Screenata

Beyond SOC 2

What is HIPAA compliant software?

August 18, 20262 min read

What is HIPAA compliant software?

No software is HIPAA compliant on its own. HIPAA imposes obligations on organisations, specifically covered entities and their business associates, not on products. What exists is software that can be used in a compliant way: it provides the safeguards the Security Rule requires, and the vendor will sign a business associate agreement. Compliance is a property of your organisation and its contracts, not a feature of a tool.

What to actually check in a vendor

RequirementWhat to ask for
Signed BAAWill they sign one, without an enterprise upgrade? This is the gate.
Access controlUnique user IDs, role-based access, no shared accounts
Audit loggingRecords of who accessed PHI, when, and what they did
EncryptionIn transit and at rest
Automatic logoffSessions terminate after inactivity
Integrity controlsPHI cannot be improperly altered or destroyed undetected
Backup and recoveryRetrievable exact copies, tested
SubcontractorsTheir subprocessors carry obligations too, under the Omnibus Rule

The BAA is the one that decides it. A product with every technical safeguard and no BAA cannot be used with PHI. A product with a BAA and weak safeguards puts you in breach through your own risk analysis. You need both, and the BAA is the one people forget to check until procurement.

There is no HIPAA certification

HHS does not certify, accredit, or endorse any product, vendor, or organisation. A "HIPAA certified" badge is either self-issued or issued by a private company with no regulatory standing.

What healthcare buyers accept instead:

  1. A signed BAA, which is a contract rather than a certificate
  2. A SOC 2 Type II report, often with HIPAA criteria mapped into scope
  3. Your risk analysis and safeguard documentation

See how much does HIPAA certification cost for what the alternatives actually cost.

If you are building the software

You are likely a business associate with direct legal obligations the moment you handle PHI for a covered entity, regardless of your size. That means a documented risk analysis, implemented safeguards, signed BAAs both upstream and downstream, and evidence that all of it operates.

The Security Rule's safeguards overlap heavily with the SOC 2 Common Criteria, particularly CC6 for access control and CC7 for operations, which is why most healthcare SaaS vendors pursue SOC 2 and map HIPAA into it rather than running two programmes. See what controls overlap between SOC 2, ISO 27001, and HIPAA.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.