Is your software HIPAA compliant?

Most HIPAA exposure in a small practice does not come from the EHR. It comes from the everyday tools around it: the email suite, the scheduler, the e-signature app, the CRM. A tool is only safe for Protected Health Information if the vendor signs a Business Associate Agreement and you configure it correctly. Below is a plain-English verdict for each tool, with the source and the setup steps. Cobrix configures and documents these for California healthcare, legal, and accounting practices.

Healthcare practices
Conditional

Is athenahealth HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

No

Is Calendly HIPAA compliant?

No. The vendor will not sign a BAA, so PHI does not belong here.

Conditional

Is Docusign HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Conditional

Is Dropbox HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Conditional

Is Google Workspace HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Conditional

Is HubSpot HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Yes, with BAA

Is Microsoft 365 HIPAA compliant?

Yes. The BAA is extended by default. The work is configuring it right.

Yes, with BAA

Is Microsoft Teams HIPAA compliant?

Yes. The BAA is extended by default. The work is configuring it right.

Conditional

Is Slack HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Conditional

Is Zoom HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Law firms
Conditional

Is Clio HIPAA compliant?

Yes, but only after a BAA and the right plan or add-on is in place.

Accounting firms
No

Is QuickBooks Online HIPAA compliant?

No. The vendor will not sign a BAA, so PHI does not belong here.