliant.
  5. Reporting - Access and auditing reports of your access to our system and management of your web sites are available. Raw web site logs are also available for your analysis.
  6. Firewalls - Multiple levels of firewalls included with all servers.
  7. Intrusion Protection - Our Intrusion Protection system alerts LuxSci staff to any issue on your server.
  8. HIPAA Infrastructure Requirements - LuxSci takes care of the HIPAA infrastructure requirements regarding media disposal, backups, restores, and related things for you.
  9. Business Associate Agreement

Does the nature of your business call for HIPAA compliance? LuxSci's dedicated web hosting servers provide a HIPAA-compliant web infrastructure where you can host HIPAA web sites. The isolated nature of the dedicated server provides enhanced security and flexibility from hackers. You can use TLS to ensure a secure connection between your website and its visitors. We also offer auditing reports for your web sites and your access to our system. With highly secure redundant firewalls and our intrusion protection system, you can rest assured that if there is an issue on your server, we will be alerted.

LuxSci's dedicated HIPAA-compliant web hosting services provide you with your own protected island on the web. You have the ability to host and share information on a secure and isolated platform. Be sure to check out our dedicated server package and to look into our helpful HIPAA-compliant information to make sure you're always protected.

Your Role in HIPAA Compliance

Like any HIPAA web hosting solution where you have the ability to design your web site and upload your own scripts and programs, LuxSci provides a compliant environment and you are responsible for ensuring that your web site is designed and implemented in a secure and compliant fashion. I.e., this includes proper use of TLS when appropriate, access auditing and unique identity verification for visitors to your web site that access ePHI, proper encryption of ePHI at-rest, etc. For further information, please see the following documents.

Learn more

eBook: HIPAA-compliant Website Basics

What healthcare organizations need to know about HIPAA-compliant web sites

Book 2 in the LuxSci Internet Security Series.

Created by Erik Kangas, PhD

Get the HIPAA eBook