← Back to blog
Guide

HIPAA questions to ask before you choose practice software

September 24, 2026

If a practice software vendor will store client records, HIPAA treats a vendor that stores your client records as your business associate. Before you sign up, there are a few questions worth asking. Here they are, with what the U.S. Department of Health and Human Services (HHS) says behind each one.

1. Will you sign a Business Associate Agreement?

HHS says a covered entity needs a written contract with a business associate, and that the same applies to a cloud service provider that stores or processes electronic protected health information for you. The agreement has to set out what the vendor may do with the information, require safeguards that follow the HIPAA Security Rule, and require the vendor to report any use or disclosure that the contract does not allow, including breaches. If a vendor will not sign one, that decides the question.

2. What happens to our data when I leave?

HHS says the agreement must require the business associate to return or destroy the protected health information when the contract ends, where that is feasible. Ask how you export your records, in what format, and how deletion works.

3. Where is the data kept and how is it protected?

Ask where records are stored and whether they are encrypted at rest and in transit. Ask which subcontractors, such as a hosting company, touch the data, and whether the vendor has a Business Associate Agreement with them.

4. Is there an audit trail?

You should be able to see who viewed or changed a record and when. Ask whether clinical notes can be edited silently, or whether changes are logged.

5. What is your breach process?

Ask how and how quickly the vendor will tell you if client information is exposed. The agreement is where that commitment belongs, so read that section before you sign.

Be careful with the words "HIPAA certified"

HHS says it does not certify any person or product as HIPAA compliant, and it does not endorse private organizations' certifications. A vendor can describe how it complies, and you should ask for that description in the agreement and in writing. A badge on a website settles nothing.

How RafaNest answers

RafaNest provides a Business Associate Agreement for practitioners. Client records are encrypted at rest, clinical records are append-only with an audit trail, the platform runs on AWS under a signed Business Associate Agreement, and you can export your patient list. You can read more in HIPAA-secure patient records, built on AWS. Read the agreement itself, as you would with any vendor.

The requirements above come from the HHS pages on business associates and HIPAA and cloud computing. This is general information and not legal advice.

Ready to modernize your practice?

Start free — no credit card required.

Get started free