Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
☰
Compliance and security

HIPAA-compliant software checklist: Essential evaluation guide

Tanja Lepcheska
Last Updated: September 25, 2026

A HIPAA-compliant software checklist is a structured way to judge whether a vendor’s system is safe to hold patient data.

It works through the three safeguard categories the Security Rule sets out — administrative, physical, and technical. It also covers the Business Associate Agreement (BAA) that any vendor touching protected health information (PHI) has to sign.

The HHS Office for Civil Rights (OCR) enforces HIPAA. Civil penalties start at $145 per violation at the lowest tier, and reach an annual cap of $2,190,294 at the highest. A breach also triggers mandatory patient notification within 60 days.

Work through the checklist before you sign, not after go-live. It turns that exposure into a set of questions you can put to a vendor in one call, and into evidence you can file afterward.

Found our content helpful?

Download your free HIPAA-compliant software checklist

The sheet works through all three safeguard categories, the clauses your BAA needs, and the encryption and access-control standards to ask about. It also lists the documents to request from every vendor on your shortlist.

Download template
Key takeaways

Key takeaways

Every evaluation covers three safeguard categories: administrative policies, physical facility controls, and the technical features your vendor builds.

A signed Business Associate Agreement is mandatory with any vendor that handles PHI, whatever their technical safeguards look like.

The technical bar is AES-256 at rest, TLS 1.2+ in transit, MFA, role-based access, and audit logs kept for 6 years.

Pabau encrypts stored patient data and logs account activity, so the audit trail an evaluation asks for already exists.

Why HIPAA compliance matters for your practice

Enforcement has tightened. The OCR has increased breach investigations and issued multi-million-dollar settlements in recent years. Beyond the fine, a breach exposes your practice to patient lawsuits, reputation damage, and weeks of operational disruption.

Compliance is also an operating question. Digital forms built with compliance controls reduce manual errors in data handling, and compliance management software creates the audit trails an OCR investigation asks for. A checklist-driven evaluation also prevents mid-implementation surprises.

Pabau digital intake and consent forms
Pabau’s digital forms capture consent and intake answers straight into the patient record, so the paper trail starts at the first appointment.

The three HIPAA safeguard pillars

The HIPAA Security Rule (45 CFR Part 164) organizes compliance into three overlapping safeguard categories. Each covers a distinct risk surface, and each lands with a different owner once your software is cloud-hosted, as the split below shows.

Three-column chart of HIPAA safeguard ownership: administrative controls owned by your practice (risk assessment, annual training, least-privilege access, 60-day incident response, sanction policy); physical controls owned by the vendor when cloud-hosted (facility access, workstation locks, secure device disposal, encrypted off-site backups); technical controls owned by your vendor (AES-256 at rest, TLS 1.2+ in transit, MFA, 6-year audit log retention, 15 to 30 minute session timeouts, integrity checks)
Only the middle column moves when you switch to cloud hosting. A vendor question list is therefore not the same as a compliance plan. Grouping follows the HIPAA Security Rule, 45 CFR Part 164.

Administrative safeguards

These are the policies and processes your practice documents and enforces. Your software has to support:

  • Risk assessment: Documented evaluation of security threats to PHI, with remediation plans and annual updates.
  • Workforce training: Annual HIPAA training for every staff member who accesses PHI, with attestation records.
  • Access controls: Unique user IDs, role-based permissions, and enforcement of least-privilege access.
  • Incident response plan: Written procedures for detecting, responding to, and reporting security incidents within 60 days.
  • Sanction policy: Discipline procedures for workforce members who violate HIPAA policy.

Physical safeguards

These control where and how your team reaches PHI. For cloud-hosted software, many of them are the vendor’s responsibility. For on-premise systems, they are yours:

  • Facility access: Locked doors, visitor logs, badge readers for server rooms.
  • Workstation security: Screen privacy filters, automatic logoff after inactivity, locked workstations during breaks.
  • Device disposal: Secure data wiping or destruction of old computers and mobile devices.
  • Media storage: Encrypted backup media stored in a secure, off-site location.

Technical safeguards

These are the software features your vendor has to provide. Ask prospective vendors directly about each one:

  • Encryption: AES-256 for data at rest, TLS 1.2+ for data in transit. Verify key management practices.
  • Multi-factor authentication: MFA enforcement for all staff accessing PHI, especially remote access.
  • Audit logging: Activity logs capturing who accessed which records, when, and what they did. Logs retained for 6 years.
  • Access controls: Role-based permissions, automatic session timeouts (typically 15 to 30 minutes), and unique user identifiers.
  • Data integrity: Mechanisms that stop PHI being altered or deleted without authorization, such as checksums.

Business Associate Agreements and vendor evaluation

Any vendor that handles PHI must provide a signed Business Associate Agreement. The BAA is a legal contract. It specifies how the vendor will protect PHI, what happens in a breach, and what audit rights your practice keeps. Shortlisting goes faster when you start from HIPAA compliance software that already publishes its controls.

When you evaluate a vendor’s BAA, verify it includes:

  • An explicit description of the vendor’s PHI handling role and permitted uses.
  • Safeguard requirements aligned with the Security Rule: encryption, access controls, audit logs.
  • Breach notification obligations, typically within 30 days of discovery.
  • Your right to audit them and request a security assessment report, often a SOC 2 Type II or ISO 27001 certification.
  • Data return or destruction procedures once the contract ends.
  • Subcontractor requirements, so the vendor also obtains BAAs from any downstream vendors.

Request the vendor’s SOC 2 Type II audit report, then ask about their encryption, backup, and incident response procedures. A reputable vendor hands these over without pushback.

Common compliance mistakes to avoid

The failures that come up most often:

  • No BAA: Using a vendor’s software without a signed BAA, even for a trial or a limited pilot. This is a direct HIPAA violation.
  • Unencrypted backups: Storing PHI backups on USB drives or external hard drives without encryption.
  • Weak or no MFA: Letting staff reach PHI with a username and password only, with no second factor.
  • No audit logging: Running software that cannot capture or export access logs, which blocks both compliance checks and breach investigation.
  • Untrained staff: Failing to document annual HIPAA training for every team member who touches PHI.
  • No incident response plan: Having no written procedure for detecting and reporting breaches inside the 60-day notification window.

Training is the item that slips most often, because it has to be repeated and recorded every year. Our guide to HIPAA training for employees covers what to teach and how to evidence it.

Encryption and access controls in detail

Two technical requirements deserve a closer look.

Encryption standards. HIPAA classifies encryption as “addressable”, which means you either implement it or document why you have not. In practice, every vendor handling PHI should support AES-256 encryption at rest and TLS 1.2 or higher in transit.

Ask three questions. Which algorithm do they use, who holds the encryption keys, and is data encrypted by default or only after setup? Walk away from any vendor that stores passwords in plaintext or sends PHI over unencrypted connections.

Access controls and least-privilege access. HIPAA requires that staff reach only the minimum PHI their role needs. A front-desk scheduler should not see clinical notes, and a clinical support assistant should not see billing records.

Check that the vendor supports granular role-based access control, where you define roles such as receptionist, clinician, and billing staff, then assign permissions to each. Test it before go-live by creating a clinician account and confirming it cannot open records outside its role.

How to use the checklist during an evaluation

Download the sheet, then work through these five steps with each vendor on your shortlist:

  1. Request vendor documentation: Ask each prospective vendor for their Security Rule compliance summary, BAA template, and SOC 2 Type II report. Most reputable vendors send these within a few business days.
  2. Review administrative safeguards: Confirm their documentation describes workforce training, incident response procedures, and risk assessment updates. Look for evidence of practice, not a checkbox response.
  3. Verify technical safeguards: Work through the encryption, MFA, and audit logging sections with their technical team. Request a demo of the audit log export so you can judge its detail and retention.
  4. Review the BAA with legal counsel: Have your practice’s legal advisor check the vendor’s BAA against HIPAA requirements. This protects you if a breach happens.
  5. Pilot and audit: Before full rollout, run a 30-day pilot with a subset of staff. Export audit logs halfway through and confirm the detail is there. Test MFA on staff devices before you mandate it site-wide.

Step one goes faster when you already know your own exposure. A HIPAA risk assessment maps where PHI sits in your practice, so you can question vendors about the systems that actually hold it.

Do I need a BAA with every software vendor I use?

Yes, if the vendor can reach any PHI, you need a signed BAA. That covers your electronic health record (EHR), patient portal, billing software, telehealth platform, and scheduling system. It also covers your email service when PHI is discussed in email, and your IT support vendor when they can reach your servers.

There is one exception. Vendors who never touch PHI directly, such as your office cleaning service, do not need a BAA. Tell them anyway that they must not disclose any PHI they happen to see.

What happens if my software causes a HIPAA breach?

Both you and the vendor are liable. The vendor must notify you immediately under the BAA, and you then have 60 days to notify affected patients and the HHS OCR. The HHS will investigate, may fine both parties, and can issue corrective action orders.

Choosing a vendor that documents its own HIPAA compliance lowers your breach risk without removing it. Access controls, staff training, and incident response stay your responsibility.

How Pabau keeps your compliance evidence in one place

Most practices assemble compliance evidence after the fact. Access logs come out of one system, training records out of a spreadsheet, and signed consent forms out of an email inbox. Pulling that together for an investigation costs days nobody planned for.

Practice management software like Pabau holds those records in one system instead. Patient data is encrypted in storage, and account activity is logged as staff open, edit, and share records. Role-based permissions decide who sees clinical notes and who sees only the schedule.

Pabau claims and billing dashboard
Billing is one of the systems that needs a BAA. Running claims inside Pabau keeps them under the same permissions and audit log as clinical notes.

The result is that the evidence an evaluation asks for already exists. You can show who opened a record and when, without reconstructing the answer from three separate tools.

Keep your compliance evidence in one system

Pabau encrypts stored patient data and logs every account action against the patient record. Access histories, consent forms, and treatment notes sit in one place, which makes vendor audits and OCR requests quicker to answer.

Pabau practice management dashboard

Conclusion

The vendors worth shortlisting are the ones that answer these questions in writing, on request, without a sales call in between. Treat a vague answer on encryption, audit logs, or the BAA as the finding, and move on to the next vendor.

Remember that a signed BAA moves some of the work to your vendor, not all of it. Training, access reviews, and incident response stay in your practice, so run the checklist again at your annual review rather than filing it after procurement. Book a demo to see how Pabau keeps encrypted patient records and account audit trails in one place for your team.

Continue your research

Continue your research

List Item #1

List Item #2

Frequently asked questions

Is HIPAA compliance certification required?

No, HIPAA has no official certification body, so vendors cannot be “HIPAA certified.” Look instead for vendors who can demonstrate compliance in writing. Ask for a SOC 2 Type II audit report, a signed BAA, and documentation of their technical and administrative safeguards.

Does a Business Associate Agreement guarantee HIPAA compliance?

A BAA is necessary but not sufficient. The BAA is a contract, and compliance depends on the vendor implementing the safeguards it promises. Verify the vendor’s technical controls independently, so ask for encryption details, MFA requirements, and audit log capabilities before signing.

How often should I audit my HIPAA-compliant software vendor?

At minimum annually, or whenever your software stack or vendor changes significantly. Request the most recent SOC 2 Type II report, which is typically issued once a year. Then review your audit logs and confirm MFA is still enforced. Document each audit as evidence of your compliance work.

Can AI tools and LLMs handle PHI under HIPAA?

Only if they have a signed BAA with your practice or with your covered entity. AI note-takers and LLM tools that read clinical notes are subject to HIPAA. Verify that the AI vendor’s BAA explicitly covers your use case before any PHI is processed.

What is the difference between HIPAA administrative, physical, and technical safeguards?

Administrative safeguards are policies and procedures, such as training, risk assessment, and workforce sanctions. Physical safeguards protect buildings and devices through facility access, workstation locks, and secure disposal. Technical safeguards are software features such as encryption, MFA, and audit logs. All three are required.

Found our content helpful?
×