Boston, MA ยท Regulated workloads
Boston PCI and HIPAA hosting with a dedicated firewall and VPN.
Dedicated servers built for workloads carrying protected health information or cardholder data. Every build includes a dedicated firewall, a dedicated VPN, hardware RAID 1 and a secured cabinet rather than shared rack space.
From $300 per month Dedicated firewall and VPN SOC 1 and SOC 2 facility
What compliant hosting actually means.
HIPAA, the Health Insurance Portability and Accountability Act of 1996, requires businesses that process, store or transmit electronic protected health information to comply with strict administrative, physical and technical safeguards. The consequences of losing or exposing that information range from reputational damage through to serious legal penalties.
Axcelx supplies the infrastructure half of that obligation. Technical controls, backup management, physical security policies and access control are all in place and documented, so your auditor has something concrete to examine.
We will be straight with you about the other half. No hosting provider can make your application compliant. That depends on how your own software handles, logs, encrypts and transmits protected data, and on the agreements between you and your partners. We provide compliant infrastructure and the reports to evidence it.
On every compliant build
- Dedicated firewall
- Dedicated VPN
- Hardware RAID 1
- Secured cabinet, not shared rack space
- DDoS protection
- /30 with 1 usable IPv4
- Always burstable networking
- SSAE-18 SOC 1 and SOC 2 facility
Compliant server plans
PCI and HIPAA server builds.
All four builds are hosted in Somerville, Massachusetts. Monthly billing, no contract, setup times exclude weekends.
| Build | Intended use | Processor | Memory | Storage | Transfer | Monthly |
|---|---|---|---|---|---|---|
| CO-D1 | HIPAA and PCI website hosting | 1x Intel Xeon E5-1620, 4 cores at 3.6 GHz | 16 GB ECC | 2x 960 GB Micron SSD, hardware RAID 1 | 30 TB at 100 Mbps on a 1 Gbps port | $300 |
| CO-D2 | HIPAA and PCI website hosting | 1x Intel Xeon E3-1275 v6, 4 cores at 3.8 GHz | 16 GB ECC | 2x 960 GB Micron SSD, hardware RAID 1 | 30 TB at 100 Mbps on a 1 Gbps port | $339 |
| CO-D3 | Compliant application hosting | 2x Intel Xeon E5-2667, 16 cores at 2.9 GHz | 32 GB ECC | 2x 960 GB Micron SSD, hardware RAID 1 | 30 TB at 100 Mbps on a 1 Gbps port | $375 |
| CO-D4 | Custom compliant hosting | 2x processors of your choice | 32 GB ECC and up | 4x SSD, capacity to order, hardware RAID | 60 TB at 200 Mbps and up on a 1 Gbps port | Quoted |
Unmetered 1 Gbps upgrades are available on every build. Bandwidth is calculated on the 95th percentile, so a 100 Mbps plan sustains 100 Mbps in both directions. Ask about higher specifications.
Built to order
Custom compliant server?
Tell us the scope you are being audited against and what the application does. We will spec the hardware, the firewall and the VPN around that rather than pushing you into the nearest tier.
- Processor and core count chosen against the workload, single or dual socket.
- 32 GB of ECC memory and up, to 512 GB.
- Four drive bays with hardware RAID, capacity to order.
- 60 TB at 200 Mbps and up, or unmetered 1 Gbps.
Related services
- Standard dedicated servers from $145 per month
- Colocation in the same SOC 1 and SOC 2 facility
- Managed service for patching and security audits
- Charlotte adds PCI DSS and HIPAA facility audits
Straight answers
PCI and HIPAA hosting questions.
Does Axcelx provide HIPAA compliant hosting?
Yes. We provide dedicated servers configured for workloads that process, store or transmit electronic protected health information, hosted in a facility with SSAE-18 SOC 1 and SOC 2 reports available on request. Every compliant build includes a dedicated firewall, a dedicated VPN, hardware RAID 1 and a secured cabinet.
What is HIPAA compliant hosting?
HIPAA, the Health Insurance Portability and Accountability Act of 1996, requires organizations handling electronic protected health information to meet administrative, physical and technical safeguards. Compliant hosting means the infrastructure side of those safeguards is in place: access control, physical security, encryption in transit, backup management and audit reporting.
Does hosting with Axcelx make my application HIPAA compliant?
No, and any provider telling you otherwise is overselling. We supply the compliant infrastructure and the documentation your auditor needs. Compliance also depends on how your own application handles, logs and transmits protected data, and on the business associate agreements between you and your partners.
What is included that a standard dedicated server does not have?
A dedicated firewall, a dedicated VPN, hardware RAID 1 storage and a secured cabinet rather than shared rack space. Standard dedicated servers can be ordered without those, which is why compliant builds start higher.
Are these servers suitable for PCI DSS?
Yes. The same isolation, firewall, VPN and secured cabinet requirements that support HIPAA workloads apply to cardholder data environments. Tell us which PCI level you are scoped at and we will confirm what we can attest to.
Which compliance reports can you provide?
The Boston facility carries SSAE-18 SOC 1 and SOC 2 reports, available annually on request. Our Charlotte facility adds SSAE 16, SOC 2 Type 2, PCI DSS and HIPAA audits.
Tell us what you are being audited against.
We will spec the server, the firewall and the VPN around your actual scope, and provide the facility reports your auditor asks for.