Editorial standards
People make real decisions off these pages — whether to keep using a tool, whether to move patient data out of it, what to tell a client who asked. That deserves a stated method rather than a confident tone. This is ours.
Last updated .
47
Vendors published
109
Primary sources cited
180 days
Maximum review interval
Primary sources only
Every factual claim on a checker page traces to a source listed at the bottom of that page, and those sources are restricted to material the vendor itself publishes: its business associate agreement page, its trust or compliance centre, its official documentation and support articles, and its terms.
We do not cite other people’s blog posts, comparison articles, competitor content or other compliance checkers, however confident they sound. A great deal of what circulates about vendor HIPAA status is years out of date and copied between sites without anyone re-reading the original. Where a vendor’s own marketing page contradicts its own support documentation — which happens more than you would expect — we follow the documentation and the agreement text, and we note the conflict.
Everything carries a date
Each source shows the date we actually read it, and each page shows when it was last reviewed and when the next review is due. A claim about a vendor is only as good as the day it was checked, and hiding that behind a “2026 update” heading on a page written years ago is the single most common failure in this genre.
Where a vendor publishes its own effective date — an eligible-services list, an included-functionality list — we record that too, because those documents get revised without announcement.
Re-verification
Every entry is re-verified at least every 180 days. Some are set to a shorter interval because the underlying facts move faster; the entry for AI assistants is on 90 days, because every source we used was updated within two days of us reading it.
A review is also triggered early when:
- a vendor changes its pricing or plan structure
- a link to a vendor’s agreement page stops resolving
- the vendor is acquired, renamed or merges a product line
- a reader tells us something looks wrong
Corrections are published, never silent
Every page carries a visible change history. If a verdict changes, or we got something wrong, the correction appears there with its date. We do not quietly edit a page and leave it looking as though it always said the new thing.
If you believe an entry is wrong or has gone stale, write to support@hipaacompliancesoftware.org. Vendor corrections are welcome on the same terms as anyone else’s: send us the documentation and we will read it.
What a verdict means
- Yes — usable with patient information given a signed agreement, without unusual restrictions.
- Conditional — usable only on a particular plan, or with particular settings, or with parts of the product excluded. Most vendors are here, and the detail is the whole point.
- No — the vendor will not sign an agreement, or its terms prohibit patient information outright.
Where the evidence for a verdict is weaker than we would like — a vendor that has never explicitly said it will not sign, for instance, so the answer is inferred from converging signals rather than a plain statement — we hold the entry to a shorter review interval and record the uncertainty in our internal notes rather than presenting inference as fact.
No paid placement, no affiliate links
No vendor pays to appear here, to rank higher, to be recommended as an alternative, or to have a verdict reconsidered. There are no affiliate links anywhere on this site, and our revenue comes solely from subscriptions to our own software.
That independence is the point. It is why we are willing to publish a straight “no” about very well-known products, and why an alternative appears on a page only when it genuinely fits the job.
What we will not do
We do not describe any organization or product as “HIPAA certified”, because no such designation exists and no body issues one. We do not tell you that using a particular vendor makes you compliant, because compliance depends on your configuration, your executed agreement and how your staff actually work. And we do not give legal advice — we are not a law firm, and questions about your specific obligations belong with counsel.
Who writes this
Entries are researched and maintained by the CompyMaxeditorial team against the method above, and reviewed before publication. Our interest in getting this right is not purely editorial: the same research feeds the vendor register inside our product, so an inaccurate entry would propagate into our customers’ own compliance records.
Everything published here is information, not certification and not legal advice. Vendors change their terms without notice — confirm anything you rely on directly with them before acting.
Keep reading
- Vendor compliance checkerVerdicts on the tools small healthcare organizations actually run.
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA compliance checklistEvery requirement, in order, with the evidence that proves it.
- HIPAA training requirementsWho must be trained, how often, and what proof to keep.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- About the teamThe compliance officers, clinicians and security people behind the research.