For healthcare software and digital health vendors
The deal is ready. The security questionnaire is not.
If your product touches protected health information on behalf of a provider or payer, you are a business associate, and their procurement team will ask you to prove it before signing. This gives you a documented program, a live trust page and a reusable answer library so the review stops being a fire drill.
Last reviewed .
Security review is now part of the sales cycle.
The pattern is familiar: a champion inside the health system loves the product, then hands you a spreadsheet of security questions, a BAA to countersign and a request for evidence of your safeguards. Every week you spend assembling that from scratch is a week the contract sits unsigned — and every deal after it repeats the exercise.
A questionnaire answer library
Around fifty of the questions that recur across health-system vendor reviews, answered from your live program data rather than from memory — encryption stance, access control, training completion, incident process, subprocessor list. Copy them out or export the set.
A trust page you can send instead of a slide
A live page showing your current compliance posture with per-section control over what is visible. Send one link during procurement rather than rebuilding a PDF for each prospect.
Evidence with dates on it
Reviewers care when something was last confirmed. Policies carry version and acknowledgement dates, training carries completion dates, and automated checks carry the timestamp they ran — so the packet reads as maintained, not assembled last night.
Verified controls where we can check them
Connect Microsoft 365 read-only and multi-factor registration, offboarding, admin sprawl and external mail forwarding are confirmed against the actual configuration. Verified items are labelled differently from self-attested ones, which is exactly the distinction a reviewer is probing for. Google Workspace checks are built and awaiting Google's verification review.
Your subprocessors, tracked
Reviewers ask who else touches the data. Keep your cloud, storage, analytics and support vendors in one register with BAA status and dates, ready to attach.
Sized for a startup, not an enterprise GRC budget
$79 a month, or $149 with the trust page and questionnaire library. Platforms built around SOC 2 typically start in the thousands per year — reasonable if SOC 2 is the requirement, heavy if what you actually need is HIPAA evidence.
How to tell whether you are a business associate
The test is not whether you work in healthcare, sell to hospitals, or store data in a certified data centre. It is whether your company creates, receives, maintains or transmits protected health information to perform a function or service for a covered entity. If it does, you are a business associate under 45 CFR 160.103, and the obligations attach directly to you — not only through your contract, but by law since the 2013 Omnibus Rule.
Three misreadings put vendors on the wrong side of this, and all three surface during procurement rather than at signature:
- “We only host it, we never look at it”
- Persistent access is what matters, not whether anyone reads the data. The conduit exception is deliberately narrow — it covers carriers moving data transiently, like an ISP or a courier. Cloud and SaaS providers that store patient information are business associates even when the data is encrypted and never accessed.
- “It is de-identified, so HIPAA does not apply”
- Only if it meets the Safe Harbor or expert-determination standard in 45 CFR 164.514. Stripping names is not enough — Safe Harbor removes eighteen identifier classes, including dates more precise than a year, ZIP codes below the first three digits, device identifiers and full-face images. Partial de-identification leaves the data protected.
- “Our customer signed a BAA, so we are covered”
- That agreement binds you rather than protecting you. It also flows downstream: every subcontractor that touches the data on your behalf needs its own agreement with you, and the chain must be unbroken. Your cloud host, error-monitoring service, analytics tool and outsourced support desk each need looking at.
If you are a business associate, the practical consequences are direct: you must execute agreements with both your customers and your subcontractors, run a documented security programme built on a risk analysis, train your workforce, and be able to notify your covered-entity customer within 60 days of discovering a breach. Enforcement against business associates is real and separate from action against providers: OCR publishes its resolution agreements, and business associates appear among them. Check the current list on the HHS enforcement pages rather than trusting any vendor's summary of it, including ours.
What a health-system security review actually asks for
Reviews vary in format but converge on the same eight areas. Knowing the shape in advance is most of the advantage, because the delay in a review is almost never the answering — it is the assembling.
| What they ask about | What they actually want to see |
|---|---|
| Risk analysis | A dated, organization-wide security risk analysis covering every Security Rule safeguard — not a vulnerability scan, which is a different exercise reviewers frequently find substituted. |
| Policies | Written policies you have actually adopted, with version numbers and evidence that staff acknowledged them. Undated templates read as shelfware. |
| Workforce training | Completion records per person with dates, plus a renewal cadence. “All staff are trained” without records is the most common finding. |
| Access control and authentication | How accounts are provisioned and removed, whether multi-factor authentication is enforced, and how you review access periodically. |
| Encryption | Your stance in transit and at rest, stated concretely, plus what happens on lost devices. |
| Incident and breach response | A documented procedure, a log showing it is used, and your notification commitment with a specific timeframe. |
| Subprocessors | The list of downstream vendors touching their data, with agreement status for each. |
| Business continuity | Backup approach, tested restores, and recovery objectives you can state in numbers. |
Two things separate a review that closes quickly from one that drags. First, every answer carries a date, because a reviewer's real question is whether the programme is maintained or was assembled the week they asked. Second, the answers agree with each other — a questionnaire claiming annual training beside an evidence pack showing two lapsed staff creates a follow-up round that costs more time than the original answer saved.
SOC 2, HITRUST and HIPAA are three different asks
Vendors lose weeks to this confusion, usually by starting an expensive certification when the buyer wanted something else entirely. Read the request literally before you scope anything.
| What the buyer asked for | What it actually requires | Rough cost and time |
|---|---|---|
| “Send your HIPAA documentation” | An executed BAA plus evidence of your programme: risk analysis, policies, training records, incident procedure. No external auditor is involved, because HIPAA has no certification. | Days to weeks with the artifacts in place |
| “Are you SOC 2 Type II?” | An audit by a licensed CPA firm against the AICPA trust services criteria, over an observation window of typically 3–12 months. | Tens of thousands of dollars, and typically 6–12 months to a first Type II report. Get quotes; this varies widely. |
| “Are you HITRUST certified?” | Assessment against the HITRUST CSF by an authorized external assessor. The heaviest of the three, and usually asked only by large health systems and payers. | The most expensive and slowest of the three. Scope it directly with an authorized assessor. |
Where they overlap: a well-run HIPAA programme produces most of the evidence a SOC 2 engagement will ask for, so the work is not wasted if certification comes later. Where they differ is the point — SOC 2 and HITRUST are assurance products that depend on a third party's opinion, while HIPAA compliance is a legal obligation you meet and evidence yourself. If procurement asks for “HIPAA certification”, the correct and credible answer is that no such designation exists, followed immediately by the evidence pack that answers what they meant.
From signup to a sendable evidence pack
The path below is the one the product is built around. A small vendor with an existing security posture typically reaches a sendable pack inside a week of elapsed time, most of which is waiting on staff to complete training and acknowledge policies rather than on the work itself.
Complete the guided risk analysis
Sixty-eight controls mapped to 45 CFR 164.308, 164.310, 164.312 and 164.316, each phrased as a plain question rather than a citation. Unanswered controls count against the score rather than being skipped, so the number means something. Expect an afternoon.
Work the remediation list it generates
Every gap becomes a task with an owner, a due date and somewhere to attach evidence. Some close in minutes — turning on a setting — and some are genuine projects. Reviewers accept open items with owners and dates far more readily than a page claiming everything is perfect.
Adopt and publish your policies
Fourteen plain-language templates covering the required Security Rule areas. Publishing is blocked while bracketed placeholders remain, because a policy still saying [ORGANIZATION NAME] is the single fastest way to fail a review.
Record training and collect acknowledgements
Each person acknowledges the specific policy version they read, and training completions carry dates and renewal intervals. This is the step gated by other people, so start it early.
Build the vendor and subprocessor register
List every downstream vendor touching patient data, with agreement status and renewal dates. Seeded from our published research so you are not starting from an empty table.
Connect Microsoft 365 for verified checks
Read-only. Multi-factor registration, dormant accounts, administrator sprawl, external mail forwarding and baseline identity protection are confirmed against the real configuration and filed as dated evidence. Verified items are labelled differently from self-attested ones.
Generate the Trust Packet and publish the trust page
One button produces the dated PDF pack; the trust page gives procurement a live link with per-section control over what is visible. Both report open gaps rather than hiding them, which is what makes them survive a follow-up question.
Questions we get
- Does software have to be HIPAA-compliant?
- Software itself is neither compliant nor certifiable — the obligations attach to organizations. If your product creates, receives, maintains or transmits patient information for covered entities, your company is a business associate: you must sign agreements, run a documented security programme, and be able to evidence it. That evidence is what the hospital questionnaire is really asking for.
- Who is exempt from HIPAA?
- Companies that never touch protected health information for a covered entity, and consumer apps where individuals enter their own health data — those answer to the FTC's health breach rules instead. The exemption vendors wrongly rely on is 'we only host it': persistent access to patient information generally makes you a business associate, and the conduit exception covers carriers like ISPs, not SaaS.
- Does SOC 2 cover privacy?
- Only if the Privacy trust services criterion is in scope, and most SOC 2 reports cover Security plus Availability only. Either way SOC 2 is an audit framework, not HIPAA: if a buyer specifically requires SOC 2 Type II, that needs an accounting firm. If the requirement is a business associate agreement plus HIPAA evidence — the common healthcare ask — that is what this platform produces.
Stop rebuilding the same answers for every deal.
Set up the program once, then answer each review from live data. Free for 14 days, no credit card, no sales call.
Start free trialWe publish software and researched information, not legal advice, and no product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules.
Keep reading
- Answering a security questionnaireWhat they are really asking for, and what to send.
- Trust Packet exportOne dated pack answering the whole request.
- For billing and RCM companiesYou are a business associate. Sooner or later someone asks.
- Questionnaire answer starterFill-in-the-blank answers to the twelve questions every form asks.