HIPAA-ready by design: what to look for in your EHR

Compliance isn't a feature you bolt on. What a HIPAA-ready EHR looks like — audit logs, encryption, access.

Share

Every EHR vendor says "HIPAA compliant." The phrase is close to meaningless as marketing — HIPAA compliance is a property of how a system is built and operated, not a checkbox on a datasheet. Here is what the phrase should actually mean, in terms you can verify.

Questions with verifiable answers

Is every access logged? A HIPAA-ready system records who viewed and changed what, and when — and lets an administrator actually query it. Ask to see the audit log, not to be told it exists.

Is data encrypted in transit and at rest? TLS everywhere, encrypted storage always, keys managed properly. This is table stakes; a vendor who hedges here is telling you something.

Is access role-based and least-privilege? The front desk does not need clinical notes; a locum does not need the whole panel. Granular roles are the difference between a policy and a hope.

Will they sign a BAA — and do their subprocessors? Every vendor that touches PHI on your behalf must sign a business associate agreement, and their own vendors must be covered too. Ask for the subprocessor list.

Where does PHI go besides the EHR? Error tracking, analytics, AI features, payment processing — each is a place PHI can leak if the vendor is careless. A serious vendor can tell you exactly which systems ever see identified data and why.

Compliance done right is invisible in daily use and obvious under audit. Ask the verifiable questions and the marketing phrase becomes testable.