Is TigerConnect HIPAA compliant?
Yes — TigerConnect's standard agreement applies automatically through its terms of service unless you negotiate your own, but it is a sales-quoted enterprise product and the invitation text reaching the patient is still ordinary carrier SMS.
Applies to TigerConnect clinical collaboration and patient engagement. Last reviewed against TigerConnect's own documentation. Next review January 2, 2027.
Reviewed by Dr. Anita Desai, MD — Psychiatrist, solo private practice.
What you must do
- Know which agreement governs you. TigerConnect's terms state that absent a separate agreement, where it acts as a business associate the parties are subject to its standard agreement, published and incorporated by reference.
- If your legal team wants negotiated terms, execute a separate agreement — it displaces the standard one.
- Buy through TigerConnect sales. There is no self-serve tier and no published pricing.
- Keep clinical detail out of the initial invitation text; the link is the gateway and the conversation is the protected part.
- Meet the covered entity obligations in the agreement: notify TigerConnect of limits in your notice of privacy practices, of revocations, and of restrictions you have agreed to.
- Plan around clinician-initiated contact — conversations are clinician-controlled, so patients cannot start one.
- Have counsel review the de-identification clause, which lets TigerConnect de-identify your records and retain ownership of what it creates.
Does TigerConnect sign a business associate agreement?
Yes. TigerConnect offers one. No published plan gate. The standard agreement applies wherever TigerConnect acts as a business associate under a services agreement. Nothing to request if you rely on the standard agreement — it is incorporated into the terms of service by reference. To negotiate your own, raise it during contracting.
What this means in practice
TigerConnect's agreement is not something you have to chase. Its terms of service say that where TigerConnect acts as a business associate and no separate agreement has been signed, both parties are bound by TigerConnect's standard agreement, published on its own site and incorporated by reference. Larger buyers still negotiate their own, which then displaces it.
The published terms are unusually specific in your favour. Patient information inside customer data may not be used to improve the services, customer data is processed and stored inside the United States, and liability for an improper disclosure of patient information is carved out of the ordinary cap. TigerConnect does keep the right to create and own de-identified data derived from your records.
For patient texting, understand the mechanics before you train staff. The patient receives an ordinary carrier text containing a link, and the conversation itself runs in a secure encrypted session with no app or password. Keep clinical detail out of that first invitation, and remember conversations are clinician-initiated — patients cannot start one.
How organizations get this wrong
The specific mistakes we see with TigerConnect, not generic advice.
- Putting clinical detail in the invitation text. Only the linked session is the secure conversation; the SMS carrying the link is ordinary carrier traffic.
- Not knowing which agreement applies. Check whether your contract has a negotiated one or silently relies on the standard version incorporated by reference.
- Overlooking the de-identification clause. TigerConnect may de-identify your patient records and owns what it creates.
- Expecting patients to start conversations. Engagement is clinician-controlled, so an inbound patient question has nowhere to land until staff reach out.
What the agreement does not cover
- Personal data about your own authorized users of the service, which the agreement states is not treated as patient information.
- De-identified information created from your records, which TigerConnect owns.
- The carrier SMS carrying the invitation link, as distinct from the secure session it opens.
- TigerConnect publishes no covered-services list, so scope is defined by whatever the services agreement names.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Published per-user pricing and a self-serve trial, which suits a small practice better
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with TigerConnect, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from TigerConnect’s own published documentation, read on the date shown.
- Business Associate Agreement — TigerConnect. Published April 22, 2026. Read July 29, 2026.
- TigerConnect Terms of Service Agreement — TigerConnect. Published July 6, 2026. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects TigerConnect’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.