HIPAA compliance software is a system of record for the work the HIPAA Security, Privacy and Breach Notification Rules ask you to do and to prove you did: the risk analysis, the policies, the business associate agreements, the training records, the access reviews and the incident log. It is useful because 45 CFR 164.316 requires that work to be documented and kept for six years. It is not a way to become compliant, and no product can make you HIPAA certified, because HHS does not recognise any certification.
This guide maps what the software does to the sections of the regulation it supports, names the one contract you need from the vendor before you upload anything, and points at the free tool HHS itself publishes. It is written for the first compliance hire or the engineering lead at a covered entity or a business associate who has been asked to pick a platform.
What HIPAA compliance software actually does
Every feature worth paying for maps to a requirement in 45 CFR Part 164. The ledger below lists the requirements where software genuinely helps, what it helps with, and what stays your job regardless of the tool. Text quoted from eCFR, up to date as of 28 September 2026.
- 164.308(a)(1)(ii)(A)Risk analysisThe regulation asks for "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI. Software gives it a structure and a record. The judgement about your systems is still yours.Required
- 164.308(a)(1)(ii)(D)Information system activity reviewRegular review of logs, access reports and incident tracking. Software can schedule the review and hold the evidence that it happened.Required
- 164.308(a)(5)Security awareness and trainingTracking who completed training and when. The content of the training is still something you choose.Standard
- 164.308(a)(8)EvaluationPeriodic technical and non-technical evaluation of your policies against the rule. Software keeps the cycle and the findings in one place.Required
- 164.308(b)(1)Business associate contractsA register of every vendor that touches PHI, with the BAA attached and its renewal tracked.Required
- 164.312(b)Audit controlsSoftware can collect the evidence that audit logging exists. It does not implement logging in your own systems.Required
- 164.316(b)(2)(i)Six-year retentionDocumentation kept "for 6 years from the date of its creation or the date when it last was in effect, whichever is later". This is where a system of record earns its keep.Required
- 164.404(b)Breach notification timingNotice to individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach". Software can run the clock and the assessment record.60 days
Notice what is missing from that list: anything that changes your infrastructure. Encryption, access control, automatic logoff and unique user IDs under 164.312 are implemented in your own systems. The best a compliance platform does there is check that they are configured and keep the proof.
There is no HIPAA certification, so software cannot give you one
Vendors in this category use the words "HIPAA certified" and "HIPAA compliant platform" loosely. HHS has answered the question directly in its Security Rule FAQ, last reviewed 26 July 2013 and still published.
HHS does not endorse or otherwise recognize private organizations’ “certifications” regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule.
HHS, "Are we required to certify our organization’s compliance with the standards of the Security Rule?"
The same answer explains what the regulation does require instead: the evaluation standard at 164.308(a)(8), a periodic technical and non-technical evaluation, which "can be performed internally by the covered entity or by an external organization". Software supports that evaluation. It is not the evaluation, and a badge on a vendor website says nothing about your own compliance.
The vendor is probably your business associate
Evidence has a way of containing PHI. A screenshot of an access review, a support ticket attached to an incident, an export of a log. The moment a compliance platform stores any of that for you, it is maintaining ePHI on your behalf, and HHS guidance on cloud computing, last reviewed 23 December 2022, is clear that this makes it a business associate even if it never looks at the data.
An entity that maintains ePHI on behalf of a covered entity (or another business associate) is a business associate, even if the entity cannot actually view the ePHI.
HHS, Guidance on HIPAA and Cloud Computing
So the first question to any vendor is not about features. It is whether they will sign a BAA, on which plan, and before or after you start uploading. Get the answer in writing, and put it in the same BAA register the software is supposed to keep for your other vendors.
The features that matter for HIPAA, and the questions to ask
Most compliance platforms were built for SOC 2 and added HIPAA later. That is fine, because the evidence overlaps heavily, but it means the HIPAA-specific parts deserve their own questions.
- 164.308(b)(1)BAA with the vendorRequired before PHI is stored with them, per the rule and HHS cloud guidance. Ask: which plans include a BAA, and can it be signed before onboarding?
- 164.306(d)(3)Required versus addressable trackingAddressable specifications need a documented decision. Ask: can I record the decision and the alternative measure for each specification?
- 164.308(a)(1)(ii)(A)Risk analysis workflowThe foundation of the Security Rule. Ask: does it hold the method, the findings and the risk management plan together?
- 164.308(b)(1)BAA register for your vendorsEvery subcontractor that touches PHI needs one. Ask: does it track expiry and renewal, and flag vendors with no BAA on file?
- 164.316(b)(2)(i)Six-year retentionA six-year obligation outlives most software contracts. Ask: what happens to my evidence if I cancel, and can I export all of it?
- 164.404(b)Breach assessment recordThe 60-day notification clock. Ask: does it record the discovery date, the risk assessment and each notice sent?
The free option: the HHS Security Risk Assessment Tool
Before you pay for anything, know that HHS publishes a free tool for the single most important requirement. The Security Risk Assessment Tool, developed by the Office of the National Coordinator for Health IT with the HHS Office for Civil Rights, is a downloadable application and Excel workbook, currently version 3.7, aimed at small and medium-sized healthcare providers.
It is honest about its limits. The HealthIT.gov page states that "use of this tool is neither required by nor guarantees compliance with federal, state or local laws", and that it may not be appropriate for larger organisations. For a small practice that needs a structured risk analysis and nothing else, it may be all the software required.
- Use the SRA Tool if you are a small provider, your main gap is the risk analysis, and you can keep policies, BAAs and training records in an organised shared drive.
- Use a compliance platform if you are a business associate selling to health systems, you also need SOC 2 or ISO 27001, or the evidence is spread across cloud accounts, HR systems and ticketing tools.
- Use neither on its own if nobody owns the programme. Software records decisions; it does not make them.
What HIPAA compliance software cannot do
- It cannot certify you. HHS recognises no certification, and a vendor badge is not evidence of your compliance.
- It cannot decide your addressable specifications. It can record the decision; a person has to make it and justify it.
- It cannot implement technical safeguards. Encryption, access control and logging live in your own systems.
- It cannot train your workforce. It can track who completed training; the content and the culture are yours.
- It cannot tell you whether an incident is a breach. The four-factor risk assessment is a judgement, and the software only records it.
Where Evidr fits, and when it is the wrong choice
Evidr tracks the administrative, physical and technical safeguards with evidence collection, runs breach assessment workflows against the Breach Notification Rule timelines, tracks BAAs with your vendors and their expiry, tracks workforce training completion, and holds the risk assessment with its remediation. HIPAA is one of the 14 frameworks included on every plan, so the same evidence can serve a SOC 2 or ISO 27001 programme at the same time.
On the contract question: Evidr’s security page states that it offers Business Associate Agreements on the Growth and Enterprise plans, and asks customers to set one up before processing any PHI. Growth is $499 a month billed annually, and AI usage is billed separately as pay-as-you-go. There is a free Starter plan for looking around before any PHI is involved.
The case against us is simple. If you are a small practice and your only real gap is the risk analysis, the HHS SRA Tool is free and was built for exactly that, and paying $499 a month would be hard to justify. And if you need a BAA on the Professional plan, the security page does not list one there today, so ask before you choose that tier.