HIPAA-Compliant EHR: 12 Things US Practices Should Check Before Buying

The JenPulse team · October 5, 2026 · 5 min read

Hands typing on a laptop with a stethoscope on the desk
Photo: National Cancer Institute on Unsplash

Almost every EHR vendor describes its product as "HIPAA-compliant". The phrase sounds reassuring, but it needs unpacking, because the government doesn't certify software as HIPAA-compliant at all. HIPAA compliance is something your practice achieves, using software that supports the right safeguards and a vendor that takes its own obligations seriously.

This checklist covers what to verify before you choose an EHR. It's a practical guide, not legal advice; your HIPAA risk analysis and a compliance professional should guide final decisions.

First, two things that are often confused

  • HIPAA compliance is about how protected health information (PHI) is used, shared and secured. There is no official HIPAA certification for software.
  • ONC certification (the federal Health IT Certification Program) tests EHR functionality and interoperability. It's required for some federal programs, such as Medicare's MIPS Promoting Interoperability, but it is not a HIPAA certificate.

Ask vendors about both, and don't accept one as proof of the other.

The 12-point checklist

1. Will the vendor sign a business associate agreement?

This is non-negotiable. Any EHR that stores PHI for you is a business associate and must sign a BAA. Read it: check how quickly they must tell you about a breach, what happens to your data at the end of the contract, and whether their subcontractors (such as cloud hosts) are bound by the same terms.

2. Is data encrypted in transit and at rest?

Data should be encrypted when it travels between devices and the servers, and when it's stored, including backups. Ask in writing. Encryption also matters legally: properly encrypted data that is lost or stolen is generally not considered "unsecured" PHI under the Breach Notification Rule.

3. Does every user get their own login?

Shared logins make it impossible to know who did what. Every clinician, receptionist and biller should have a unique account, and accounts should be easy to switch off the day someone leaves.

4. Is there strong sign-in security?

Ask about password requirements, automatic sign-out after inactivity, and multi-factor authentication. Multi-factor sign-in is one of the most effective protections against stolen passwords.

5. Can you limit access by role?

HIPAA's minimum necessary standard means people should only see what their job requires. Look for role-based permissions, ideally down to specific fields: the front desk may need demographics and appointments, but not clinical notes; a billing contractor may need charges, but not psychotherapy notes.

6. Are there detailed audit logs?

The Security Rule requires audit controls. Your EHR should record who viewed, created, changed or exported a record, and when. Ask whether you can review the logs yourself and how long they are kept.

7. How are backups and outages handled?

Ask how often data is backed up, where backups are stored, how quickly service can be restored after a failure, and what the vendor's uptime commitment is. Your own contingency plan should cover what staff do if the system is unavailable.

8. Where is the data hosted, and who can access it?

Find out which hosting provider and regions are used, which vendor staff can access customer data, and under what circumstances. Ask whether the vendor has independent security assessments it can share, such as a SOC 2 report.

9. Can patients get their records easily?

Patients have a right to access their records under HIPAA, and the 21st Century Cures Act adds expectations around timely electronic access and avoiding information blocking. Check how the EHR supports patient access: a portal, app access or quick, complete record exports.

10. Can you export all of your data?

Your data belongs to your practice. Confirm you can export everything in usable formats, at any time, without a support ticket or fee, and what happens to your data if you leave. Vendor lock-in is a business risk and, if it delays patient access, a compliance risk too.

11. How does the vendor handle security incidents?

Ask how the vendor monitors for threats, how it would notify you of a breach (and how fast), and whether it has had incidents before. The answers, and how comfortable the vendor is giving them, tell you a lot.

12. Does it fit your risk analysis and training?

Your HIPAA risk analysis must cover your EHR. Make sure the system's settings, your policies and staff training line up: who can export data, how devices are secured, how records requests are handled.

Red flags

  • "HIPAA certified" claims with no detail behind them
  • Reluctance to sign a BAA, or a BAA that limits the vendor's obligations heavily
  • No audit logs, or logs only the vendor can see
  • Shared or generic accounts recommended "for convenience"
  • Data exports that require fees or long waits

Frequently asked questions

Is there an official HIPAA certification for EHR software?

No. The government does not certify software as HIPAA-compliant. HIPAA compliance is achieved by your practice, using software and vendors that support the required safeguards.

Is a cloud-based EHR HIPAA-compliant?

It can be, if the vendor signs a business associate agreement and the system has the right safeguards: encryption, access controls, audit logs and backups. Cloud hosting itself is not a problem.

Who is responsible if our EHR vendor has a data breach?

Both of you have obligations. The vendor, as your business associate, must protect the data and tell you about a breach; your practice must notify affected patients and HHS as required. The BAA sets out the details. Our HIPAA checklist for small practices explains breach notification.

Do small practices need multi-factor authentication?

The current HIPAA Security Rule doesn't name multi-factor authentication specifically, but it is one of the most effective protections against stolen passwords, and proposed updates to the rule would make it expected. Turn it on wherever your systems offer it.

What else should we compare between EHRs?

Workflow, billing, cost and support matter as much as security. See our EHR buyer's guide.

How JenPulse approaches this

JenPulse gives every staff member their own login, lets you set what each role can see down to individual fields, keeps an audit trail of sign-ins and changes, keeps each clinic's data separate from every other clinic's, and lets you export your data at any time. You can explore these controls in the live demo. Whichever EHR you choose, including ours, put a signed BAA in place before storing any patient information, and read our HIPAA checklist for small practices for the rest of your compliance program.