
Can Your Current Software Be Made HIPAA Compliant in 2026?
A practice administrator at a dental group in Hialeah called us last spring with a question that comes up more than you'd think. Her office had been using the same scheduling and billing platform for three years. When cyber insurance renewal came around, the insurer asked for proof that the software handling patient records was HIPAA-compliant. She had assumed the vendor took care of that. She was wrong, and the gap cost her weeks of frantic documentation and a delayed renewal.
That assumption, that compliance lives in the software and not in how you use it, is one of the most common and expensive mistakes healthcare practices make. HIPAA doesn't certify software. It regulates your practice. The tools you use are part of the picture, but they're not the whole picture, and signing up for a "HIPAA-friendly" EHR doesn't mean your practice is compliant.
Here's the question worth answering properly: can the software you already have be configured, documented, and used in a way that satisfies HIPAA's requirements? For most practices, the answer is yes, but with conditions. This guide walks you through what those conditions are and how to find out where your stack stands today.
Key Takeaways
- HIPAA compliance is a shared responsibility. Your software vendor provides the platform; your practice is responsible for configuration, documentation, and training.
- A Business Associate Agreement (BAA) is the minimum legal requirement before any vendor can access, process, or store protected health information on your behalf.
- Most purpose-built healthcare software, EHRs, practice management tools, and billing platforms, can meet HIPAA's technical safeguards when properly configured.
- General-purpose tools like standard email, messaging apps, and consumer cloud storage almost always require enterprise-grade upgrades or should be replaced.
- A structured gap assessment of your current stack is the fastest way to know where you stand before a breach, an audit, or an insurance renewal forces the issue.
What HIPAA Actually Requires from Your Software
Before you can evaluate your software, you need a clear picture of what HIPAA actually demands at the technical level. Most practice administrators have heard the broad strokes, but the specifics matter when you're reviewing a vendor contract or configuring a system.
The Three Safeguard Categories
HIPAA's Security Rule breaks down into three types of safeguards: administrative, physical, and technical. Software plays a central role in the technical safeguard category, but administrative safeguards (policies, training, risk assessments) and physical safeguards (workstation security, facility controls) are equally required. A compliant EHR doesn't absolve you of writing and enforcing access policies.
Technical safeguards under the Security Rule include: access controls that limit who can view protected health information (PHI), audit controls that log who accessed what and when, integrity controls that prevent PHI from being altered or destroyed without detection, and transmission security that protects PHI when it's sent over networks. Your software needs to support all four, but your practice needs to turn them on and use them correctly.
Technical Safeguards in Plain Language
Think of it this way. Access controls mean unique logins for every user, no shared passwords, and role-based permissions so a front-desk staffer doesn't see the same data as a physician. Audit controls mean the system keeps logs, and you review them. Integrity controls mean data isn't quietly corrupted or deleted. Transmission security means any data leaving your system, whether it's going to a billing clearinghouse or another provider, is encrypted in transit.
If your software can do all of that and you've configured it to do all of that, you've met the technical safeguard requirements. The gap for most practices isn't capability; it's configuration and documentation.
Actionable tip: Pull up your EHR's admin settings today and verify that unique user accounts are active for every staff member, that shared or generic logins have been disabled, and that audit logging is turned on.
Does Your Vendor Count as a Business Associate?
This is where a lot of practices get tripped up. A business associate is any vendor or contractor who creates, receives, maintains, or transmits PHI on your behalf. If your software vendor's system touches patient data, they're almost certainly a business associate, and HIPAA requires you to have a signed Business Associate Agreement with them before you start sharing data.
Who Needs to Sign a BAA
The list is longer than most practices expect. Your EHR vendor, yes. Your billing company or clearinghouse, yes. Your cloud backup provider if it stores patient records, yes. Your telehealth platform, yes. Your IT managed services provider if they have access to systems that store PHI, yes. Any cloud storage service where PHI might land, yes.
Many major vendors, including Google, Microsoft, and several EHR companies, will sign a BAA if you're on a qualifying business or enterprise plan. A BAA from these vendors doesn't make the entire product HIPAA-compliant by itself, but it establishes the legal foundation you need and commits the vendor to specific security and breach notification obligations.
What Happens When There's No BAA
Operating without a BAA when one is required is a HIPAA violation regardless of whether a breach ever occurs. OCR (the Office for Civil Rights) has levied fines specifically for missing BAAs independent of any data exposure. If you're storing PHI in a system and haven't confirmed whether the vendor will sign a BAA, that's the first thing to fix. Some vendors, particularly consumer-grade services, won't sign one. If that's the case, the PHI has to move.
I sat with a practice manager last fall who had been storing scanned insurance documents in a consumer Dropbox account for two years. The vendor wouldn't sign a BAA, and there was no question about whether it was compliant. The answer was no. We migrated the files to a BAA-covered storage solution in a week, but the prior exposure was a documented risk that had to be disclosed in their next risk assessment.
Actionable tip: Create a simple spreadsheet listing every third-party tool or service that touches patient data. For each one, confirm whether a BAA is signed and on file. If you don't have a copy, request one now.
Auditing Your Current Stack
Once you understand what HIPAA requires and who your business associates are, the next step is to walk through your actual software stack and evaluate each tool against those requirements. Most practices find a mix of tools that are fine as configured, tools that need configuration changes, and tools that need to be replaced.
Clinical Tools: EHRs, Practice Management, and Billing Platforms
Purpose-built clinical software is typically your best starting point. Major EHR vendors design their platforms to support HIPAA's technical requirements, and most offer BAAs as a standard part of their contracts. The work here is mostly on your end: ensuring user accounts are set up correctly, audit logs are reviewed periodically, and access permissions reflect actual job roles.
One area that often gets missed is former employee access. When a staff member leaves, their account should be deactivated immediately. In practices without a formal offboarding checklist, it's common to find active credentials for people who left months or years ago. That's a Security Rule violation waiting to become a breach report.
Our compliance management services include a full access review as part of the initial assessment, specifically because this gap is so common in small and mid-sized practices.
Communication Tools: Email, Messaging, and File Sharing
This is where most practices have the most exposure. Standard consumer email, even from reputable providers, is not HIPAA-compliant by default. Standard text messaging is not HIPAA-compliant. WhatsApp, Signal, and similar consumer messaging apps are not HIPAA-compliant regardless of their encryption claims, because the vendor won't sign a BAA.
Google Workspace and Microsoft 365 both offer HIPAA-compliant configurations, but only on qualifying enterprise tiers, and only if you've configured specific security settings and signed a BAA with Google or Microsoft directly. If your practice is using the basic version of Gmail or Outlook, those BAAs don't apply. The fix is either upgrading to the enterprise tier or using a dedicated HIPAA-compliant email service. Our managed IT services include configuration and management of Microsoft 365 environments specifically for healthcare compliance requirements.
Storage and Backup
Every system that stores PHI, whether it's an on-premises server, a cloud backup, or a shared network drive, needs to meet the same safeguard requirements and carry a BAA. Consumer cloud storage (standard Dropbox, iCloud, Google Drive without Workspace) won't sign a BAA and should not be used for PHI under any circumstances.
For backup specifically, the Security Rule's contingency plan requirements mean you need documented, tested backup and recovery procedures. It's not enough to have a backup running; you need to know it works and have a plan for restoring operations if your primary system goes down. Learn more about how we approach cybersecurity and data protection for healthcare environments.
Actionable tip: Run a search in your cloud storage tools for common PHI file types (scanned forms, insurance cards, lab results, patient intake PDFs). If any land in a non-BAA-covered storage location, move them immediately and document the remediation.
Common Software That Fails HIPAA by Default, and How to Fix It
Some tools are used in virtually every healthcare practice but require specific steps before they can legally touch PHI. Here's how to handle the most common ones.
Standard Gmail or Outlook
Free Gmail and personal Outlook accounts are not HIPAA-compliant and cannot be made compliant because the vendors won't sign a BAA at those tiers. The fix is moving to Google Workspace Business Plus or above (with a signed BAA from Google) or Microsoft 365 Business Premium or above (with a signed BAA from Microsoft and the appropriate admin-level security configuration). Both paths require someone to actually complete the BAA process and configure the relevant security settings. Neither happens automatically on upgrade.
Standard Video Platforms
Zoom's healthcare plan and Microsoft Teams (with a proper Microsoft 365 enterprise BAA) can be used for telehealth and care coordination. Standard consumer Zoom accounts cannot be used for any PHI-containing conversations. If your providers are running telehealth visits from a personal Zoom account, that's a violation to address immediately. The fix is either moving to Zoom for Healthcare or using a purpose-built telehealth platform that comes with a BAA built in.
Consumer Cloud Storage
Standard Dropbox Personal, iCloud, and Google Drive outside of Workspace cannot be used for PHI. Dropbox Business Advanced and Dropbox Business Plus offer BAAs. Google Workspace at qualifying tiers includes PHI-eligible storage covered by Google's BAA. OneDrive within a properly configured Microsoft 365 enterprise subscription is also covered. The common failure mode is staff using personal storage accounts out of habit or convenience. A clear written policy and regular reminders are required; the technical access control to prevent it is to ensure PHI only lives in approved, BAA-covered systems.
Actionable tip: Add a one-paragraph statement to your employee handbook specifying which storage and communication tools are approved for PHI and which are prohibited. Have every staff member sign it annually.
What to Do When Your Software Can't Be Made Compliant
Not every tool can be upgraded or configured into compliance. Some vendors simply won't sign a BAA. Some tools lack the technical capability to support audit logs, access controls, or encryption. When that's the case, the path forward is straightforward: the PHI has to move out of that tool, or the tool has to stop being used for PHI-related work.
The key is having an accurate inventory of where PHI lives before you're forced to figure it out under pressure. A breach investigation or an OCR audit is not when you want to discover that patient records were stored in a non-compliant system for two years. A proactive technology assessment for your healthcare practice is how you find and close those gaps on your schedule, not the regulator's.
If your practice is due for a risk assessment (OCR requires one at least annually) or your team is unsure where your current stack stands, that's the right starting point. We work with medical practices, dental offices, behavioral health providers, and home health agencies throughout South Florida to complete structured HIPAA risk assessments and remediation plans. See how we approach co-managed IT for healthcare organizations that already have some internal IT resources but need compliance support.
Ready to find out exactly where your software stack stands? Book a free workflow and security assessment and we'll walk through your current tools with you and give you a clear picture of what's compliant, what needs to change, and what the remediation looks like.
Frequently Asked Questions
Does using a HIPAA-certified EHR mean my practice is HIPAA compliant?
No. There's no official HIPAA certification for software. When vendors describe their product as "HIPAA-certified" or "HIPAA-ready," they mean the platform is built to support HIPAA's technical requirements. Whether your practice is compliant depends on how you configure the software, how your staff uses it, and whether you've completed required administrative safeguards like risk assessments, policies, and training. The software is a tool; compliance is a practice-level responsibility.
Can I use Google Workspace or Microsoft 365 in a healthcare practice?
Yes, but only on qualifying enterprise tiers and only after signing a BAA with Google or Microsoft directly. You also need to configure specific security settings (multi-factor authentication, data loss prevention, audit logging) that are not enabled by default. If you're on a basic plan or haven't signed a BAA, those tools should not be used for PHI. Reach out to your IT provider to confirm your current configuration before assuming you're covered. We've helped dozens of South Florida practices audit their Microsoft 365 setup as part of our compliance management engagements.
What happens if I use non-compliant software and there's a breach?
OCR investigates every reported breach affecting 500 or more individuals and selects a percentage of smaller breaches for investigation as well. If a breach investigation reveals that PHI was stored in a non-compliant system without a BAA, the practice faces civil monetary penalties that can range from a few hundred dollars per violation for unknowing violations to $50,000 per violation for willful neglect. Beyond the fines, the remediation costs, legal fees, and reputational damage are typically far more expensive. The cost of getting compliant now is almost always less than the cost of responding to a breach.
How often should I review my software stack for HIPAA compliance?
OCR requires a risk analysis at least annually, but in practice your stack should be reviewed any time you add a new tool, change vendors, or have a significant change in how you store or transmit PHI. Staff onboarding and offboarding are also trigger points: new staff may introduce personal tools they're used to, and departing staff accounts need immediate deactivation. A quick quarterly review of your vendor list and BAA status takes less than an hour and catches most drift before it becomes a problem.
Who is responsible for ensuring my software is HIPAA compliant?
Your practice is the covered entity under HIPAA, which means ultimate responsibility sits with the practice owner or designated privacy officer. Vendors are business associates and share responsibility for the portions of the data they handle, but they can't make your practice compliant. An IT managed services provider who specializes in healthcare can configure and manage your technical environment, but your practice still needs to maintain the administrative safeguards, train staff, and document your risk management decisions. HIPAA compliance is a team effort across your practice, your vendors, and your IT provider.
Ready to Know Where Your Practice Stands?
Most practices aren't starting from zero. You already have software in place, and most of it can probably be configured or adjusted to meet HIPAA's requirements. The goal isn't to replace everything; it's to know what you have, close the gaps that exist, and document that you've done the work.
If your practice hasn't done a formal review of your software stack against HIPAA's technical safeguard requirements, or if you're not sure whether all your vendors have signed BAAs, that's the place to start. We work with healthcare practices throughout the Miami metro to complete structured compliance assessments and build remediation plans that don't require a full technology overhaul.
Schedule a free assessment and let's take a look at your current setup together. You'll leave the call with a clear picture of where you stand and a prioritized list of what to fix first.
