HIPAA-Compliant Practice Management Software

“HIPAA-compliant practice management software” is a real requirement described by a phrase that means less than it sounds. No agency certifies software as HIPAA compliant. What HIPAA actually requires is a set of safeguards: a signed business associate agreement, access controls with audit logging, encryption in transit and at rest, and a breach process. The software can be built to meet them, but compliance is how you run it, not a stamp on the box. We publish our own posture on the security page.

Key takeaways

  • HHS does not certify any product or vendor as HIPAA compliant. A “HIPAA-certified” claim is a marketing red flag, not proof.
  • Real compliance means 5 things: a signed BAA, the 3 Security Rule safeguard categories, access controls plus audit logs, encryption in transit and at rest, and a breach-notification process.
  • You need a written BAA before patient data flows. OCR once settled with a single practice for $31,000 over a missing BAA alone.
  • Ask the vendor 5 direct questions in writing. If any answer is a slogan instead of a specific, keep shopping.
What 'HIPAA compliant' actually requires of practice management software, and how to verify each one (July 2026). Requirements map to the HIPAA Security Rule and Privacy Rule.
CapabilityWhat it requiresHow you verify it
Signed BAAA written business associate agreementAsk for the actual document before you sign anything
Administrative safeguardsRisk analysis, policies, workforce trainingAsk what their risk analysis covers and how often
Physical safeguardsFacility and device access controlsAsk where data lives and who can reach the hardware
Technical safeguardsAccess control, audit controls, integrity, transmission securityAsk them to name each one, not "enterprise security"
Access control + audit loggingLogged, role-scoped access to recordsAsk to see what the audit trail records
EncryptionIn transit and at restAsk for the specifics: TLS version and at-rest standard
Breach proceduresA documented breach-notification processAsk for the timeline and who gets notified
Honest certification statusNo "HIPAA certified" claim existsTreat any HIPAA certificate claim as a red flag

Signed BAA

What it requiresA written business associate agreement
How you verify itAsk for the actual document before you sign anything

Administrative safeguards

What it requiresRisk analysis, policies, workforce training
How you verify itAsk what their risk analysis covers and how often

Physical safeguards

What it requiresFacility and device access controls
How you verify itAsk where data lives and who can reach the hardware

Technical safeguards

What it requiresAccess control, audit controls, integrity, transmission security
How you verify itAsk them to name each one, not "enterprise security"

Access control + audit logging

What it requiresLogged, role-scoped access to records
How you verify itAsk to see what the audit trail records

Encryption

What it requiresIn transit and at rest
How you verify itAsk for the specifics: TLS version and at-rest standard

Breach procedures

What it requiresA documented breach-notification process
How you verify itAsk for the timeline and who gets notified

Honest certification status

What it requiresNo "HIPAA certified" claim exists
How you verify itTreat any HIPAA certificate claim as a red flag

”HIPAA certified” is not a thing anyone can sell you

Start here because it clears up half the confusion. There is no HIPAA certification. HHS says plainly, in its own Security Rule FAQ, that “there is no standard or implementation specification that requires a covered entity to certify compliance.” The Office for Civil Rights, which enforces HIPAA, does not certify people, products, or organizations as compliant.

So when a vendor puts a “HIPAA Certified” badge on its site, one of two things is true. Either they mean their software includes the safeguards HIPAA calls for, phrased sloppily, or they’re hoping you won’t check. A third-party firm might run an attestation or assessment against HIPAA criteria, and that’s useful, but it still isn’t a government certificate. The honest version of the claim sounds like “we’re built to meet the HIPAA Security Rule and we’ll sign a BAA,” not “we’re HIPAA certified.” Watch the verb.

This matters because the badge does a lot of unearned work in a buying decision. A busy solo doctor sees “HIPAA compliant,” checks the box, and moves on. The safeguards behind the phrase are what actually protect the practice, and those you have to ask about one by one.

What HIPAA actually requires of your software

HIPAA has two rules that touch your practice management system directly. The Privacy Rule governs when and how patient information can be used and disclosed. The Security Rule governs how electronic patient information is protected. Compliant software is really software that supports both.

The Security Rule organizes its requirements into three safeguard categories, and a serious vendor can speak to all three:

  • Administrative safeguards. The policies and process side. Risk analysis, workforce training, assigned security responsibility, and access-management procedures. This is the part people forget is software-adjacent, but your PMS vendor’s own program lives here.
  • Physical safeguards. Facility access, workstation use, and device and media controls. For a cloud PMS, this is largely about where the data physically sits and who can reach the servers.
  • Technical safeguards. The parts that live in the code: access control, audit controls, integrity controls, and transmission security. Encryption and access logging both sit in this bucket.

Notice what’s missing from that list: a feature you switch on. HIPAA describes outcomes and controls, not a settings toggle. Two practices can run the same software and one is compliant while the other isn’t, because compliance depends on configuration, BAAs, and habits as much as on the product.

The five things a compliant PMS has to get right

Strip away the jargon and the requirement comes down to five concrete things. Run every practice management vendor against these.

A signed BAA. If a vendor stores, transmits, or touches your patient data, it’s a business associate, and the Privacy Rule requires a written business associate agreement before any protected health information moves. This isn’t optional and it isn’t waived by small practice size. In 2017, OCR settled with a small Illinois practice, the Center for Children’s Digestive Health, for $31,000 over a missing BAA with a vendor. One document, a five-figure lesson. Ask for the actual BAA and read it.

Access controls and audit logging. Not everyone in the practice should see everything, and the system should record who did. The Security Rule names access control and audit controls as technical safeguards, which in plain terms means role-scoped access plus a log of who viewed, changed, or exported a record and when. If a vendor can’t show you what the audit trail captures, that’s a gap.

Encryption in transit and at rest. In transit means TLS on every connection, 1.2 or newer. At rest means strong encryption on stored records and account data, with AES-256 as the common standard. A vendor that answers “bank-grade security” instead of naming the actual standard is dodging. Get the specifics in writing.

Breach procedures. When data is exposed, HIPAA’s Breach Notification Rule sets what happens next: notify affected individuals, notify HHS, and in larger breaches notify the media, within defined timelines. Your vendor should have a documented process, not an improvised scramble. Ask what their breach playbook is and how fast they’d tell you.

Honest certification status. Since no HIPAA certificate exists, the tell of a trustworthy vendor is how they talk about it. “Aligned with the HIPAA Security Rule, BAA available” is honest. “HIPAA certified” is not. If they lean on a certificate that can’t exist, ask what else they’re rounding up.

The five questions to ask before you sign

You don’t need to be a compliance officer to vet a PMS. You need five questions and the patience to make the vendor answer in specifics, in writing.

  1. Will you sign a BAA, and can I see it now?
  2. What encryption do you use, in transit and at rest, by name?
  3. Who on your side can access our patient data, and is that access logged?
  4. What is your breach-notification process and timeline?
  5. What is your honest certification status?

Picture a two-provider clinic on a Thursday, comparing three quote-only PMS vendors. The one worth trusting answers all five plainly and hands over the BAA. The one to walk away from sends back a brochure with a “HIPAA compliant” badge and no BAA in sight. The questions do the filtering for you.

Where we land, honestly

Here’s our own posture, because you should hold us to the same standard. Patient Square is an AI clinical platform, and Practice Copilot bundles an AI EHR at the Copilot plan alongside the scribe. On the compliance front we’ll say exactly what’s true and nothing more. Our safeguards are aligned with the HIPAA Security Rule. We make BAAs available to every customer. We use encryption in transit and at rest, with role-scoped, logged access. Our SOC 2 Type II audit is in progress. We are not “SOC 2 certified” and we are not “HIPAA certified,” because neither claim would be honest, and one of them can’t exist for anyone.

The scribe module at the center of it captures the visit ambiently and hands back a structured SOAP note, ICD-10 suggestions, and a prescription draft, ready to review and sign minutes after the visit. The compliance posture around all of it is the plain version above, not a badge.

We think honesty on this topic is the whole game. YMYL health content and health software both get judged on whether they overclaim, and a vendor that fudges its compliance status is telling you how it’ll handle your data. So we’d rather under-promise the certificate and show you the BAA.

When a compliance-first enterprise PMS is the better fit

To be fair about it: we aren’t the right answer for every practice. If you’re a large group or a hospital with a formal vendor-risk program, a procurement team, and a checklist that demands a completed SOC 2 Type II report, HITRUST certification, or a signed security questionnaire before anything moves, an established enterprise practice-management vendor that already holds those artifacts is a cleaner fit than a platform with SOC 2 in progress. That’s a real gap and we won’t paper over it.

Where a published, honest posture wins is the independent practice that wants to actually understand what it’s buying, sign a real BAA, and not get sold a certificate that doesn’t exist. If that’s you, see the pricing or book a short demo and we’ll walk the safeguards on your own workflow, no badge required.

What “compliant” should mean when you shop

Strip the phrase down and “HIPAA-compliant practice management software” means a vendor who’ll sign a BAA, applies the Security Rule’s administrative, physical, and technical safeguards, controls and logs access, encrypts your data both ways, and has a breach plan. It does not mean a certificate, because none exists. If you take one thing from this: ask the five questions, get the answers in writing, and trust the vendor who names specifics over the one who shows you a badge.

For related reading, our AI scribe security checklist runs the same discipline for the documentation layer, and the BAA and consent guide goes deeper on what a business associate agreement has to contain. If you want the honest number for our own platform, it’s on the pricing page.

Frequently asked questions

The FAQ above covers the recurring ones: whether any PMS is truly HIPAA certified, what compliance actually requires, whether you need a BAA, the three safeguard categories, cloud safety, the questions to ask, and whether audit logs are required. For the fuller vendor-vetting drill, see the security checklist; a demo shows how our own safeguards work on real visits.

FAQ

Common questions

Is any practice management software actually HIPAA certified?

No. HHS states there is no standard that requires certifying compliance with the Security Rule, and the Office for Civil Rights does not certify software or vendors. A product can be built and operated to meet HIPAA safeguards, and prove it with a signed BAA and documented controls, but a HIPAA certificate does not exist. Treat any vendor selling one as a red flag.

What makes practice management software HIPAA compliant?

Compliance is a set of safeguards, not a badge. The vendor must sign a business associate agreement, apply administrative, physical, and technical safeguards under the Security Rule, control and log who touches patient data, encrypt it in transit and at rest, and follow the breach-notification rule if data is exposed. Compliance is how the software is configured and run, not a feature you toggle on.

Do I need a BAA with my practice management vendor?

Yes. Any vendor that creates, receives, stores, or transmits protected health information for you is a business associate, and the Privacy Rule requires a written agreement before that data flows. It does not matter how small your practice is. OCR has settled with a single practice for a missing BAA, so this is not a formality you can skip on a handshake.

What are the three types of HIPAA Security Rule safeguards?

Administrative, physical, and technical. Administrative safeguards cover policies, risk analysis, and workforce training. Physical safeguards cover facility access and device controls. Technical safeguards cover access control, audit controls, integrity, and transmission security, which is where encryption and access logging live. A compliant PMS vendor should be able to speak to all three in writing.

Is cloud practice management software safe under HIPAA?

It can be, and most modern PMS platforms are cloud-based. HIPAA does not favor on-premise over cloud. What matters is the same safeguard set: a signed BAA with the vendor and any subprocessors, encryption, access controls, audit logging, and a documented breach process. A well-run cloud vendor often has stronger controls than a small practice can maintain on a server in a back office.

What questions should I ask a PMS vendor about HIPAA?

Ask five things in writing. Will you sign a BAA. What encryption do you use in transit and at rest. Who on your side can access patient data and is that access logged. What is your breach-notification process and timeline. And what is your honest certification status, not a marketing slogan. If any answer is vague or refused, keep looking.

Does HIPAA require audit logs in practice management software?

Effectively, yes. The Security Rule names audit controls as a technical safeguard, meaning the system must record and examine activity that touches protected health information. In practice that means a log of who viewed, changed, or exported a patient record and when. Ask your vendor to show you what the audit trail captures before you trust it with charts.

Sources

  1. HHS: HIPAA Security Rule overview (administrative, physical, and technical safeguards; fetched July 2026).
  2. HHS: Are we required to certify our organization's compliance with the standards of the Security Rule? (HIPAA FAQ; fetched July 2026).
  3. HHS: Business Associate Contracts, sample provisions (fetched July 2026).
  4. HHS: Breach Notification Rule (fetched July 2026).
  5. HHS: No Business Associate Agreement? $31K Mistake (Center for Children's Digestive Health resolution agreement, April 2017; fetched July 2026).