Framework: HIPAA
Okta backup and disaster recovery for HIPAA
HIPAA Administrative and Technical Safeguards require documented controls and contingency planning for the identity layer that gates PHI access. Butterfly is the disaster-recovery layer for that identity layer.
Scope
In-scope control families
- 164.308(a)(1) – Security Management Process
- 164.308(a)(7) – Contingency Plan
- 164.312(a)(1) – Access Control
Coverage mapping
How Butterfly maps to HIPAA
164.308(a)(7)(ii)(A) – data backup plan
Scheduled, encrypted, point-in-time Okta backups; target retention per plan with enforcement migrating from soft to scheduled prune.
164.308(a)(7)(ii)(B) – disaster recovery plan
Restore preview + dry-run + readiness score; restore is provable, not theoretical.
164.308(a)(7)(ii)(D) – testing and revision procedures
Restore preview is non-mutating; the operation is audit-logged and shows up in the Audit Pack.
FAQ
Does Butterfly access PHI?
No. Butterfly handles Okta configuration data only – users, groups, policies, app assignments.
Will you sign a BAA?
Not today. Butterfly does not currently sign HIPAA BAAs. The technical and administrative safeguards in 45 CFR 164.308 and 164.312 are implemented at the platform layer, and a BAA program is planned once the SOC 2 Type 2 attestation closes. Contact butterflysecurity.org/contact if you want to be notified when that changes.
Where is configuration data stored?
In your designated Cloudflare R2 region. Encrypted at rest. Documented in the Trust Center.
Other frameworks