Logo Menu

16 platforms Β· Last updated

HIPAA compliance software, and the BAA question nobody answers

No software is HIPAA certified, because HHS certifies nothing and says so directly. Several SOC 2 platforms automate the Security Rule work: risk analysis, workforce training, policy management and business associate tracking. The question that actually decides your shortlist is whether the vendor will sign a business associate agreement with you, and most do not say.

Eligible: core SOC 2 platforms whose registry record carries a HIPAA framework claim. This is nearly the same set as our PCI DSS listing, which is honest rather than lazy: framework support is the gate for a framework page. The two pages part company at the table below, which asks a question the PCI page does not.

The deciding question

Will the platform itself sign a BAA with you, and what does it actually ship for HIPAA

Almost every vendor here markets a feature that helps you track business associate agreements with your own downstream vendors. That is a different question from whether the platform is your business associate. If it touches your PHI it must sign a BAA with you, and if it does not touch PHI it should be able to explain why. We went looking for a published answer from each of these vendors on 2026-07-24. One says no outright, one contradicts itself, and the rest say nothing at all. "Not established" below means we found no public statement either way, not that the answer is no.

PlatformWill it sign a BAA with youNames a HIPAA risk analysis featureOther HIPAA-specific artifacts it names
Comp AI Not establishedNot statedIts HIPAA content hub currently publishes no articles, which is a fair read on depth
Vanta No, and it says so plainly: it states it does not process PHI, so a BAA is not required and it does not sign themYesWorkforce training, guided controls, a vendor and BAA tracker for your own vendors
Secureframe Its own support documentation answers both ways: one entry says no BAA is needed, another says it maintains BAAs with customersNot statedBAA sending, e-signature and tracking for your vendors, a training module
Drata Not established. Its own blog offers a compliance automation company as an example of a business associate, but publishes no BAA commitmentNot statedNot established beyond framework coverage
Sprinto Not established. Its public HIPAA content explains what a BAA is rather than committing to sign oneNot statedTrust center
Scytale Not establishedYes, named explicitly as a HIPAA risk assessmentNot established
Thoropass Not established. Its published data processing addendum contains no HIPAA or BAA languageYesWorkforce training, incident response, business associate management
Scrut Automation Not established. Its published data processing addendum contains no HIPAA or BAA languageYes, automatedPHI workflow mapping, employee HIPAA training
ComplyJet Not established. Its own copy frames BAA tracking as managing agreements with your vendors, not with itselfYes, named as a required Security Rule deliverableAutomated workforce training with acknowledgement tracking, BAA tracking
Strike Graph Not establishedYesBreach notification protocol
Carbide Not establishedNot statedVendor and BAA tracking as you add vendors, with an advisor layer over it
TrustCloud Not establishedNot statedGap analysis across HIPAA and other frameworks
Anecdotes Not establishedNot statedRisk, policy and control correlation, continuous testing
Apptega Not establishedNot statedPre-built HIPAA questionnaires and assessment templates
Trustero Not establishedNot statedNot established beyond framework coverage
Delve Not establishedNot statedNot established beyond framework coverage

Each cell comes from the vendor's own legal, support or product documentation, read on 2026-07-24. Vanta's answer is quoted from its published terms FAQ; Secureframe's two conflicting answers both appear in one support article; Thoropass's and Scrut's data processing addenda were read in full and are silent on HIPAA. "Not established" means no public statement was found, and it is the correct answer to publish rather than a guess. Ask each shortlisted vendor directly and get the answer in your contract.

The eligible set

16 platforms that qualify.

Membership is computed from our registry rather than chosen by hand, so this list changes when the underlying facts do.

Platform Best for Pricing Integrations Frameworks
Comp AI Engineering-led startups and growing software companies pursuing SOC 2 or adjacent frameworks, especially teams that… Quote-based 590+ SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, SOC 1, FedRAMP, ISO 42001, ISO 9001, CCPA, NEN 7510
Anecdotes Mid-market to enterprise security/GRC teams running several frameworks at once (SOC 2, ISO 27001, HIPAA, etc.) with a… Quote-based (reported $47K–$78K/yr) 230+ SOC 2, SOC 1, ISO 27001, HIPAA, PCI DSS, GDPR, NIST CSF, SOX ITGC, FedRAMP, NYDFS Part 500
Apptega A managed security/service provider (MSSP, MSP, or compliance consultancy) building a recurring, multi-client,… Quote-based (reported from $6/user/month) 16+ SOC 2, ISO 27001, CMMC, PCI DSS, HIPAA, NIST CSF, NIST 800-53, NIST 800-171
Carbide Early-stage SaaS company (often Canadian) pursuing its first compliance framework with little or no in-house security… Published, $7.5K–$22K/yr 100+ SOC 2, ISO 27001, HIPAA, PCI DSS
ComplyJet An early-stage B2B SaaS company (up to ~50 employees) pursuing its first SOC 2 report with no dedicated compliance or… Published, $5K–$8K/yr 350+ SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIST CSF, HITRUST, ISO 42001
Delve A very early-stage SaaS startup pursuing its first SOC 2 report to unblock a specific enterprise deal on a tight budget… Quote-based (reported $10K–$30K/yr) 100+ SOC 2, HIPAA, ISO 27001, GDPR, PCI DSS, ISO 42001
Drata Growth-stage SaaS companies pursuing a first SOC 2 or expanding into a multi-framework program (ISO 27001, HIPAA, PCI… Quote-based (reported $9.6K–$60K/yr) 300+ SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, NIS2, DORA, NYDFS Part 500
Scrut Automation Growth-stage SaaS/tech companies (roughly 20-500 employees) pursuing SOC 2 alongside one or more additional frameworks… Quote-based (reported from $15K/yr) 80+ SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, NIST AI RMF, CCPA
Scytale Startup-to-growth-stage SaaS company that wants platform automation plus hands-on compliance-expert guidance, selects a… Quote-based (reported from $7.5K/yr) 150+ SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, GDPR, SOX ITGC, C5
Secureframe Mid-market to enterprise companies juggling multiple overlapping frameworks (SOC 2 plus ISO 27001, HIPAA, FedRAMP, or… Quote-based (reported $7.5K–$80K/yr) 300+ SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, FedRAMP
Sprinto Early- to growth-stage SaaS startups (roughly Series A-C) pursuing their first SOC 2 or ISO 27001 quickly, with a… Quote-based (reported $6K–$25K/yr) 300+ SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, CMMC, NIST 800-171, ISO 42001
Strike Graph Growth-stage SaaS/tech companies that need SOC 2 plus one or more adjacent frameworks (HIPAA, ISO 27001, GDPR) and want… Published, $10K–$35K/yr 300+ SOC 2, ISO 27001, HIPAA, GDPR, ISO 27701, PCI DSS, NIST 800-171, CCPA
Thoropass A growth-stage or regulated company that wants the audit itself, not only readiness, run by the same team that runs the… Quote-based (reported from $15K/yr) 200+ SOC 2, SOC 1, ISO 27001, HIPAA, HITRUST, PCI DSS, GDPR, NIST CSF, CMMC, Cyber Essentials
TrustCloud Mid-market to enterprise CISOs and GRC leaders managing several overlapping frameworks (SOC 2 plus ISO… Quote-based 100+ SOC 2, ISO 27001, HIPAA, CMMC, HITRUST, ISO 9001, GDPR, CCPA, ISO 27701, ISO 42001, NIST AI RMF, PCI DSS
Trustero Mid-market to enterprise GRC/compliance teams running one or several overlapping frameworks off a shared control… Quote-based (reported $5K–$25K/yr) 200+ SOC 2, SOC 1, ISO 27001, HIPAA, PCI DSS, NIST CSF, CMMC
Vanta Cloud-native SaaS companies on mainstream stacks (AWS/GCP/Azure, common HRIS/identity/dev tooling) pursuing a first SOC… Quote-based (reported $7.5K–$57K/yr) 400+ SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, ISO 42001, NYDFS Part 500

Is there such a thing as HIPAA certified software

No, and the Department of Health and Human Services says so itself. Its own guidance states that no standard or implementation specification requires a covered entity to certify compliance, that HHS does not endorse or recognise private organisations' certifications regarding the Security Rule, that such certifications do not absolve a covered entity of its legal obligations, and that a certification performed by an outside organisation does not prevent HHS from later finding a violation.

That matters commercially, because "HIPAA certification" is one of the phrases buyers search for most in this category. Any badge you see is a private claim by a private company, and it carries exactly the weight of that company's reputation and nothing more. HIPAA regulates organisations and their conduct, not software products, so strictly speaking a tool cannot be HIPAA compliant at all. It can support your compliance. You remain the regulated party.

This category also has a live illustration of why the badge is not the thing. In March 2026 TechCrunch reported allegations from an anonymous whistleblower that Delve, a compliance automation startup, had supplied customers with evidence that did not reflect real control operation, with HIPAA and GDPR named as specific exposure. Delve disputed the characterisation and said it provides templates. We list Delve in the table above with that stated, because the allegation is unresolved and because the episode is the clearest argument in the category for reading the evidence rather than the badge.

Will the vendor sign a BAA with us, or do we still need our own agreements

Both, and buyers routinely conflate them. Under HIPAA, anyone who creates, receives, maintains or transmits protected health information on your behalf is a business associate and must be under a business associate agreement with you. That covers your cloud provider, your messaging vendor, your analytics tool and, if it touches PHI, your compliance platform. Every platform in the table above sells a feature that helps you track the agreements you need with your own vendors. Almost none of them publishes whether it will sign one with you.

Vanta is the exception, and it answers no. Its published terms state that it does not process PHI, so a BAA is not required and it does not sign them, and the product is architected to keep PHI out. That is a legitimate design choice and arguably the safer one, but it is a fact you want before procurement asks, not after. Secureframe's own support documentation contains both answers in a single article, which is worth resolving with your account team in writing rather than reading either way.

For everyone else the honest answer is that we could not find one. That absence is the finding. Ask the question in the first sales call, ask for the answer in the contract rather than an email, and treat a vendor that cannot answer it quickly as a signal about how much of its HIPAA positioning is architecture and how much is marketing.

Do we need a HIPAA risk analysis if we are a SaaS company and not a hospital

Yes, if you are a business associate, and most SaaS companies handling PHI on a customer's behalf are. The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information, at 45 CFR 164.308(a)(1)(ii)(A). HHS publishes dedicated guidance on it. It is not a questionnaire and it is not a penetration test.

It is also the single most consequential thing on this page, because it is what HHS enforcement actions most often turn on. Read the published resolution agreements and the phrase "failure to conduct a risk analysis" recurs more than any other. If you do one thing after buying a platform, do the risk analysis properly and keep the evidence that you did.

Software helps here in a narrow, real way: it gives you a repeatable structure, it keeps the inventory of systems that touch PHI current, and it timestamps the work so you can show when it was done. It cannot decide your scope, it cannot tell you which of your data flows carry PHI, and it cannot make the judgement calls the analysis consists of. Several platforms name a HIPAA risk analysis as a feature; the table above says which.

What changed with the 2025 HIPAA Security Rule proposal, and is it in effect yet

Not yet, and the dates get misreported constantly. HHS issued the notice of proposed rulemaking on 27 December 2024, and it published in the Federal Register on 6 January 2025. It proposes removing the addressable and required distinction so that specifications such as encryption and multi-factor authentication become mandatory, along with asset inventories, network mapping and more prescriptive incident response. It is a proposal.

The operative sentence is HHS's own: while the Department is undertaking this rulemaking, the current Security Rule remains in effect. Nothing in the proposal binds you today. What buyers should take from it is direction rather than deadline: the proposed baseline is roughly where a well-run SOC 2 program already sits, so a platform that has you encrypting, enforcing MFA and maintaining an asset inventory is not going to be caught out.

On timing, the Unified Agenda is reported to have moved the target for a final rule from 2026 to 2027. We could not read that entry at the source ourselves, and multiple law-firm and trade summaries are the basis for it, so treat the date as reported rather than confirmed. Treat anyone selling you urgency about a 2026 deadline accordingly.

How much does HIPAA compliance cost beyond the platform fee

Every figure here is a secondary-source range rather than a quote, because HHS regulates the requirement and not the market. A third-party risk assessment is commonly reported at $2,000 to $10,000, and doing it with software plus internal time at $500 to $3,000. A fuller external HIPAA assessment is reported from around $5,000. Penetration testing, which HIPAA does not mandate by name but which enterprise health customers routinely ask for, is reported at $10,000 to $50,000 depending on scope.

On the platform line itself there are two markets and they are priced very differently. HIPAA-specialist tools aimed at clinics and small providers start around $499 a year. The multi-framework platforms in the table above start around $7,500 to $12,000 a year, because you are buying SOC 2 and HIPAA and usually more off one evidence base. If HIPAA is genuinely all you need and you are not selling to enterprise software buyers, the specialist tools are worth pricing. If you are a SaaS company that also needs SOC 2 to close deals, paying twice makes no sense.

Legal review is the line we will not put a number on. Rates for healthcare privacy counsel vary far too much by market and seniority for a range to be useful, and a false-precision figure would be worse than none. Budget for it as hours rather than as a fixed fee, and get your BAA template reviewed before you sign your first one, not your tenth.

What actually triggers an HHS investigation, and how large are the fines

Mostly breaches, and mostly technical ones. Reading the published resolution agreements, the recent pattern is dominated by hacking, ransomware and phishing investigations rather than paperwork audits. Recent examples from the public record: Warby Parker at $1.5 million in February 2025 following a credential-stuffing incident, Solara Medical Supplies at $3 million in January 2025 after a phishing compromise, Gulf Coast Pain Consultants at $1.19 million in December 2024, and Montefiore Medical Center at $4.75 million in 2024 after a malicious insider exfiltrated records.

The range is enormous, and small organisations are not exempt: the same public record includes a $10,000 settlement with a five-physician surgical group in January 2025. The statutory maximum is tiered by culpability and adjusted for inflation each year, and 2026 secondary sources put the top annual cap per violation category at roughly $2.19 million. We have not verified that figure against the Federal Register inflation notice, so treat it as reported.

The thing worth internalising is what the settlements have in common rather than their size. A breach opens the investigation; what determines the outcome is whether you had done the risk analysis, whether the BAAs existed, and whether you could show it. That is the work. The software is how you keep the evidence of it.

Buyer questions

Frequently asked.

What is the best HIPAA compliance tool?

It depends on whether you also need SOC 2. If you do, a multi-framework platform that runs both off one evidence base is the right purchase, and the table above is how to choose between them. If HIPAA is genuinely all you need and you are a clinic or a small provider rather than a software company, the HIPAA-specialist tools start at a fraction of the price and go deeper on clinical workflows. Buying a SOC 2 platform for HIPAA alone is the common expensive mistake.

What is HIPAA compliant software?

Strictly, there is no such thing. HIPAA regulates covered entities and business associates and the way they handle protected health information, not software products. A tool can be built so that it supports your compliance, and a vendor that handles your PHI can be under a business associate agreement with you, but the regulated party is always you. Treat any product marketed as HIPAA compliant as a claim to check rather than a status to rely on.

Is there a HIPAA certification for software?

No. HHS states in its own guidance that no requirement to certify exists, that it does not endorse or recognise private certifications regarding the Security Rule, that a certification does not absolve you of your obligations, and that it does not prevent HHS from later finding a violation. Any HIPAA certified badge is a private company's claim about another private company.

Is SaaS HIPAA compliant?

Not by category. A SaaS product that creates, receives, maintains or transmits protected health information on a customer's behalf is a business associate and must be under a business associate agreement with that customer, must meet the Security Rule safeguards, and must report breaches. A SaaS product that never touches PHI is out of scope. The determining question is your data flows, not your delivery model.

Do we need a HIPAA risk analysis if we already have SOC 2?

Yes. SOC 2 evidence covers a lot of the same ground, including access control, encryption, logging and change management, but the HIPAA risk analysis at 45 CFR 164.308(a)(1)(ii)(A) is a specific required assessment of risks to electronic protected health information, and a SOC 2 report does not substitute for it. It is also the deficiency HHS enforcement actions cite most often, so it is the wrong corner to cut.

Can we use an AI tool with patient data?

Only under a business associate agreement, and only if the vendor will sign one. The general consumer tiers of the major AI assistants are not offered under a BAA, while several enterprise tiers of the large cloud providers are. The rule is the same as for any other vendor: if it processes PHI on your behalf it is a business associate, and no amount of vendor marketing about security substitutes for the agreement.

Related