HIPAA-aligned tools for solo and small-team advocates
What 'HIPAA-aligned' actually means, why consumer apps fall short, and the safeguards every independent advocate should expect from their software stack.
"HIPAA-compliant" is one of the most misused phrases in healthcare software. Vendors slap it on landing pages, advocates inherit it as an assumption, and almost no one stops to ask what it actually means for the tools they use every day. If you're a solo or small-team advocate, the gap between "we take security seriously" and "this software is genuinely safe to put protected health information into" matters a great deal.
What HIPAA actually requires
HIPAA's Security Rule defines three categories of safeguards: administrative, physical, and technical. Administrative covers policies and training. Physical covers the data centers your information lives in. Technical covers encryption, access controls, audit logs, and the architecture of the software itself. A tool is only meaningfully aligned with HIPAA if all three are addressed - not just one.
Why most consumer apps fall short
Free messaging apps, generic note tools, and consumer cloud storage are designed for a different threat model. They're built for convenience, not for handling protected health information. Even when they offer encryption, they typically don't provide the access controls, audit trails, or business associate agreements that HIPAA expects when you're handling client information professionally.
The safeguards every advocate should expect
- Encryption in transit and at rest. Every byte of client data should be encrypted both while moving and while sitting on disk.
- Access controls per user. No shared logins. No "team password." Every person with access should have their own account with appropriate permissions.
- Audit logs. You should be able to answer the question "who looked at this client's record, and when?"
- A clear data agreement. The vendor should be willing to sign an appropriate agreement that defines who is responsible for what.
- US-based data handling and a real company behind the product. Anonymity and offshore-only operations are a red flag.
The practical test
Ask any vendor: "Where does my client data live, who has access to it, and what happens if I close my account?" If you can't get a clear answer in plain English, that's your answer. The software you use is part of your professional standard of care - treat it that way.
