For business associates and the MSPs who support them
HIPAA compliance software that proves it to the clients who ask.
Run a real compliance programme — risk assessment, policies, training, BAA register, incident log — and export the dated evidence pack your clients, partners and insurers request. Self-serve from $79/month, no sales call, no consultant on retainer.
No credit card. No onboarding fee. Cancel in one click.
Is your software HIPAA compliant? Check it free.
We publish researched verdicts on the tools small healthcare organizations actually run — 47 so far, of which 5 should not be used with patient information at all. Each entry gives the verdict, the exact conditions, which plan you need, a link to the vendor’s own business associate agreement, and the primary sources behind it with the date we read them.
Nothing here is sponsored. Alternatives are listed on merit, which is why we are willing to say “no” about products with very large marketing budgets.
Browse the full vendor checker →Free, no signup. Verdict, conditions and the vendor’s own agreement link.
Most looked up
The job is not “be compliant”. It is to show someone that you are.
Almost nobody buys this software because they woke up wanting a risk assessment. They buy it the week a hospital client sends a security questionnaire, a payer attaches a security addendum to a contract, or an insurer asks what safeguards are in place — each with a deadline attached. The programme matters, but the deliverable is what unblocks you.
Answer the assessment
Plain-language questions mapped to the Security Rule safeguards. A posture score and a gap list in one sitting, no consultant required.
Close the gaps
Every gap becomes a task with an owner, a due date and somewhere to attach evidence. Policies and training are written for you.
Send the proof
One dated pack: assessment summary, remediation status, signed policies, certificates, vendor register and incident log.
Everything a HIPAA compliance programme needs, in one place.
Six modules that feed one another, so evidence accumulates as a by-product of doing the work rather than as a separate scramble before a deadline.
HIPAA risk assessment
A guided security risk assessment mapped to the Security Rule safeguards, in plain language, scoring you in under ten minutes and turning every gap into a tracked task.
Policies and acknowledgements
A versioned policy library your staff read and sign in their own accounts, so you hold dated proof rather than a folder of documents nobody opened.
Staff training and certificates
Short annual courses with a quiz and a dated certificate per person, plus reminders that chase whoever has not finished.
Vendor and BAA register
Track every vendor that touches patient information, whether a business associate agreement is signed, and when it needs revisiting.
Incident and breach log
Record incidents, work through the four-factor risk assessment, and keep notification deadlines counting down from the date of discovery.
Audit-ready evidence pack
One button produces a dated PDF with everything above in it — the artifact your client, partner or insurer actually asked for.
Verified, not self-attested.
Most compliance software in this price range is an honour system: it asks whether multi-factor authentication is enforced and records whatever you click. Connect Microsoft 365 or Google Workspace read-only and we check the setting itself, then attach the dated result as evidence. Items confirmed this way are marked verified in your evidence pack; everything else stays honestly labelled as self-attested.
Read-only, and limited to security configuration — never the contents of mail, files, calendars or messages.
- Multi-factor authentication actually enforced, per account
- Accounts still enabled after someone has left
- External sharing and public link settings
- Mailbox forwarding rules, a common breach signal
- Audit logging switched on
- Device encryption posture where available
Built for the organizations that actually get asked
Medical billing and RCM companies
You handle claims on behalf of practices, which makes you a business associate. Sooner or later a client asks you to prove it.
Learn more →Healthcare software vendors
Deals stall on the hospital security questionnaire. Answer it from a live trust page instead of rebuilding a deck each time.
Learn more →IT providers and MSPs
Run every healthcare client's programme from one console and resell it as a managed service at your own margin.
Learn more →Understand the requirements first
Free, dated and cited reference material — no signup, written to be checked rather than taken on faith.
HIPAA compliance checklist
Every requirement, in order, with the evidence that proves it.
HIPAA training requirements
Who must be trained, how often, and what proof to keep.
HIPAA compliance audits
The three different things called an audit, and what each asks for.
Security questionnaires
What a client is really asking for, and what to send back.
HIPAA glossary
Plain-language definitions, each with its citation.
HIPAA for MSPs guide
Where your obligations start, and how to package the service.
HIPAA compliance software questions
- What is HIPAA compliance software?
- Software that runs the ongoing programme HIPAA requires and documents it: a security risk assessment, remediation tracking, written policies with staff acknowledgements, workforce training, a register of vendors and business associate agreements, and an incident log. Its real output is dated evidence you can hand to whoever asked for it. No software can make you compliant — that depends on how you actually operate.
- How much does HIPAA compliance software cost?
- Ours starts at $79 per month for a single organization and $149 with the public trust page and questionnaire library. MSPs pay $49 per client organization per month, dropping to $39 at ten clients and $29 at twenty-five. There is a 14-day free trial with no credit card and no onboarding fee.
- What software is HIPAA-compliant?
- No software is compliant by itself, and no product can be 'HIPAA certified' — no such designation exists. The practical question is whether a vendor signs a business associate agreement and under what conditions. Our free vendor checker publishes researched, dated verdicts on the tools small healthcare organizations actually run, with no affiliate links and no payment for placement.
- Is there a HIPAA compliant ChatGPT?
- Only on specific OpenAI products — ChatGPT for Healthcare, ChatGPT for Clinicians, sales-managed Enterprise or Edu, or the API with Modified Retention — and never on free, Plus, Pro or ChatGPT Business accounts. Our ChatGPT entry lists the exact conditions with primary sources and the date we read them.
- Can Microsoft be HIPAA compliant?
- Yes — Microsoft's business associate agreement applies automatically to Microsoft 365 business and enterprise subscriptions through its Data Protection Addendum, provided patient information stays inside the services Microsoft lists as in scope. Our Microsoft 365 entry covers the conditions and what the agreement does not cover.
Have the answer ready before the next questionnaire lands.
Complete the assessment in an afternoon and export a packet the same day. 14 days free, no credit card, no sales call.
CompyMax is software and published research, not a law firm. No product can make an organization “HIPAA certified” — no such designation exists.