Every scheduling tool, form builder, fax service, and cloud backup aimed at healthcare has a page with a badge on it. HIPAA COMPLIANT. Sometimes with a shield icon.

There is no such certification. The HHS Office for Civil Rights, the agency that actually enforces HIPAA, says it plainly: "HHS and OCR do not endorse any private consultants' or education providers' seminars, materials or systems, and do not certify any persons or products as 'HIPAA compliant.'"

Any badge you see was made by the company's own marketing team, or bought from a third-party auditor whose standards the company chose. That doesn't mean the vendors are lying, exactly. It means the sentence is doing less work than it appears to.

The question that actually means something

Not "are you HIPAA compliant." Ask: "Will you sign a Business Associate Agreement?"

A BAA is a contract. In it, the vendor accepts legal responsibility for safeguarding the protected health information they handle on your behalf, agrees to report breaches to you, and agrees to hold their own subcontractors to the same terms. It's the mechanism the law actually uses.

The answers sort themselves quickly. "Yes, here it is." Good — read it, sign it, keep a copy where you can find it. "Yes, on our Enterprise plan." Common and legitimate, and it means the plan you're currently on isn't covered, which is worth knowing before rather than after. "Our platform is HIPAA compliant." That's not an answer to the question; ask again, plainly. "You don't need one for what we do." Sometimes true — a vendor that genuinely never touches PHI doesn't need a BAA. Get them to say in writing that they don't handle it, and make sure that matches what your setup actually does.

Compliance is split, and the split is the point

Even with a BAA in hand, the vendor is responsible for their part and you're responsible for yours. The cloud provider secures the infrastructure. You control who has accounts, whether MFA is on, who still has access after they quit, what gets shared outside the practice, and what happens on the laptop in someone's car.

Most breaches at small practices land squarely on the customer's side of that line. Not because the software failed — because an account stayed active, or a password was shared, or a device left the building. Which means a vendor's compliance posture, however good, cannot save a practice from its own access control. That's the uncomfortable part, and it's why "we bought the HIPAA-compliant one" isn't a plan.

A short checklist for your next vendor conversation

Will you sign a BAA? Get the document, not the assurance. What exactly do you store, and where? Do you use subcontractors who touch our data, and are they under the same terms? How and how fast do you notify us of a breach? What happens to our data if we leave, in what format and within how long? Do you support single sign-on and multi-factor authentication for our staff accounts?

That's a fifteen-minute call. It'll tell you more about a vendor than any badge.

The paperwork nobody has

Here's where most small practices actually sit: four or five vendors touching patient data, maybe two signed BAAs somewhere in an email thread, and no single list of what they've agreed to with whom.

You don't need a compliance program to fix that. You need one page listing every system that touches patient data, who the vendor is, whether a BAA exists and where the copy lives, and who at your practice owns the relationship.

That page takes an afternoon. It's the difference between a bad day and a catastrophic one, because in an incident the first question anyone asks is "what systems were involved," and the answer has to already exist.

This article is general information, not legal advice. For how these requirements apply to your practice, talk to a healthcare attorney.