Short answer: A vendor claiming to be "HIPAA compliant" on their website isn't evidence — you need to verify it directly by asking for their security documentation (a SOC 2 report or similar), confirming they'll sign a Business Associate Agreement, and asking specific questions about how they handle encryption, access controls, and breach notification. HIPAA compliance isn't a certification a vendor can hold in the way, say, an ISO certification works — so "we're HIPAA compliant" on a marketing page tells you very little on its own.
Why vendor marketing claims aren't enough
Plenty of software vendors put "HIPAA compliant" somewhere on their site because it's expected in healthcare-adjacent markets, not because they've been independently verified against a specific standard. There's no single HIPAA compliance certificate a vendor earns and displays. What actually matters is whether their specific practices meet the requirements — and the only way to know that is to ask directly and get real answers, not take the marketing copy at face value.
What to actually ask a prospective vendor
Will you sign a Business Associate Agreement? This is the first real test. A vendor that hesitates, or tries to avoid signing a BAA while still wanting access to PHI, is a immediate red flag — not a technicality to work around.
Can you provide a SOC 2 report or similar independent audit? A SOC 2 Type II report (or comparable independent security audit) is real, third-party evidence of security practices — closer to actual proof than a vendor's own claims about itself.
How is data encrypted, at rest and in transit? A vendor should be able to answer this specifically, not vaguely reference "industry-standard security."
Do you enforce multi-factor authentication? For any account with access to PHI, this should be a clear yes, not an optional add-on.
What's your breach notification process and timeline? If something goes wrong on their end, you need to know how and how quickly they'll tell you — this affects your own breach notification obligations under HIPAA.
Where is data stored, and who else can access it? Especially relevant for cloud-based tools — understanding where your patients' data physically lives and who has access to it (including the vendor's own subcontractors) matters.
Do you have subcontractors who would also touch this data? If yes, those subcontractors need their own adequate safeguards too, and your agreement with the vendor should address that.
Red flags worth taking seriously
- Reluctance or refusal to sign a BAA
- Vague or evasive answers to specific security questions
- No independent audit or certification of any kind
- Unclear answers about where data is stored or who can access it
- Pressure to skip due diligence because "everyone uses us"
Making vendor vetting less of a one-off scramble
Every new vendor relationship is an opportunity to either strengthen or weaken your practice's actual security posture, and it's easy to skip proper vetting when you're excited about a new tool's features. Building a simple, repeatable vetting checklist — the questions above, asked every time — turns this from a one-off judgment call into a consistent process.