“HIPAA-compliant practice management software” is a real requirement described by a phrase that means less than it sounds. No agency certifies software as HIPAA compliant. What HIPAA actually requires is a set of safeguards: a signed business associate agreement, access controls with audit logging, encryption in transit and at rest, and a breach process. The software can be built to meet them, but compliance is how you run it, not a stamp on the box. We publish our own posture on the security page.
Key takeaways
- HHS does not certify any product or vendor as HIPAA compliant. A “HIPAA-certified” claim is a marketing red flag, not proof.
- Real compliance means 5 things: a signed BAA, the 3 Security Rule safeguard categories, access controls plus audit logs, encryption in transit and at rest, and a breach-notification process.
- You need a written BAA before patient data flows. OCR once settled with a single practice for $31,000 over a missing BAA alone.
- Ask the vendor 5 direct questions in writing. If any answer is a slogan instead of a specific, keep shopping.
| Capability | What it requires | How you verify it |
|---|---|---|
| Signed BAA | A written business associate agreement | Ask for the actual document before you sign anything |
| Administrative safeguards | Risk analysis, policies, workforce training | Ask what their risk analysis covers and how often |
| Physical safeguards | Facility and device access controls | Ask where data lives and who can reach the hardware |
| Technical safeguards | Access control, audit controls, integrity, transmission security | Ask them to name each one, not "enterprise security" |
| Access control + audit logging | Logged, role-scoped access to records | Ask to see what the audit trail records |
| Encryption | In transit and at rest | Ask for the specifics: TLS version and at-rest standard |
| Breach procedures | A documented breach-notification process | Ask for the timeline and who gets notified |
| Honest certification status | No "HIPAA certified" claim exists | Treat any HIPAA certificate claim as a red flag |
Signed BAA
Administrative safeguards
Physical safeguards
Technical safeguards
Access control + audit logging
Encryption
Breach procedures
Honest certification status
”HIPAA certified” is not a thing anyone can sell you
Start here because it clears up half the confusion. There is no HIPAA certification. HHS says plainly, in its own Security Rule FAQ, that “there is no standard or implementation specification that requires a covered entity to certify compliance.” The Office for Civil Rights, which enforces HIPAA, does not certify people, products, or organizations as compliant.
So when a vendor puts a “HIPAA Certified” badge on its site, one of two things is true. Either they mean their software includes the safeguards HIPAA calls for, phrased sloppily, or they’re hoping you won’t check. A third-party firm might run an attestation or assessment against HIPAA criteria, and that’s useful, but it still isn’t a government certificate. The honest version of the claim sounds like “we’re built to meet the HIPAA Security Rule and we’ll sign a BAA,” not “we’re HIPAA certified.” Watch the verb.
This matters because the badge does a lot of unearned work in a buying decision. A busy solo doctor sees “HIPAA compliant,” checks the box, and moves on. The safeguards behind the phrase are what actually protect the practice, and those you have to ask about one by one.
What HIPAA actually requires of your software
HIPAA has two rules that touch your practice management system directly. The Privacy Rule governs when and how patient information can be used and disclosed. The Security Rule governs how electronic patient information is protected. Compliant software is really software that supports both.
The Security Rule organizes its requirements into three safeguard categories, and a serious vendor can speak to all three:
- Administrative safeguards. The policies and process side. Risk analysis, workforce training, assigned security responsibility, and access-management procedures. This is the part people forget is software-adjacent, but your PMS vendor’s own program lives here.
- Physical safeguards. Facility access, workstation use, and device and media controls. For a cloud PMS, this is largely about where the data physically sits and who can reach the servers.
- Technical safeguards. The parts that live in the code: access control, audit controls, integrity controls, and transmission security. Encryption and access logging both sit in this bucket.
Notice what’s missing from that list: a feature you switch on. HIPAA describes outcomes and controls, not a settings toggle. Two practices can run the same software and one is compliant while the other isn’t, because compliance depends on configuration, BAAs, and habits as much as on the product.
The five things a compliant PMS has to get right
Strip away the jargon and the requirement comes down to five concrete things. Run every practice management vendor against these.
A signed BAA. If a vendor stores, transmits, or touches your patient data, it’s a business associate, and the Privacy Rule requires a written business associate agreement before any protected health information moves. This isn’t optional and it isn’t waived by small practice size. In 2017, OCR settled with a small Illinois practice, the Center for Children’s Digestive Health, for $31,000 over a missing BAA with a vendor. One document, a five-figure lesson. Ask for the actual BAA and read it.
Access controls and audit logging. Not everyone in the practice should see everything, and the system should record who did. The Security Rule names access control and audit controls as technical safeguards, which in plain terms means role-scoped access plus a log of who viewed, changed, or exported a record and when. If a vendor can’t show you what the audit trail captures, that’s a gap.
Encryption in transit and at rest. In transit means TLS on every connection, 1.2 or newer. At rest means strong encryption on stored records and account data, with AES-256 as the common standard. A vendor that answers “bank-grade security” instead of naming the actual standard is dodging. Get the specifics in writing.
Breach procedures. When data is exposed, HIPAA’s Breach Notification Rule sets what happens next: notify affected individuals, notify HHS, and in larger breaches notify the media, within defined timelines. Your vendor should have a documented process, not an improvised scramble. Ask what their breach playbook is and how fast they’d tell you.
Honest certification status. Since no HIPAA certificate exists, the tell of a trustworthy vendor is how they talk about it. “Aligned with the HIPAA Security Rule, BAA available” is honest. “HIPAA certified” is not. If they lean on a certificate that can’t exist, ask what else they’re rounding up.
The five questions to ask before you sign
You don’t need to be a compliance officer to vet a PMS. You need five questions and the patience to make the vendor answer in specifics, in writing.
- Will you sign a BAA, and can I see it now?
- What encryption do you use, in transit and at rest, by name?
- Who on your side can access our patient data, and is that access logged?
- What is your breach-notification process and timeline?
- What is your honest certification status?
Picture a two-provider clinic on a Thursday, comparing three quote-only PMS vendors. The one worth trusting answers all five plainly and hands over the BAA. The one to walk away from sends back a brochure with a “HIPAA compliant” badge and no BAA in sight. The questions do the filtering for you.
Where we land, honestly
Here’s our own posture, because you should hold us to the same standard. Patient Square is an AI clinical platform, and Practice Copilot bundles an AI EHR at the Copilot plan alongside the scribe. On the compliance front we’ll say exactly what’s true and nothing more. Our safeguards are aligned with the HIPAA Security Rule. We make BAAs available to every customer. We use encryption in transit and at rest, with role-scoped, logged access. Our SOC 2 Type II audit is in progress. We are not “SOC 2 certified” and we are not “HIPAA certified,” because neither claim would be honest, and one of them can’t exist for anyone.
The scribe module at the center of it captures the visit ambiently and hands back a structured SOAP note, ICD-10 suggestions, and a prescription draft, ready to review and sign minutes after the visit. The compliance posture around all of it is the plain version above, not a badge.
We think honesty on this topic is the whole game. YMYL health content and health software both get judged on whether they overclaim, and a vendor that fudges its compliance status is telling you how it’ll handle your data. So we’d rather under-promise the certificate and show you the BAA.
When a compliance-first enterprise PMS is the better fit
To be fair about it: we aren’t the right answer for every practice. If you’re a large group or a hospital with a formal vendor-risk program, a procurement team, and a checklist that demands a completed SOC 2 Type II report, HITRUST certification, or a signed security questionnaire before anything moves, an established enterprise practice-management vendor that already holds those artifacts is a cleaner fit than a platform with SOC 2 in progress. That’s a real gap and we won’t paper over it.
Where a published, honest posture wins is the independent practice that wants to actually understand what it’s buying, sign a real BAA, and not get sold a certificate that doesn’t exist. If that’s you, see the pricing or book a short demo and we’ll walk the safeguards on your own workflow, no badge required.
What “compliant” should mean when you shop
Strip the phrase down and “HIPAA-compliant practice management software” means a vendor who’ll sign a BAA, applies the Security Rule’s administrative, physical, and technical safeguards, controls and logs access, encrypts your data both ways, and has a breach plan. It does not mean a certificate, because none exists. If you take one thing from this: ask the five questions, get the answers in writing, and trust the vendor who names specifics over the one who shows you a badge.
For related reading, our AI scribe security checklist runs the same discipline for the documentation layer, and the BAA and consent guide goes deeper on what a business associate agreement has to contain. If you want the honest number for our own platform, it’s on the pricing page.
Frequently asked questions
The FAQ above covers the recurring ones: whether any PMS is truly HIPAA certified, what compliance actually requires, whether you need a BAA, the three safeguard categories, cloud safety, the questions to ask, and whether audit logs are required. For the fuller vendor-vetting drill, see the security checklist; a demo shows how our own safeguards work on real visits.