HIPAA compliant practice management software stores and transmits protected health information under a signed business associate agreement, with encryption in transit and at rest, role-based access controls, and audit logging that records who opened each record. Your signed BAA is the document that carries legal weight, and that leaves a gap between what a vendor's homepage claims and what your contract actually covers.
That gap matters because the claim is everywhere. Search this category and the first page fills with platforms describing themselves as HIPAA compliant, sitting beside a discussion thread where practitioners ask whether their patient management software actually is. The phrase has become table stakes in marketing copy while meaning different things at different companies.
Practice Better's own guidance says the quiet part plainly: "HIPAA-compliant" appears in almost every platform's marketing copy, and what it means varies significantly. Some vendors cover compliance on every plan. Others hold the business associate agreement behind a higher pricing tier. Some encrypt records while they travel and leave them unencrypted while they sit.
This guide gives you the seven checks that separate a platform that holds up from one that markets well, plus the questions to send a vendor before you hand over a single client file.
HIPAA compliant practice management software is two things at once: a set of technical safeguards inside the product, and a signed business associate agreement between you and the vendor. A platform can have excellent security and still leave you exposed if nobody signed the agreement.
HIPAA applies to covered entities and to their business associates. There are three types of covered entity: health care providers, health care plans, and health care clearinghouses. Health care providers covers individuals who get paid to provide health care, including doctors, dietitians, chiropractors, naturopathic doctors, and other health and wellness professionals who are regulated or hold a healthcare license. Many wellness businesses and alternative practitioners fall into that category, especially where their services are covered by a client's medical coverage.
Your practice management platform sits on the other side of that line, as a business associate: a person or entity that performs functions involving the use or disclosure of protected health information on behalf of a covered entity. The business associate agreement is the contract that binds it to protect that data.
No federal body certifies software as HIPAA compliant, and no government-endorsed certification program exists. Certification badges on vendor sites come from private auditors and reflect that auditor's standard rather than a government stamp.
This is why the badge alone settles nothing. Pull the compliance page directly, because the homepage badge on its own is not sufficient.
It is when the plan you bought carries a signed business associate agreement, encryption protects records at rest as well as in transit, and every tool your client data touches sits inside that coverage. The claim on a vendor homepage settles none of those three on its own, and three gaps show up again and again when practitioners look past the label.
The BAA sits behind a pricing tier. Some platforms offer HIPAA compliance at the infrastructure level while requiring a business associate agreement only on higher-tier plans. The product page says compliant. The plan you bought says otherwise.
Encryption stops at the door. Others encrypt data in transit and leave it unencrypted at rest. Records in motion are protected; the same records sitting in storage are not. Email is the everyday version of this problem, which is why the rules for HIPAA compliant client email turn on the same two questions.
The stack has holes between the tools. Many practitioners assume the tools they use are HIPAA compliant. Some are. Some offer it only on higher-tier plans. Some require a business associate agreement that was never signed. And some tools were never designed for healthcare at all, and are general-purpose business software being used in a clinical context.
That third gap is the one practitioners find hardest to see, because each individual tool looks fine on its own.
Run these before you buy. Each one produces a written answer you can keep on file.
| # | What to verify | The question to send the vendor | What a good answer looks like |
|---|---|---|---|
| 1 | BAA for your plan | "Please send the business associate agreement for the plan I am buying." | The document arrives without a sales call attached, and covers the plan you named |
| 2 | Encryption at rest and in transit | "Which encryption standard protects stored records, and which protects data in motion?" | A named standard for both states, in writing |
| 3 | Access controls | "Can I set per-user permissions for staff and contractors?" | Role-based permissions, configurable per team member |
| 4 | Audit logging | "Does the platform log who opened each client record and when? Can I export that log?" | Automatic logging, exportable on request |
| 5 | Coverage across the workflow | "Which parts of the product does the BAA cover: intake, scheduling, notes, video, messaging, payments?" | Every surface where client data lands |
| 6 | AI and data use | "Is client data used to train models, shared with third parties, or retained after cancellation?" | A clear written no on training and sharing, plus a stated retention period |
| 7 | Breach and subprocessor terms | "What is your breach notification timeline, and who are your subprocessors?" | A defined timeline and a current subprocessor list |
Ask for the document itself rather than a yes. Read which services it covers. A vendor that hands you the agreement quickly, for the tier you intend to buy, has answered the question that the homepage badge cannot.
Data has two states worth protecting: moving between your device and the server, and sitting in storage afterward. Ask about both by name. Practice Better publishes that AES-256 encryption protects all data in transit and at rest, covering sessions, notes, billing records, and client communications.
A solo practice grows into a small team, and the compliance question changes with it. Role-based permissions let you give a virtual assistant scheduling access without opening clinical notes. Practice Better publishes that role-based permissions ensure only authorized team members see what they need.
If a client asks who has viewed their record, or a complaint arrives, the audit log is what answers. Ask two things: whether the platform records every access automatically, and whether you can get that record out. Practice Better publishes that automatic audit logs track every access. Push past the headline on any platform and ask which events the log actually records, because creating, editing and sharing a record are not always logged the same way as simply opening one.
This is the check that catches the fragmented-stack problem. Write down every place a client's information lands in a normal week: the intake form, the calendar, the video call, the note, the message thread, the invoice. Then mark which of those tools you hold a BAA with. The unmarked rows are your exposure.
Practice Better's co-founder and chief technology officer, Graeme Downes, describes the first question the team asks about any tool: "the one thing that we thought about when we went into picking a tool and picking a use case to solve, is how is this thing being trained and who has access to it?" Ask your vendor the same question and keep the answer.
The company applies that standard to its own charting summaries. Downes states it directly: "The data that we're storing and using to provide this summary feature isn't being used to train other models; it's not being sold to a marketing company. This data is strictly being used for the purpose of helping the practitioner do their work better." The company's AI page states it more broadly: your client data is never used to train AI models. When you ask a vendor the same question, ask which document the answer lives in, because a product page and a contract are not the same commitment.
A breach notification timeline and a subprocessor list tell you how seriously a vendor takes the part of the relationship nobody wants to use. A vendor that publishes neither is asking you to take it on trust. Practice Better keeps both in a public trust center, including a named subprocessor list.
A wellness practice running five tools has five compliance relationships to maintain. With a fragmented stack, you can carry gaps you do not know about.
The pattern usually looks like this. Scheduling runs on a general booking tool chosen before the practice took clinical clients. Video runs on whatever consumer app was already installed. Notes live in a documentation product. Payments run through a processor picked for its fees. Each tool works. The seams between them are where protected health information travels without a contract behind it.
Consolidating removes the seams. Practice Better covers HIPAA compliance and BAA coverage across scheduling, telehealth, messaging, documentation, and billing inside one platform.
{{ehr-migration-checklist}}
The best platform for a therapy or wellness practice is the one whose business associate agreement covers every place client data lands, including the between-session channels: secure messaging, food and habit logs, and program materials. Plenty of EHR and practice management portals were designed for medicine: the patient shows up, sees the doctor, leaves, and the portal exists to book the next appointment and view a visit summary. Wellness care runs on continuous contact between sessions instead.
That changes where client data lives. A fifty-minute nutrition counseling session, a twelve-week coaching program, food and habit logs between appointments, and lab results reviewed over months all generate protected health information in places a medical-first tool never planned for.
The compliance consequence is practical. If your platform covers documentation but leaves food logs, program materials, and between-session messaging outside its BAA, the data your clients share in those channels sits outside your coverage. For practitioners working with eating disorders, disordered relationships with food, or mental health comorbidities, clients share things in session that they have not shared anywhere else, so understanding exactly how a tool uses that data matters in ways that go beyond HIPAA compliance.
For comparison against whatever else you are evaluating, here is what Practice Better publishes about its own posture.
Run the same seven questions at whatever else is on your list, and keep the written answers side by side. The platform that answers all seven in writing is the one you can defend if anyone ever asks.
Step six catches what a feature comparison cannot. A platform that satisfies every technical requirement and forces a clumsy workflow gets worked around, and the workaround is where compliance goes.
Verified compliance protects you from a category of legal and financial risk. What your clients experience is something else: their information stays where they expect it to stay, and the person they trusted with it knows exactly where that is.
You can run the seven checks above against any platform on your shortlist, including this one. Practice Better gives wellness practitioners intake, scheduling, charting, telehealth, messaging, and billing under one compliance relationship. Start a free trial and run your own audit inside it.
Two categories of software do different jobs. Practice management and EHR platforms hold protected health information and carry compliance obligations for the data they store, which is where a signed business associate agreement applies. Compliance management tools handle the administrative side: risk assessments, policy documents, workforce training records, and BAA tracking. A practice that stores client records in a compliant platform still owns its own risk analysis, policies, and training.
A general-purpose CRM becomes usable for protected health information when the vendor signs a business associate agreement and the account is configured with encryption, access controls, and audit logging. Read the vendor's own covered-services list rather than its price page, because a consumer account has no commercial services agreement for a BAA to attach to at all. Check what the plan you are actually buying covers.
Consumer chatbot accounts are not built to hold protected health information, and Practice Better's guidance is direct about it: you should not be using ChatGPT for anything related to interfacing with your patient care. For clinical work, use AI features inside a platform that already covers you under a BAA and states in writing what it does with your client data.
In January 2025 the US Department of Health and Human Services published a proposed rule that would tighten the Security Rule's technical safeguards, including encryption, multi-factor authentication, and asset inventories. It is still a proposal: the comment period closed in March 2025 and no final rule has been published, so there is no effective date or compliance date yet. Ask any vendor you are evaluating how they plan to meet the requirements if they are finalized.
HIPAA has no certification program behind it. HHS states plainly that it does not certify any persons or products as HIPAA compliant. Vendor badges are issued by private auditors, so what a badge proves depends entirely on which auditor issued it and against which standard. Your signed business associate agreement and the safeguards actually running in the product are what carry legal weight.
A signed BAA covers the vendor relationship. Your own obligations remain: a documented security risk analysis, written policies and procedures, workforce training, access management when staff join or leave, and a breach response plan. Compliant software removes a category of technical risk and leaves the administrative work with you.
{{free-trial-simple-text}}

HIPAA compliant practice management software stores and transmits protected health information under a signed business associate agreement, with encryption in transit and at rest, role-based access controls, and audit logging that records who opened each record. Your signed BAA is the document that carries legal weight, and that leaves a gap between what a vendor's homepage claims and what your contract actually covers.
That gap matters because the claim is everywhere. Search this category and the first page fills with platforms describing themselves as HIPAA compliant, sitting beside a discussion thread where practitioners ask whether their patient management software actually is. The phrase has become table stakes in marketing copy while meaning different things at different companies.
Practice Better's own guidance says the quiet part plainly: "HIPAA-compliant" appears in almost every platform's marketing copy, and what it means varies significantly. Some vendors cover compliance on every plan. Others hold the business associate agreement behind a higher pricing tier. Some encrypt records while they travel and leave them unencrypted while they sit.
This guide gives you the seven checks that separate a platform that holds up from one that markets well, plus the questions to send a vendor before you hand over a single client file.
HIPAA compliant practice management software is two things at once: a set of technical safeguards inside the product, and a signed business associate agreement between you and the vendor. A platform can have excellent security and still leave you exposed if nobody signed the agreement.
HIPAA applies to covered entities and to their business associates. There are three types of covered entity: health care providers, health care plans, and health care clearinghouses. Health care providers covers individuals who get paid to provide health care, including doctors, dietitians, chiropractors, naturopathic doctors, and other health and wellness professionals who are regulated or hold a healthcare license. Many wellness businesses and alternative practitioners fall into that category, especially where their services are covered by a client's medical coverage.
Your practice management platform sits on the other side of that line, as a business associate: a person or entity that performs functions involving the use or disclosure of protected health information on behalf of a covered entity. The business associate agreement is the contract that binds it to protect that data.
No federal body certifies software as HIPAA compliant, and no government-endorsed certification program exists. Certification badges on vendor sites come from private auditors and reflect that auditor's standard rather than a government stamp.
This is why the badge alone settles nothing. Pull the compliance page directly, because the homepage badge on its own is not sufficient.
It is when the plan you bought carries a signed business associate agreement, encryption protects records at rest as well as in transit, and every tool your client data touches sits inside that coverage. The claim on a vendor homepage settles none of those three on its own, and three gaps show up again and again when practitioners look past the label.
The BAA sits behind a pricing tier. Some platforms offer HIPAA compliance at the infrastructure level while requiring a business associate agreement only on higher-tier plans. The product page says compliant. The plan you bought says otherwise.
Encryption stops at the door. Others encrypt data in transit and leave it unencrypted at rest. Records in motion are protected; the same records sitting in storage are not. Email is the everyday version of this problem, which is why the rules for HIPAA compliant client email turn on the same two questions.
The stack has holes between the tools. Many practitioners assume the tools they use are HIPAA compliant. Some are. Some offer it only on higher-tier plans. Some require a business associate agreement that was never signed. And some tools were never designed for healthcare at all, and are general-purpose business software being used in a clinical context.
That third gap is the one practitioners find hardest to see, because each individual tool looks fine on its own.
Run these before you buy. Each one produces a written answer you can keep on file.
| # | What to verify | The question to send the vendor | What a good answer looks like |
|---|---|---|---|
| 1 | BAA for your plan | "Please send the business associate agreement for the plan I am buying." | The document arrives without a sales call attached, and covers the plan you named |
| 2 | Encryption at rest and in transit | "Which encryption standard protects stored records, and which protects data in motion?" | A named standard for both states, in writing |
| 3 | Access controls | "Can I set per-user permissions for staff and contractors?" | Role-based permissions, configurable per team member |
| 4 | Audit logging | "Does the platform log who opened each client record and when? Can I export that log?" | Automatic logging, exportable on request |
| 5 | Coverage across the workflow | "Which parts of the product does the BAA cover: intake, scheduling, notes, video, messaging, payments?" | Every surface where client data lands |
| 6 | AI and data use | "Is client data used to train models, shared with third parties, or retained after cancellation?" | A clear written no on training and sharing, plus a stated retention period |
| 7 | Breach and subprocessor terms | "What is your breach notification timeline, and who are your subprocessors?" | A defined timeline and a current subprocessor list |
Ask for the document itself rather than a yes. Read which services it covers. A vendor that hands you the agreement quickly, for the tier you intend to buy, has answered the question that the homepage badge cannot.
Data has two states worth protecting: moving between your device and the server, and sitting in storage afterward. Ask about both by name. Practice Better publishes that AES-256 encryption protects all data in transit and at rest, covering sessions, notes, billing records, and client communications.
A solo practice grows into a small team, and the compliance question changes with it. Role-based permissions let you give a virtual assistant scheduling access without opening clinical notes. Practice Better publishes that role-based permissions ensure only authorized team members see what they need.
If a client asks who has viewed their record, or a complaint arrives, the audit log is what answers. Ask two things: whether the platform records every access automatically, and whether you can get that record out. Practice Better publishes that automatic audit logs track every access. Push past the headline on any platform and ask which events the log actually records, because creating, editing and sharing a record are not always logged the same way as simply opening one.
This is the check that catches the fragmented-stack problem. Write down every place a client's information lands in a normal week: the intake form, the calendar, the video call, the note, the message thread, the invoice. Then mark which of those tools you hold a BAA with. The unmarked rows are your exposure.
Practice Better's co-founder and chief technology officer, Graeme Downes, describes the first question the team asks about any tool: "the one thing that we thought about when we went into picking a tool and picking a use case to solve, is how is this thing being trained and who has access to it?" Ask your vendor the same question and keep the answer.
The company applies that standard to its own charting summaries. Downes states it directly: "The data that we're storing and using to provide this summary feature isn't being used to train other models; it's not being sold to a marketing company. This data is strictly being used for the purpose of helping the practitioner do their work better." The company's AI page states it more broadly: your client data is never used to train AI models. When you ask a vendor the same question, ask which document the answer lives in, because a product page and a contract are not the same commitment.
A breach notification timeline and a subprocessor list tell you how seriously a vendor takes the part of the relationship nobody wants to use. A vendor that publishes neither is asking you to take it on trust. Practice Better keeps both in a public trust center, including a named subprocessor list.
A wellness practice running five tools has five compliance relationships to maintain. With a fragmented stack, you can carry gaps you do not know about.
The pattern usually looks like this. Scheduling runs on a general booking tool chosen before the practice took clinical clients. Video runs on whatever consumer app was already installed. Notes live in a documentation product. Payments run through a processor picked for its fees. Each tool works. The seams between them are where protected health information travels without a contract behind it.
Consolidating removes the seams. Practice Better covers HIPAA compliance and BAA coverage across scheduling, telehealth, messaging, documentation, and billing inside one platform.
{{ehr-migration-checklist}}
The best platform for a therapy or wellness practice is the one whose business associate agreement covers every place client data lands, including the between-session channels: secure messaging, food and habit logs, and program materials. Plenty of EHR and practice management portals were designed for medicine: the patient shows up, sees the doctor, leaves, and the portal exists to book the next appointment and view a visit summary. Wellness care runs on continuous contact between sessions instead.
That changes where client data lives. A fifty-minute nutrition counseling session, a twelve-week coaching program, food and habit logs between appointments, and lab results reviewed over months all generate protected health information in places a medical-first tool never planned for.
The compliance consequence is practical. If your platform covers documentation but leaves food logs, program materials, and between-session messaging outside its BAA, the data your clients share in those channels sits outside your coverage. For practitioners working with eating disorders, disordered relationships with food, or mental health comorbidities, clients share things in session that they have not shared anywhere else, so understanding exactly how a tool uses that data matters in ways that go beyond HIPAA compliance.
For comparison against whatever else you are evaluating, here is what Practice Better publishes about its own posture.
Run the same seven questions at whatever else is on your list, and keep the written answers side by side. The platform that answers all seven in writing is the one you can defend if anyone ever asks.
Step six catches what a feature comparison cannot. A platform that satisfies every technical requirement and forces a clumsy workflow gets worked around, and the workaround is where compliance goes.
Verified compliance protects you from a category of legal and financial risk. What your clients experience is something else: their information stays where they expect it to stay, and the person they trusted with it knows exactly where that is.
You can run the seven checks above against any platform on your shortlist, including this one. Practice Better gives wellness practitioners intake, scheduling, charting, telehealth, messaging, and billing under one compliance relationship. Start a free trial and run your own audit inside it.
Two categories of software do different jobs. Practice management and EHR platforms hold protected health information and carry compliance obligations for the data they store, which is where a signed business associate agreement applies. Compliance management tools handle the administrative side: risk assessments, policy documents, workforce training records, and BAA tracking. A practice that stores client records in a compliant platform still owns its own risk analysis, policies, and training.
A general-purpose CRM becomes usable for protected health information when the vendor signs a business associate agreement and the account is configured with encryption, access controls, and audit logging. Read the vendor's own covered-services list rather than its price page, because a consumer account has no commercial services agreement for a BAA to attach to at all. Check what the plan you are actually buying covers.
Consumer chatbot accounts are not built to hold protected health information, and Practice Better's guidance is direct about it: you should not be using ChatGPT for anything related to interfacing with your patient care. For clinical work, use AI features inside a platform that already covers you under a BAA and states in writing what it does with your client data.
In January 2025 the US Department of Health and Human Services published a proposed rule that would tighten the Security Rule's technical safeguards, including encryption, multi-factor authentication, and asset inventories. It is still a proposal: the comment period closed in March 2025 and no final rule has been published, so there is no effective date or compliance date yet. Ask any vendor you are evaluating how they plan to meet the requirements if they are finalized.
HIPAA has no certification program behind it. HHS states plainly that it does not certify any persons or products as HIPAA compliant. Vendor badges are issued by private auditors, so what a badge proves depends entirely on which auditor issued it and against which standard. Your signed business associate agreement and the safeguards actually running in the product are what carry legal weight.
A signed BAA covers the vendor relationship. Your own obligations remain: a documented security risk analysis, written policies and procedures, workforce training, access management when staff join or leave, and a breach response plan. Compliant software removes a category of technical risk and leaves the administrative work with you.
{{free-trial-simple-text}}

Try any paid plan free.