Is that tool HIPAA compliant?
A straight answer for 47 of the tools small healthcare organizations actually run — the verdict, the exact conditions, which plan you need, where to get the vendor's business associate agreement, and the sources we based it on with the date we read them.
- 3 Yes
- 39 Conditional
- 5 No
Free, no signup. Verdict, conditions and the vendor’s own agreement link.
Most looked up
How we decide
Primary sources only. We read the vendor’s own agreement page, trust page and documentation. Never another blog, never a competitor, never another checker.
Dated, and re-checked. Every page shows when we last read the sources and when it is due for review. Corrections appear in a visible change history, never as a silent edit.
No paid placement. Alternatives are listed on merit. We take no money from any vendor named here and use no affiliate links.
Email providers
All email providers →Gmail
ConditionalYes for Gmail inside a managed Google Workspace account once a super administrator accepts Google's amendment — a free personal Gmail address cannot be covered at all.
Hushmail
ConditionalOnly if you sign up on a Hushmail for Healthcare plan — the identically priced Small Business, Law and Personal plans are marked as not including a business associate agreement.
LuxSci
ConditionalYes — LuxSci includes the agreement at no extra cost, but an authorised officer must sign and return LuxSci's own form, and patient information must stay inside the services it lists as eligible.
Paubox
YesYes — every Paubox account includes a business associate agreement at no extra cost, and Paubox will not finish configuring your email until you have agreed to it.
Virtru
ConditionalYes on a paid Virtru package, but only after you email their BAA address and execute the agreement — Virtru does not issue it automatically, and its subscription terms require you to ask.
Video conferencing
All video conferencing tools →Google Meet
ConditionalYes, if you run Meet inside a managed Google Workspace account and a super administrator accepts the amendment before any patient visit takes place.
Microsoft Teams
ConditionalYes — Teams is named on Microsoft's in-scope services list and the agreement applies to business subscriptions automatically, but you configure the tenant and keep patient information out of anything not on that list.
Zoom
ConditionalYes, if you are on a paid Zoom plan and you execute Zoom's business associate agreement before using Zoom for anything involving patient information.
Telehealth platforms
All telehealth platforms →Doxy.me
ConditionalYes — doxy.me gives every user a free agreement you generate yourself in account settings, but the version on individual accounts names one provider, so a practice with two or more clinicians needs the clinic version instead.
SimplePractice
YesYes — you agreed to SimplePractice's business associate agreement when you started your trial, it covers every feature including telehealth on all plans, and you never sign it again.
VSee
ConditionalYes for VSee Clinic once you email their compliance address and get the agreement signed — but the free VSee Messenger app is excluded, and VSee's own pages disagree about whether the free Clinic tier needs a paid subscription first.
Fax services
All fax services →eFax
ConditionalOnly on eFax's business-grade plans — the agreement is listed on Business and Corporate, and the consumer Personal plan does not include one, so a solo practice on a cheap eFax number is unprotected.
Documo (mFax)
YesYes — Documo states HIPAA compliance comes standard with every plan at no extra fee and that it signs a business associate agreement for healthcare customers, including on its cheapest tier.
SRFax
ConditionalYes if you buy from SRFax's Healthcare Solutions range and request the agreement — the cheaper Standard Solutions plans are sold for general small business use, not healthcare.
Patient texting
All patient texting platforms →Spruce Health
ConditionalYes — the agreement is built into Spruce's standard terms and applies automatically on trials and both paid plans, but Spruce classes SMS, email, fax and phone as unsecure channels, so only app-to-app messaging inside Spruce is genuinely secure.
TigerConnect
ConditionalYes — TigerConnect's standard agreement applies automatically through its terms of service unless you negotiate your own, but it is a sales-quoted enterprise product and the invitation text reaching the patient is still ordinary carrier SMS.
Productivity suites
All productivity suites →Google Workspace
ConditionalYes, if a super administrator accepts Google's business associate amendment in the Admin console and you keep patient information only inside the specific Google services it covers.
Microsoft 365
ConditionalYes — the agreement already applies to business and enterprise subscriptions automatically through Microsoft's Data Protection Addendum, but you must keep patient information inside the services Microsoft lists as in scope.
File storage
All file storage and sharing tools →Box
ConditionalYes, if you are on a Box Enterprise-tier account and you request and sign the agreement before any patient files are stored.
Dropbox
ConditionalYes, if you are on a Dropbox team plan and your administrator signs the agreement in the admin console before any patient files are uploaded.
OneDrive
ConditionalYes for OneDrive for Business on a Microsoft 365 business subscription, where the agreement applies automatically — but the consumer OneDrive on a personal Microsoft account is a different product and is not covered.
Phone systems
All phone and VoIP systems →Google Voice
ConditionalYes, if you use Google Voice inside a paid Google Workspace account with licenses assigned to the staff who handle patient information, and your administrator accepts Google's amendment first — the free consumer version cannot be used with patient information.
OpenPhone (now Quo)
ConditionalYes for calls if you are on the Business or Scale plan and sign the agreement — but text messaging is explicitly excluded from it, so anything you text a patient sits outside the agreement entirely.
RingCentral
ConditionalYes, if you are a paying customer, ask RingCentral for their business associate agreement and sign it, and keep patient information within the specific services that agreement names.
Scheduling
All scheduling tools →Calendly
NoNo — Calendly's customer terms specifically forbid putting patient information into the service and Calendly does not offer a business associate agreement, so it should not be used to book patients or collect their details.
Acuity Scheduling
ConditionalYes, if you are on the Premium or Powerhouse plan and enter the agreement from your scheduling settings — but it covers Acuity only, and turning HIPAA mode on permanently disables invoices.
E-signature
All e-signature tools →Docusign
ConditionalYes, if you buy an Enhanced plan through Docusign sales and sign their business associate addendum first — the self-serve Personal, Standard and Business Pro plans do not include it.
Dropbox Sign
ConditionalOnly on an annual Standard or Premium plan that meets Dropbox's minimum contract value and has a signed agreement — there is no self-serve path and monthly billing does not qualify.
Docs and notes
All document and note tools →Asana
ConditionalOnly on Asana's top tier with the HIPAA feature switched on — and even then Asana forbids using it as your system of record or for contacting patients, so it is a staff task tracker and nothing more.
monday.com
ConditionalYes on the Enterprise plan only, once an admin accepts the agreement and clicks Activate HIPAA Compliance — and coverage ends the moment you downgrade to a lower plan.
Notion
ConditionalYes, if you are on the Enterprise plan, accept the agreement inside workspace settings and lock the workspace down as Notion requires — and even then you may not use Notion to communicate with patients.
Databases and app builders
All database and app-building tools →HubSpot
ConditionalYes now, but only on an Enterprise subscription where a super admin switches on Sensitive Data, identifies the account as a covered entity and accepts the agreement — and only in the specific tools HubSpot lists.
Salesforce
ConditionalYes, if you sign Salesforce's business associate addendum through your account representative and it names the specific Salesforce service you are putting patient information into.
Zoho CRM
ConditionalYes, if you are on Zoho CRM Enterprise or Ultimate, email Zoho's legal team for the agreement, and then mark by hand every module and field that will hold patient information.
Form builders
All form builders →Formstack
ConditionalYes, if Formstack moves you onto one of its healthcare plans, which comes with a signed agreement but restricts your integrations, email and attachments.
Google Forms
ConditionalYes, if you use Forms inside a paid Google Workspace account where a super administrator has accepted Google's amendment — Forms is covered as part of Google Drive.
Jotform
ConditionalYes, if you are on the Gold or Enterprise plan and run Jotform's HIPAA setup wizard, which migrates your whole account to an isolated system and ends with you signing the agreement.
Squarespace website forms
NoNo — Squarespace states its contact form features, including the form block, cannot be part of a HIPAA compliant solution, and its addendum covers Acuity Scheduling and nothing else.
Typeform
ConditionalOnly on Typeform's enterprise-level plans, after you tell Typeform in advance and it agrees to sign — on the ordinary self-serve plans Typeform's own terms bar you from collecting patient information.
Turn this list into your vendor register.
Knowing which tools are allowed is step one. Tracking which agreements you have actually signed, when they expire and who owns each one is what a client’s security questionnaire actually asks for. Our platform keeps that register — and exports it as part of a dated evidence pack.
See how it worksKeep reading
- HIPAA glossaryPlain-language definitions, each with its citation.
- HIPAA compliance checklistEvery requirement, in order, with the evidence that proves it.
- HIPAA training requirementsWho must be trained, how often, and what proof to keep.
- HIPAA compliance auditsThe three different things called an audit, and what each asks for.
- Practice management softwareHow to evaluate what a vendor is actually offering you.
- How we researchSourcing, review cadence and corrections policy.
- About the teamThe compliance officers, clinicians and security people behind the research.
Looking for the software rather than the explanation? Vendor and BAA register.
This checker is information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change their terms without notice, so confirm anything you rely on directly with them. Signing an agreement is necessary but not sufficient — whether your use is compliant also depends on how you configure the tool and how your staff use it.