A health system that wants to keep email, files, documents, video and chat under HIPAA has two ways to get there. It can configure a hyperscale SaaS suite carefully and accept that the contingency plan for those systems is the vendor's. Or it can run a single-tenant collaboration platform on infrastructure it, or its managed provider, controls, where every safeguard in the Security Rule can be configured, evidenced and rehearsed. This post is the second path. It takes the controls in the proposed HIPAA Security Rule update, including the 72-hour restoration objective, and maps each one to Nextcloud Hub Enterprise as MassiveGRID deploys it for healthcare customers: one tenant per organisation, in a US datacenter, under a Business Associate Agreement, with a migration plan that lets clinicians keep Outlook and their phones' mail apps.
The scenario: a regional health system that outgrew "it is in the BAA"
Harbor Point Health, a fictional 600-clinician system with four hospitals and thirty clinics, ran Microsoft 365 E3 for eight years. Its compliance officer's problem was not any single control. It was that the contingency plan for email and the shared document store said, in effect, "Microsoft will restore it", and the proposed rule's 72-hour restoration and 48-hour backup clauses would require that sentence to be backed by a criticality analysis, a backup design and an annual test with evidence. The IT director's problem was cost: the E3 renewal had risen again, the add-ons needed for audit retention and backup pushed it further, and the organisation was paying per seat for a video and chat product its clinicians used for internal messages that were, in HIPAA terms, ePHI.
The decision was to move email, files, office documents, video and messaging to a managed, single-tenant Nextcloud Hub Enterprise deployment, keep the EHR where it was, and keep Microsoft 365 licences only for the Windows desktop applications. What follows is the compliance mapping that went into the board paper.
What Nextcloud Hub Enterprise replaces
Nextcloud Hub is a single open-source platform that covers the collaboration workloads Microsoft 365 is used for in a health system. The Enterprise edition adds the long-term support, security hardening and vendor backing that regulated deployments need, and Nextcloud GmbH itself states that the Enterprise edition is designed for HIPAA and HITECH use.
| Microsoft 365 workload | Nextcloud Hub Enterprise component | Clinician-facing change |
|---|---|---|
| Exchange Online, Outlook | Nextcloud Mail and Groupware (CalDAV and CardDAV) on a mail platform in the same tenant | Outlook and phone mail apps keep working over IMAP and SMTP; calendar and contacts sync over open standards |
| OneDrive, SharePoint | Nextcloud Files with desktop and mobile sync clients, group folders, retention and file access control | Same sync-folder model; sharing links gain expiry, password and download-limit controls by policy |
| Word, Excel, PowerPoint online | Nextcloud Office (Collabora Online) with real-time co-editing of DOCX, XLSX and PPTX | Browser editing of the same file formats; desktop Office stays for power users |
| Teams meetings and chat | Nextcloud Talk with a dedicated High Performance Backend | Internal chat, calls and video on the same tenant, with no external relay |
| Forms, Planner, Whiteboard | Nextcloud Forms, Deck and Whiteboard | Equivalent tools, data stays in the tenant |
| Entra ID | Existing Active Directory or Entra ID via LDAP, SAML or OpenID Connect | None; the same identities, the same MFA policy |
The identity row is the one that makes the migration feasible. Harbor Point kept its directory, so group memberships, departures and MFA policy did not change, and the proposed rule's one-hour access termination clause is enforced in one place.
Safeguard by safeguard: the proposed rule mapped to the deployment
The table lists the proposed Security Rule controls with a measurable requirement, and how the Harbor Point deployment satisfies and evidences each one. "Evidence" is the artefact that goes in the compliance file, because under the proposal the written record is what an investigator audits.
| Proposed control | How it is met | Evidence on file |
|---|---|---|
| Asset inventory and network map | One tenant, a known set of components (application nodes, database, object storage, mail, Talk backend, Collabora) in one segmented network, documented by MassiveGRID per deployment | Deployment architecture document, updated on change |
| Encryption at rest and in transit | AES-256 encrypted storage volumes; TLS 1.2 or later on every endpoint; optional server-side encryption and end-to-end encryption for designated folders | Configuration export, TLS scan report |
| MFA, no exceptions | Enforced at the identity provider for every login path; Nextcloud's own second factor as a fallback for local accounts | IdP policy export, list of local accounts with MFA state |
| Network segmentation | Database, storage and mail reachable only from the application tier over a private network; admin access through a bastion with MFA | Firewall rule set, network diagram |
| Anti-malware, extraneous software, unused ports | Hardened images with only the required services; antivirus scanning of uploaded files; ports closed by default | Image baseline, port scan |
| Patching: 15 days critical, 30 days high | Managed patching by MassiveGRID with Nextcloud Enterprise security releases applied on the vendor's schedule | Patch log with dates per advisory |
| Audit controls, 6-year retention | Nextcloud audit log of every file, share, login and admin action, shipped to retained storage | Log retention policy, sample exports |
| Backups no more than 48 hours old | Files, database and configuration backed up at least daily to a separate storage system, with off-site replication | Backup job history showing age of the newest copy |
| 72-hour restoration of critical systems | Documented runbook; replicated storage and highly available application tier for the common failure modes; full rebuild from backup as the last resort | Runbook, annual rehearsal report with measured time |
| Contingency plan tested every 12 months | Annual restoration rehearsal into an isolated environment, conducted with the customer | Dated test report, tickets, timings |
| Vulnerability scanning every 6 months, pen test every 12 | MassiveGRID scans the deployment; the customer's tester is given scope and a window | Scan and test reports |
| Business associate verification every 12 months | MassiveGRID provides a deployment-specific written attestation of the technical safeguards | Signed attestation |
| 24-hour contingency activation notice | Written into the BAA; delivered by the 24/7 NOC to named contacts | BAA clause, contact list, incident records |
The point of the table is not that any single row is impossible on Microsoft 365. Most are possible. It is that the last six rows are things the covered entity, with its managed provider, can do and show for its own systems, rather than things it has to take on trust from a platform it cannot inspect.
Designing for the 72 hours
The restoration objective drove the architecture more than any other requirement. Harbor Point's deployment runs on MassiveGRID's high-availability platform, Proxmox clusters with Ceph storage, so the ordinary failures, a failed host, a failed disk, a failed node, are handled by live migration and replicated storage without a restoration at all. The 72-hour clause is about the uncommon failures: a corrupted database, a ransomware event inside the tenant, an administrator error, a datacenter loss. For those, the design has three layers.
- Point-in-time recovery for the database and daily snapshots of files, held on a storage system separate from production, replicated to a second site. This is what satisfies the 48-hour currency clause, with margin.
- A documented rebuild runbook that starts from a clean platform, restores configuration, database and files in order, and ends with the identity provider reconnected and a clinician logging in. The order is the criticality analysis in executable form.
- An annual rehearsal of that runbook into an isolated environment, timed, with the customer's compliance officer watching. Harbor Point's first rehearsal came in well inside the window for the full tenant, and the report is the evidence the proposed rule asks for.
Our post on building a disaster recovery architecture around the 72-hour objective goes through the design in more depth, including how to size the restore for a multi-terabyte document store.
The migration, without losing Outlook
Compliance mappings do not fail; migrations do. Harbor Point's plan followed the sequence in our Microsoft 365 to Nextcloud migration guide, with three healthcare-specific adjustments.
- Files first, by department, with retention mapped. SharePoint sites became Nextcloud group folders with the same permissions, and Purview retention labels were translated into Nextcloud retention rules before any data moved, so that nothing lost its retention period in transit.
- Mail cut over on a weekend with coexistence. Mailboxes were migrated over IMAP, MX records moved, and the old tenant kept receiving for a week as a safety net. Outlook users got a new account profile and nothing else changed for them, which is what made the clinician-facing part of the project a communications exercise rather than a training exercise.
- Teams history exported, not migrated. Chat history containing ePHI was exported to retained storage for the record and Talk started clean. The alternative, a lossy migration of years of chat, would have created a second copy of ePHI with no clear owner.
The old tenant was retained read-only for the period the risk analysis required and then closed, which removed a business associate from the annual verification list. Our guide to the first 90 days after replacing a hosted suite covers what changed for the help desk.
Cost, honestly
Harbor Point did not move to save money, but it did. The replacement is priced per deployment rather than per seat, so the cost does not rise with headcount, and the add-ons that compliance required on Microsoft 365, extended audit retention and third-party backup, are included in the managed service. The organisation kept a smaller number of Microsoft 365 Apps licences for desktop Office and dropped E3 entirely. Our Nextcloud versus Microsoft 365 cost comparison walks through the numbers for a comparable organisation; the short version is that the savings came from the per-seat items that compliance had made mandatory.
The honest cost is organisational: a dedicated platform means a dedicated relationship with the provider, a named escalation path, and an annual rehearsal that takes a day of the compliance officer's time. For a health system whose contingency plan previously consisted of a vendor's trust page, that day is the point.
Frequently Asked Questions
Is Nextcloud HIPAA compliant?
Software is not compliant on its own; deployments are. Nextcloud Hub Enterprise provides the technical safeguards the Security Rule requires, including encryption, access control, audit logging and retention, and Nextcloud GmbH states that the Enterprise edition is designed for HIPAA and HITECH use. Compliance depends on how it is hosted and operated, which is why MassiveGRID deploys it single-tenant, signs a Business Associate Agreement and documents every control per deployment.
Who signs the Business Associate Agreement?
MassiveGRID, as the hosting and operating provider that maintains ePHI on the customer's behalf. Nextcloud GmbH does not have access to customer data and is not a business associate in a MassiveGRID deployment. Our guide to BAAs for self-hosted collaboration explains the roles in detail.
Can clinicians keep using Outlook and their phones' mail apps?
Yes. Mail is served over IMAP and SMTP, and calendar and contacts over CalDAV and CardDAV, so Outlook, Apple Mail and the native iOS and Android clients connect with a new account profile. The Nextcloud web interface and mobile apps are available as well.
Where is the data hosted?
In a MassiveGRID datacenter in the United States for HIPAA customers, with off-site backup replication to a second US site, or in the customer's own facility under the hybrid model. Data residency is written into the agreement.
How long does a migration from Microsoft 365 take?
For a system the size of Harbor Point, files take four to six weeks by department, mail cuts over on one weekend after a pilot, and the old tenant is retained read-only for the period the risk analysis sets. Smaller organisations complete the whole move in a few weeks.
Replace Microsoft 365 under a BAA you can audit
Sovereign Workspaces is MassiveGRID's managed, single-tenant Nextcloud Hub Enterprise deployment: mail, files, office, video and chat in a US datacenter, with a Business Associate Agreement, backups inside the proposed 48-hour limit and an annual restoration rehearsal. Start with a discovery call.
Explore Sovereign Workspaces