Skip to main content

Framework: HIPAA

Okta backup and disaster recovery for HIPAA

HIPAA Administrative and Technical Safeguards require documented controls and contingency planning for the identity layer that gates PHI access. Butterfly is the disaster-recovery layer for that identity layer.

Scope

In-scope control families

  • 164.308(a)(1) – Security Management Process
  • 164.308(a)(7) – Contingency Plan
  • 164.312(a)(1) – Access Control

Coverage mapping

How Butterfly maps to HIPAA

164.308(a)(7)(ii)(A) – data backup plan

Scheduled, encrypted, point-in-time Okta backups; target retention per plan with enforcement migrating from soft to scheduled prune.

164.308(a)(7)(ii)(B) – disaster recovery plan

Restore preview + dry-run + readiness score; restore is provable, not theoretical.

164.308(a)(7)(ii)(D) – testing and revision procedures

Restore preview is non-mutating; the operation is audit-logged and shows up in the Audit Pack.

FAQ

Does Butterfly access PHI?

No. Butterfly handles Okta configuration data only – users, groups, policies, app assignments.

Will you sign a BAA?

Not today. Butterfly does not currently sign HIPAA BAAs. The technical and administrative safeguards in 45 CFR 164.308 and 164.312 are implemented at the platform layer, and a BAA program is planned once the SOC 2 Type 2 attestation closes. Contact butterflysecurity.org/contact if you want to be notified when that changes.

Where is configuration data stored?

In your designated Cloudflare R2 region. Encrypted at rest. Documented in the Trust Center.