HIPAA Compliance Checklist for Small Business Software

HIPAA isn't just for hospitals. If you handle protected health information in any software tool, you need a Business Associate Agreement — here's how to verify compliance.

By The StackMatch Research Team

60% of healthcare-adjacent SMBs unknowingly use non-compliant tools for protected health information — exposing them to six-figure fines

60%of healthcare SMBs use non-compliant tools
$50K-$1.5MHIPAA fine range per violation
7compliance checks before every PHI tool purchase

HIPAA isn't just for hospitals. If you handle protected health information in any software tool, you need a Business Associate Agreement — here's how to verify compliance.

60%
of healthcare SMBs use non-compliant tools
Many small healthcare businesses unknowingly use tools that violate HIPAA requirements.

Using a non-HIPAA-compliant tool for protected health information can expose your business to fines starting at $50,000 per violation.

HIPAA compliance checklist

  • Does the vendor sign a Business Associate Agreement (BAA)?
  • Is data encrypted at rest and in transit?
  • Are access controls and audit logs in place?
  • Does the tool support data backup and disaster recovery?

HIPAA compliance for software requires BAAs, encryption, access controls, and audit capabilities.

HIPAA compliance is a chain. Every tool that touches protected health information must have security safeguards and a signed Business Associate Agreement in place.

The HIPAA compliance checklist

Vendor compliance verification

  • Business Associate Agreement (BAA) signed and current
  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access controls with unique user credentials
  • Audit logging: who accessed what data, when, and from where
  • Breach notification commitment within 60 days
$125K
average HIPAA settlement for small providers
The average HIPAA settlement for a small healthcare business exceeds $125,000 — not including legal fees, remediation costs, and reputational damage.

Consumer-grade tools (Gmail, Dropbox, Google Sheets) can be HIPAA-compliant — but only if you purchase the business tier and sign the appropriate BAAs. The default consumer terms are never compliant.

The most common HIPAA mistake is assuming compliance because the vendor says they're 'HIPAA-friendly.' Friendly isn't compliant. Only a signed BAA with specific, audited safeguards creates legal compliance.

Each compliance element is a building block. Missing any one — encryption, access controls, audit logs, BAA — creates a gap in your compliance posture that a breach would expose.

Common compliance gaps

HIPAA compliance by tool type

Tool typeBAA availableEncryptionAudit trail
Business-tier CRM
Consumer file sharingPartial
Enterprise email
Free project management
Industry-specific EHR
7
vendor compliance checks to run before purchase
Every tool handling PHI needs BAA, encryption, access controls, audit logging, backup, breach notification, and employee training verification.

HIPAA isn't just for hospitals. If you handle protected health information in any software tool, you need a Business Associate Agreement — here's how to verify compliance.

StackMatch savings illustration
See which tools in your stack handle sensitive data — and whether your current vendors have the compliance documentation you need.

Run the free audit to see which tools in your stack handle sensitive data — and whether your current vendors have the compliance documentation you need.

Common mistakes

The most common HIPAA mistake is assuming compliance because the vendor says they're 'HIPAA-friendly.' Friendly isn't compliant — only a signed BAA with specific safeguards is. Another mistake is using consumer-grade tools (Gmail, Dropbox, Google Sheets) for PHI without a BAA in place. These tools can be made compliant, but only if you purchase the business tier and sign the appropriate agreements. The default consumer terms are not HIPAA-compliant.

HIPAA isn't just for hospitals. If you handle protected health information in any software tool, you need a Business Associate Agreement — here's how to verify compliance.

Run the free audit to see which tools in your stack handle sensitive data — and whether your current vendors have the compliance documentation you need.

Run your own audit
More from the blog