HIPAA Checklist for Choosing Medical Software: 10 Questions to Ask Vendors
Every medical software decision is also a security decision. The moment patient information enters a vendor’s system, your practice’s regulatory exposure and your patients’ privacy ride on choices that vendor made — and on questions you did or didn’t ask before signing.
This guide is a practical checklist for that conversation. One important framing note: this is educational content, not legal advice. HIPAA obligations depend on your specific circumstances, and a qualified compliance professional or healthcare attorney is the right source for decisions about your practice. What follows will make you a sharper questioner — which is exactly what vendor conversations require.
The background in three paragraphs
HIPAA — the Health Insurance Portability and Accountability Act — establishes national standards for protecting health information in the U.S. Its Privacy Rule governs how protected health information (PHI) may be used and disclosed; its Security Rule requires administrative, physical, and technical safeguards for electronic PHI; and its Breach Notification Rule dictates what happens when protections fail.
Two roles matter for software shopping. Your practice is a covered entity. A software vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate — and HIPAA requires a written Business Associate Agreement (BAA) between you before that data flows.
One myth to discard immediately: there is no official “HIPAA certification” for software. The government certifies nothing of the sort. Vendors displaying “HIPAA Certified!” badges are, at best, summarizing an internal assessment. The checklist below is how you evaluate the substance instead of the badge.
The 10-question vendor checklist
1. “Will you sign a BAA, and can I read it before signing the contract?”
The gate question. No BAA, no PHI — end of evaluation. Also read the BAA itself: check whether it covers all services you’re buying (some vendors exclude certain modules or free tiers), and what it promises about breach notification timelines.
2. “Is data encrypted both in transit and at rest?”
Encryption in transit (TLS) protects data moving between your browser and their servers; encryption at rest protects stored data. Both should be unambiguous yeses, with current standards. Vague answers about “bank-level security” without specifics are a signal to dig further.
3. “What access controls and authentication do you support?”
You’ll want, at minimum: unique logins per user (never shared accounts), role-based permissions so the front desk doesn’t see what only clinicians should, automatic session timeouts, and multi-factor authentication — ideally enforceable for all users, not merely available.
4. “What do your audit logs capture, and can I access them?”
HIPAA’s Security Rule expects mechanisms to record and examine system activity. Practically: can you see who viewed which record and when? Can you run a report when you suspect snooping? Logs the vendor keeps but you can’t access are only half useful.
5. “Where is our data stored, and who are your subcontractors?”
Cloud vendors run on infrastructure providers and third-party services — each handling PHI should be covered by the vendor’s own downstream BAAs. Ask where data centers are located and whether data ever leaves the U.S. Clear answers here indicate a vendor that has actually mapped its data flows.
6. “What third-party security attestations do you hold?”
Since no HIPAA certification exists, serious vendors demonstrate security through recognized frameworks: SOC 2 reports, HITRUST certification, or ISO 27001. These aren’t legally required, and small vendors may reasonably lack the fancier ones — but a vendor with none of them, and no substantive answer about security program maturity, is asking for trust on faith.
7. “What is your breach history and notification process?”
Past breaches aren’t automatically disqualifying — response quality matters more than a spotless record. Ask directly: have you had reportable incidents? How were customers notified, and how fast? What’s the committed notification timeline in the BAA? (Large breaches of health data are publicly searchable on the HHS breach portal, so answers here are checkable.)
8. “How do backups and disaster recovery work?”
Ransomware against healthcare organizations is common enough that recovery capability is now a core purchasing criterion. Ask about backup frequency, where backups live (isolated from production?), tested recovery time, and whether recovery drills actually happen.
9. “How do we get our data out, and what does it cost?”
Data portability is both an operational and a compliance issue — you retain records-retention obligations long after you leave a vendor. Nail down export formats, timelines, costs, and post-termination data destruction in the contract, before signing, when your leverage is at its peak.
10. “What compliance responsibilities remain ours?”
A trustworthy vendor answers this candidly, because the honest answer is “many.” Software cannot conduct your risk analysis, train your staff, set your policies, or stop an employee from writing a password on a sticky note. Vendors who imply their product “makes you compliant” are overpromising — and that overpromise tells you something about their other claims.
Red flags worth walking away from
- Refusal or evasiveness about signing a BAA
- “HIPAA certified” as the centerpiece of security marketing, with no substance beneath
- Shared logins presented as a normal workflow
- No MFA support in the current decade
- Inability to name where data is stored or who subcontractors are
- Export terms they’ll “work out later”
Bottom line
You don’t need to become a security engineer to buy medical software safely — you need a vendor who has done that work and can prove it under direct questioning. The BAA is the gate; encryption, access controls, audit logs, attestations, and exit terms are the substance. Ask all ten questions, in writing where possible, and keep the answers with your compliance documentation — the paper trail itself is part of doing this properly.
For how these security questions fit into the broader selection process, our small-practice software guide and practice management buyer’s guide cover the full evaluation.
Frequently Asked Questions
- Is there such a thing as HIPAA-certified software?
- No. The U.S. Department of Health and Human Services does not certify software as HIPAA compliant, so "HIPAA certified" badges are marketing language, not official designations. What matters is whether the vendor signs a Business Associate Agreement, implements appropriate safeguards, and whether your practice uses the software in a compliant way.
- What is a Business Associate Agreement (BAA)?
- A BAA is a contract required under HIPAA between a covered entity (like a medical practice) and a vendor that handles protected health information on its behalf. It obligates the vendor to safeguard the data and report breaches. If a vendor that will touch patient data will not sign a BAA, that product is generally not usable for patient information.
- Does using compliant software make my practice HIPAA compliant?
- No — software is only one layer. Compliance also depends on your practice's policies, staff training, access management, risk analysis, and day-to-day behavior. Well-configured software makes compliance achievable; it cannot make it automatic. For obligations specific to your practice, consult a qualified compliance professional or attorney.
- Are cloud-based EHRs safe for patient data?
- Reputable cloud vendors typically offer stronger security than a small practice can achieve with an office server — professional monitoring, encryption, redundancy, and dedicated security teams. The key is verifying the specifics: BAA, encryption practices, access controls, audit logging, and third-party security attestations rather than assuming either cloud or on-premises is inherently safer.
- What happens to patient data if I cancel the software?
- That depends on your contract, which is why export terms should be negotiated before signing. Ask in what format you can export records, how long the vendor retains data after termination, what export costs, and how data is destroyed afterward. Records-retention requirements for your state and specialty continue to apply regardless of which vendor holds the data.