Framework Decisions~6 min readUpdated July 2026

Do You Need HIPAA Compliance Software?

Start with the fact the sales pages step around: there is no official HIPAA certification. HIPAA is a regulation, enforced by HHS - no body certifies compliance with it, and no product can make you "HIPAA certified." What the platforms sell is readiness: organized risk assessments, policies, safeguards, evidence. That's real value when the obligation is real - and pure shelf-ware when it isn't. This page is about telling those apart.

This guide is independent. GRC Migrate takes nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.

The test is PHI, not "health"

HIPAA obligations attach to covered entities (providers, plans, clearinghouses) and business associates - vendors that create, receive, maintain, or transmit protected health information on a covered entity's behalf, usually under a BAA. Two clean signals: a customer asking you to sign a BAA means the obligation is real; PHI in your data flows means it's real whether anyone asked or not. No PHI, no BAAs, no covered-entity relationships? Then "HIPAA compliance" software is a module in search of an obligation.

Map your actual obligations, not your industry adjective.

Find your minimum framework set in 3 minutes

Your data flows, customers, and frameworks in - what actually applies to you out. No email required to see results.

Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.

Who's being oversold

The classic case: a health-adjacent app with no PHI - wellness tracking with self-entered data, fitness content, B2B tooling that sells to health companies without touching their patient data. "You're in health, so you need our HIPAA module" is topic-matching, not compliance analysis. The tell is the missing paperwork: nobody has asked you for a BAA, and you couldn't name where PHI would enter your systems if pressed. Map the data flows first; the map either produces an obligation or it doesn't, and it's free.

What you actually need when HIPAA applies

The regulation's own shape, not a badge: a documented risk assessment, BAAs with every vendor touching PHI, administrative/physical/technical safeguards, training, and breach procedures. A platform earns its fee by organizing exactly that and keeping the evidence current - genuinely useful once obligations are real, especially alongside SOC 2 for the same buyers. But sequence matters: the risk assessment produces the requirements; the software organizes them. Bought in the other order, the module is the expensive way to stay non-compliant with a nicer dashboard.

Obligation is real? Then it's a tooling-fit question.

Get your framework plan - 3 minutes

HIPAA rarely travels alone - the assessment sequences it with SOC 2 and the rest of your actual set.

Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.

What the platforms bundle (and what to check)

HIPAA is usually sold as a framework add-on to the same platforms covered across this site - which means the same economics as every add-on: paid per framework, priced better at signing than mid-contract, compounding at renewal (mechanics in the cost-stacking guide; quote structures on the pricing hub). We don't print HIPAA-specific assessment costs - none are vetted; treat any you read as sales collateral and get yours quoted in writing. One check that matters more than features: whether the platform vendor itself will sign a BAA covering the PHI-adjacent evidence you'd store in it. Ask before the demo, not after.

Frequently asked questions

Buy for the obligation, not the adjective.

Find your minimum framework set in 3 minutes

Free, no email required to see results - the same assessment our qualification calls start from.

Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.

Related: Which frameworks do you need? · Do you need SOC 2? · Multi-framework cost stacking