Quick answer

Your practice management software vendor is a business associate, not your privacy officer. Their “HIPAA compliant” claim covers their product; the written risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), the policies, the training records, and the business associate agreements remain your practice’s legal obligations. The enforcement record shows both failure modes: practices fined for missing documents no software produces, and, in the 2026 MMG Fusion case, a dental software vendor whose breach exposed roughly 15 million records without the practices it served being told. Here is where the line actually sits, and what stays on your side of it.

Somewhere in almost every sales conversation with a small practice, the same sentence comes up: “our PMS is HIPAA compliant, so we’re covered.” It is said in good faith. It is also the single most expensive misunderstanding in small-practice compliance.

What does “HIPAA compliant software” actually mean?

When a practice management vendor says their product is HIPAA compliant, they are describing their side of the relationship: encrypted storage, access controls in the application, their data centers, their internal audits. That is real and it matters. A modern cloud PMS is genuinely safer than the unpatched server in your supply closet.

But notice what that claim is about. It is about the software. HIPAA regulates your practice, and the obligations it puts on a covered entity are mostly not software features. There is also no official government seal behind any of it: HHS has never created or endorsed a HIPAA certification for products or practices. The badge on the vendor’s website is marketing language for architecture you will never see.

The practical test: read the vendor’s own business associate agreement. It carefully describes what they protect, and every sentence quietly draws the boundary around everything they do not.

What stays on your side of the line?

The obligations OCR actually enforces against small practices are the ones no PMS can perform:

The risk analysis. 45 CFR 164.308(a)(1)(ii)(A) requires a written, accurate, organization-wide analysis of risks to patient data everywhere it lives, and your PHI does not live only in the PMS. It is on tablets, in email, at the lab, in the backup account, on paper. This is the document cited in roughly 90 percent of OCR’s Security Rule enforcement actions, and in OCR’s own audit program, 86 percent of covered entities failed it. OCR now runs a dedicated enforcement campaign on this one document, the Risk Analysis Initiative, which reached its twelfth action in 2026 and is expanding into risk management, where audit failure rates ran to 94 percent.

Policies, training, and the paper trail. Written policies under 45 CFR 164.530 that describe your office, not a template. Training that is documented by name and date, because undocumented training does not exist to an investigator. A records-request workflow with an owner and a clock: 30 days federal, and 15 business days for electronic records under Texas HB 300, which also carries state penalties up to $1.5 million per violation category per year, enforced by the Texas Attorney General.

The vendor file itself. Your PMS vendor is one of a dozen vendors touching patient data, and 45 CFR 164.502(e) requires a signed business associate agreement with every one of them before data flows. The price of skipping that paperwork with a single vendor is on the public record: Raleigh Orthopaedic paid $750,000 over X-ray films handed to a vendor on a phone agreement.

What happens when the vendor is the one that fails?

In March 2026, OCR settled with MMG Fusion, a software company serving dental practices. An intruder had been in its systems since December 2020, and the information of roughly 15 million people was exposed. OCR’s findings included a familiar list: no adequate risk analysis, impermissible disclosure, and a failure to notify the covered entities it served.

Sit with that last one. The practices whose patients were exposed were not told, and their duty to notify those patients under the Breach Notification Rule never moved. A vendor’s silence does not transfer your liability; it hides it from you. The settlement itself was $10,000, scaled to what remained of the company’s finances, with a three-year corrective action plan. Whatever that resolution did, it did not notify a single patient, repair a single practice’s reputation, or answer a single angry phone call at a front desk.

That is the asymmetry to understand: when your practice fails, you pay; when your vendor fails, you still pay. The practices fined under the Risk Analysis Initiative, like the small New York neurology practice that paid $25,000 after ransomware encrypted its network, were not fined for being attacked. They were fined because they could not produce the document showing they had ever looked for the weaknesses.

The honest division of labor

Software earns its subscription doing what software does: securing its own product, encrypting its own storage, patching its own code. Some platforms add useful checklists and training portals on top, and used honestly they help. The trouble starts when the subscription is mistaken for the program.

The division of labor that survives an investigation looks like this: the vendor secures the container, and the practice governs the data. You know where PHI lives, you have analyzed the risks in writing, your team is trained and it is documented, your vendor list matches your BAA file, and someone owns the records clock. None of that can be bought as a feature, and all of it is what OCR asks for first, against 2026 penalties that run to $2,190,294 per violation category under Federal Register 2026-01688.

What to do next

Three moves, in order. First, count your vendors and count your signed BAAs; the gap between those numbers is your fastest fix. Second, ask when your risk analysis was last updated, and if the honest answer involves a software questionnaire or a year that starts with 202-something-early, treat it as missing. Third, close the center gap: our flat-fee HIPAA Risk Analysis ($3,500 to $4,500, three weeks) is the document the whole program stands on, the $750 Privacy Exposure Review finds your top three gaps in 48 hours, and if you are still comparing options, eight questions to ask any HIPAA consultant will screen anyone you talk to, including us. You can also run the free 60-second privacy check right now and see three of your risk signals before you talk to anyone.

Your PMS vendor is a fine business associate. Just remember which name is on the OCR letter.

Last Updated: July 20, 2026