HIPAA Compliance

What HIPAA Compliant Software Actually Requires

A practical breakdown of the Security Rule controls that determine whether a system can legally handle protected health information — and how to evidence each one before you sign a contract.

Book an Assessment →Read the FAQ
Why This Matters

Compliance is a property of configuration, not a label


There is no government-issued "HIPAA compliant" certification for software. The Department of Health and Human Services enforces the Security Rule (45 CFR Part 164, Subpart C) against covered entities and their business associates — it does not certify products. When a vendor markets a tool as HIPAA compliant, that claim means the tool can be configured and operated to satisfy the Security Rule's administrative, physical, and technical safeguards, not that it is compliant by default.

The distinction matters because liability does not transfer with the purchase. A covered entity remains responsible for how a system is configured, even when the underlying platform is capable of compliant operation. Misconfigured access controls or an unsigned Business Associate Agreement create HIPAA exposure regardless of what the vendor's marketing page claims.

The constraint that catches most evaluations off guard: audit logging is frequently treated as a reporting feature, when the Security Rule treats it as a control. §164.312(b) requires hardware, software, and procedural mechanisms that record and examine activity in systems containing PHI — not just the ability to export a report on request.

At a Glance
  • No certification body. HIPAA compliance is self-attested and audited, not certified.
  • BAA required. Any vendor touching PHI must sign one.
  • Liability stays with you. Configuration failures are the covered entity's exposure.
Compliance Matrix

Security Rule requirements mapped to controls and evidence


This is not legal advice — it is a starting checklist for evaluating a vendor's technical safeguards against 45 CFR §164.312. Confirm applicability with counsel or a compliance officer before relying on it for an audit response.

RequirementControlEvidence
Access control (§164.312(a)(1))Unique user IDs, role-based permissions, automatic logoffAccess control policy, role matrix, session-timeout configuration export
Audit controls (§164.312(b))System-level logging of access to and modification of PHIAudit log retention policy, sample log export, log-review cadence records
Integrity controls (§164.312(c)(1))Mechanisms to confirm PHI has not been improperly altered or destroyedChecksum/versioning documentation, change-history records
Transmission security (§164.312(e)(1))Encryption in transit (TLS 1.2+) for any PHI leaving the system boundaryTLS configuration scan, data-flow diagram, encryption-in-transit attestation
Business Associate Agreement (§164.502(e))Signed BAA with every vendor that creates, receives, maintains, or transmits PHIExecuted BAA on file, vendor risk-assessment record
Selection Criteria

What to check before you shortlist a vendor


Access Control Depth

Role-based permissions at the field level, not just the record level — PHI fields need tighter scoping than a generic CRM field.

Signed BAA Available

The vendor offers a Business Associate Agreement as standard, not as a negotiated add-on reserved for enterprise tiers.

Immutable Audit Trail

Access and modification logs that administrators cannot silently edit or delete — tamper-evidence matters as much as logging itself.

Minimum Necessary Controls

The ability to restrict PHI visibility to the minimum necessary for a given role, per the HIPAA Privacy Rule's minimum-necessary standard.

ROI Model

Modeling the cost of compliant vs. non-compliant tooling


Compliance failures are rarely priced in until an audit or breach happens. This model frames the comparison as avoided cost plus implementation cost, using ranges rather than a single number.

InputValue / range
HIPAA-ready software license (per seat/mo)$45–$180, depending on PHI field coverage
Compliant configuration & BAA setup (one-time)$8,000–$35,000, depending on integration count
Average HIPAA settlement (HHS OCR, resolved cases)$100,000–$1.5M+, published HHS enforcement data
Breach notification cost per affected record$150–$220 (industry incident-response estimates)

Avoided-cost ROI = (probability-weighted breach/settlement exposure) − (compliant tooling cost + configuration cost)

Assumptions

  • Settlement figures come from published HHS Office for Civil Rights resolution agreements, not this vendor's own claims.
  • Per-record breach notification costs are industry averages and will vary by state notification law and record volume.
  • This model does not include legal fees, patient trust erosion, or corrective action plan costs, all of which are typically additional.
Worked Scenario

How this plays out in a mid-size practice


Hypothetical worked scenario

A 40-provider outpatient group evaluates two CRM finalists

This is an illustrative scenario, not a real client engagement. No client names, outcomes, or figures below describe an actual project.

A multi-location outpatient group is replacing a spreadsheet-based patient outreach process. Finalist A offers a signed BAA and field-level access control out of the box; Finalist B offers a BAA only on its highest tier and logs access at the record level, not the field level.

The compliance officer flags that Finalist B would expose insurance and diagnosis fields to any user with record access, which fails the minimum-necessary standard for front-desk staff. Finalist A's per-seat cost is 22% higher, but the configuration cost to retrofit field-level control onto Finalist B — using a middleware layer — erases the difference within the first year.

The group selects Finalist A. The lesson generalizes: a lower list price that requires custom compliance engineering is not actually the cheaper option once implementation cost is included.

FAQ

Common questions on HIPAA compliant software


No product is certified HIPAA compliant by a government body — HIPAA has no certification program. A system is compliant when its technical safeguards (access control, audit controls, integrity controls, transmission security) and its vendor's willingness to sign a Business Associate Agreement together satisfy the Security Rule at 45 CFR §164.312. Compliance is a property of how the software is configured and used, not a label the vendor can sell you.

Next Step

Ready to evaluate your current systems?

Book an assessment to map your existing tooling against the Security Rule controls above before you shortlist vendors.

Book an Assessment →