HEALTHCARE AI

    HIPAA Compliant Software in 2026: Categories, BAAs, and How to Choose

    HIPAA compliant software is defined by contracts and configuration, not a product label. This guide covers what makes software compliant, the categories that need a BAA, which major vendors sign one, and the popular tools that do not.

    CloudNSite Team
    August 12, 2026
    10 min read

    Search for "HIPAA compliant software" and you get two different answers mixed together: software that helps you run a compliance program, and software that is safe to use with protected health information. This guide separates them, because buying the wrong one is a common and expensive mistake.

    The single most important thing to understand first: HIPAA compliant software is a category defined by contracts and configuration, not by a product label. A tool becomes appropriate for protected health information (PHI) when the vendor signs a business associate agreement, the product supports the required safeguards, and your team configures and operates it correctly. HHS cloud computing guidance makes the threshold concrete: any cloud or software vendor that creates, receives, maintains, or transmits ePHI on your behalf is a HIPAA business associate, and a signed business associate agreement is required before that vendor handles PHI.

    What makes software HIPAA compliant?

    Software is HIPAA compliant for your use when four things line up: a signed business associate agreement (BAA) with any vendor that will handle PHI on your behalf, support for the HIPAA Security Rule safeguards, correct configuration, and workforce controls around how people use it. Miss any one and the tool is not compliant, even if the vendor's marketing page says it is. One case is different: software you run entirely on your own infrastructure, where no outside vendor ever receives PHI, has no vendor to sign a BAA for that layer, though your own safeguards still apply. That is part of why some healthcare teams choose a self-hosted private AI deployment.

    The HHS Security Rule requires administrative, physical, and technical safeguards for electronic PHI, including access controls and audit controls, plus encryption where a risk analysis finds it reasonable and appropriate. A BAA is the contract that sets a vendor's permitted uses of PHI and binds it to those safeguards. A vendor that qualifies as a business associate is also directly liable under the HITECH Act, with or without a signed BAA. Neither the contract nor the safeguards alone is enough. As Microsoft states plainly in its own HIPAA documentation, having a BAA with a vendor does not on its own achieve HIPAA compliance; your organization is still responsible for its own program and for how it uses the service.

    That is why "is this software HIPAA compliant" is the wrong question. The right question is "can this software be used compliantly for my specific workflow, under a BAA, configured the way HIPAA requires." The answer changes with the plan, the feature, the region, and the account type.

    The categories of HIPAA compliant software

    Most healthcare software buying falls into a handful of categories. Each has a different BAA path and a different set of risks.

    Cloud infrastructure and AI platforms

    Cloud platforms are the foundation most HIPAA-ready software is built on. The three major providers all sign BAAs for their HIPAA-eligible services.

    • Amazon Web Services presents a standard Business Associate Addendum for signature, accepted through AWS Artifact in the console. AWS is explicit that account holders should only process, store, and transmit PHI in the HIPAA-eligible services named in that addendum. The BAA is not automatic; a customer has to accept it.
    • Microsoft Azure and Microsoft 365 are covered by a Business Associate Agreement that Microsoft offers by default through its Online Services Data Protection Addendum to covered entity and business associate customers. In-scope services include Azure, Exchange Online, SharePoint, Teams, Microsoft 365 Copilot, and Power Automate.
    • Google Cloud and Google Workspace require customers subject to HIPAA to enter a Business Associate Amendment before using covered services. Google is clear that the amendment does not extend to third-party applications, add-ons, or "Additional Google Services" outside the covered set.

    The pattern is the same across all three: the BAA covers a defined list of services, and using anything outside that list for PHI breaks compliance. For teams building custom applications or AI on these platforms, the provider BAA is the starting point, not the finish line. The application you build on top still needs its own controls. That build path is what we cover in private AI deployment.

    Productivity and collaboration software

    Microsoft 365 and Google Workspace are the two dominant productivity suites, and both can be used with PHI under their BAAs when configured correctly. The recurring trap is scope. Microsoft 365 Copilot and Google Workspace with Gemini are covered as in-scope functionality, but consumer accounts, personal add-ons, and services outside the covered list are not. A free Gmail account and a managed Workspace account under a BAA are not the same product for HIPAA purposes.

    Secure email and messaging

    Standard email is not built for PHI. Purpose-built secure email vendors such as Paubox market HIPAA compliant email and publish a business associate agreement for customers. As with any category, the diligence is the same: confirm the BAA covers your plan, and confirm how the product handles message storage, attachments, and retention.

    Compliance management and GRC platforms

    This is the category most often confused with the rest. Platforms such as Vanta are compliance-automation, or governance, risk, and compliance (GRC), tools. They do a different job than the software above: they help you run the compliance program itself through automated evidence collection, control mapping, policy templates, continuous monitoring, and tracking the BAAs you sign with your own vendors. They are not where your PHI lives. If you search "HIPAA compliance software" and land on one of these, understand that you are buying a program-management tool, not a PHI-handling application. Many teams need both.

    AI tools

    AI is now its own procurement category, and it carries the same rule with sharper edges: the model is only compliant inside a covered, configured deployment. General platforms like Azure OpenAI, AWS Bedrock, and Google Vertex AI can be used with PHI under the cloud BAAs above. Healthcare-specific AI scribes and assistants have their own BAA paths. Consumer chat tools generally do not qualify. We break the AI category down in detail in HIPAA compliant AI tools, with dedicated guides for AI note takers and scribes and for medical practices.

    Telehealth, storage, forms, and scheduling

    Video visits, file storage, intake forms, and scheduling all touch PHI and all need a BAA. The category rule holds: name the exact product and plan, confirm the vendor will sign a BAA for it, and confirm the configuration. Do not assume the consumer version of a familiar brand carries the same terms as its healthcare or enterprise tier.

    Popular software that is not HIPAA compliant

    Some widely used tools will not sign a BAA at all, which means they cannot be used with PHI no matter how you configure them. Knowing these prevents a costly assumption.

    • Zapier states in its own documentation that it is not HIPAA compliant, will not sign a business associate agreement, and should not be used to store, send, or automate PHI. Teams that need to connect healthcare systems often reach for Zapier first, which is exactly the wrong move. We explain the details and the alternatives in is Zapier HIPAA compliant.
    • Consumer AI chat tools used through personal or lower-tier accounts generally do not carry a BAA. The tier matters; a personal ChatGPT account is not the same as an enterprise or healthcare deployment. We cover the tier-by-tier breakdown in is ChatGPT HIPAA compliant.

    The lesson is simple. Before any tool touches PHI, confirm it will sign a BAA. If the vendor says no, the conversation is over, regardless of how useful the tool is.

    How to evaluate HIPAA compliant software

    Use this checklist before you introduce any software to PHI. It applies to every category above.

    1. BAA scope. Confirm the vendor will sign a BAA for the exact product, plan, feature, region, and account type you intend to use. A general BAA claim is not enough if a specific feature is excluded.
    2. Covered configuration. Identify which features are included, excluded, or must be disabled under HIPAA-ready use.
    3. Safeguards. Confirm access control, encryption, and audit logging meet the Security Rule requirements.
    4. PHI boundary. Map where PHI enters, where it is stored, which systems process it, and where it leaves.
    5. Retention and deletion. Define how long data, logs, and backups persist, and how deletion works.
    6. Subprocessors. Review the vendor's downstream providers and their terms.
    7. Audit evidence. Confirm you can produce logs of user actions, access, and administrative changes.
    8. Certification claims. Treat "HIPAA certified" with caution. There is no HHS-approved certification that proves a business associate is HIPAA compliant, a point Microsoft makes directly in its own documentation. We explain what the term does and does not mean in HIPAA certification.

    The same tool can pass this checklist for one workflow and fail it for another. Drafting a general patient education handout is not the same as generating prior authorization packets from chart notes.

    Where custom and AI software fit

    Off-the-shelf software works when the vendor built the product for your workflow, the BAA is clear, and you can operate inside the vendor's configuration model. That covers a lot of ground: productivity suites, secure email, ambient documentation, and program-management platforms.

    It stops working when the workflow crosses several systems, needs custom permissions, depends on organization-specific rules, or has to keep data inside your own cloud environment. Prior authorization automation, referral routing, payer document assembly, chart abstraction, and internal clinical policy agents rarely fit a single product. Those are build decisions, and in a build the model is only one layer. The compliant version includes BAA-covered services, identity, secure storage, retrieval, logging, human review, retention, and incident procedures.

    This is where CloudNSite works. We design and operate HIPAA-ready architecture and private AI deployments for healthcare teams, and we maintain them after launch as models and payer rules change. Compliance is not a one-time configuration; it is an operating posture. Use the HIPAA compliance checklist for AI to start the review before PHI enters any system, or book an AI strategy call to map your workflow.

    FAQ

    What is HIPAA compliant software?

    HIPAA compliant software is software you can use with protected health information because the vendor signs a business associate agreement, the product supports the HIPAA Security Rule safeguards, and you configure and operate it correctly. No product is HIPAA compliant on its own; compliance is an outcome of the contract, the configuration, and how your workforce uses the tool.

    Is there certified HIPAA compliant software?

    No. There is no certification approved by the Department of Health and Human Services that proves a business associate is HIPAA compliant, which Microsoft states directly in its own HIPAA documentation. Vendors may hold related certifications such as HITRUST or ISO 27001, and those are useful signals, but they are not an official HIPAA certification.

    Does a BAA make software HIPAA compliant?

    A BAA is necessary but not sufficient. It makes the vendor legally accountable as a business associate, but your organization is still responsible for its own risk analysis, configuration, access controls, and workforce training. A signed BAA with an unconfigured tool is not compliance.

    Is Zapier HIPAA compliant?

    No. Zapier states in its own documentation that it is not HIPAA compliant and will not sign a business associate agreement, so it cannot be used to store, send, or automate PHI. Healthcare teams that need workflow automation should use a platform that will sign a BAA or a custom build inside a covered environment.

    What is the difference between HIPAA compliance software and HIPAA compliant software?

    Compliance-management software, such as a GRC platform, helps you run the compliance program: risk assessments, policies, evidence, and vendor BAA tracking. HIPAA compliant software is any application you can use with PHI under a BAA. The first manages your program; the second handles your data. Many organizations need both.

    Where should a healthcare team start?

    Start with one workflow and map the PHI boundary: who uses the data, where it enters, where it is stored, and where it leaves. Then match the workflow to a category above, confirm the BAA, and configure the safeguards before any PHI is introduced.

    Sources

    • U.S. Department of Health and Human Services, Guidance on HIPAA and Cloud Computing: confirms a cloud or software vendor that handles ePHI is a business associate and a signed BAA is required before it handles PHI.
    • U.S. Department of Health and Human Services, The Security Rule: requires administrative, physical, and technical safeguards, including access controls and audit controls, for electronic PHI.
    • Amazon Web Services, HIPAA Compliance: states that AWS presents a standard Business Associate Addendum for signature and that PHI should only be processed in HIPAA-eligible services.
    • Microsoft, HIPAA and the HITECH Act: states that Microsoft offers a Business Associate Agreement by default to covered entity and business associate customers, lists in-scope services, and notes that no HHS-approved HIPAA certification exists and that a BAA alone does not achieve compliance.
    • Google, HIPAA compliance with Google Workspace and Cloud Identity: states that customers subject to HIPAA must enter a Business Associate Amendment and that the amendment does not extend to third-party apps, add-ons, or Additional Google Services.
    • Zapier, Is Zapier HIPAA compliant?: Zapier's own statement that it is not HIPAA compliant, will not sign a BAA, and should not be used for PHI.

    LET'S BUILD

    Need Help with Healthcare AI?

    Our team can help you implement the strategies discussed in this article.