Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

HIPAA compliance software for clinical research units and academic medical centres

Which HIPAA compliance software genuinely automates evidence, policy and training for a research unit — and what the Security Rule still leaves to you.

Ask about HIPAA compliance software for clinical research units and academic medical centres

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

The layer you can price today · Verified 18 August 2026

Sign.Plus — the BAA-covered signature layer every one of these platforms assumes you already have

Free tier (3 requests). Enterprise $49.99/mo is the only tier with HIPAA cover and a BAA

Be clear about what this pick is and is not. The platform you are about to google is Vanta, and for a research unit that needs SOC 2 or ISO 27001 alongside HIPAA it is a defensible shortlist entry — we have no commercial relationship with it and print no price for it, because it does not publish one we can verify. But every GRC platform in this category, Vanta included, monitors evidence that something else produces. Policy attestations, workforce training acknowledgements, the signed BAAs themselves, delegation-of-authority logs and consent documentation all have to be executed somewhere, under a signature your auditor and your privacy officer will accept, inside a service that will sign a BAA with you. Sign.Plus does that with a published price, which is rarer in this category than it should be: Free covers 3 signature requests, Personal is $9.99/mo for 10 a month, Professional $19.99/mo for unlimited requests, Business $29.99/mo, and Enterprise $49.99/mo is the only tier carrying HIPAA cover and a BAA. Audit trails and eIDAS-grade records are on every tier including the free one, so you can test the workflow with non-PHI policy attestations this week and only pay when PHI or a BAA enters the picture. Verified 19 August 2026.

Start free with Sign.Plus Opens on the vendor’s site · CASRAI referral link

Build the BAA register before you buy any platform → — If you cannot list every vendor touching PHI, a compliance dashboard will simply display that gap in a nicer font.

Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.

In summary

  • No software makes an organisation HIPAA compliant. The §164.308 risk analysis, the BAA chain and breach notification remain the covered entity’s work, and any page implying otherwise is selling.
  • What these platforms genuinely automate: policy versioning and attestation, workforce training tracking, continuous monitoring of a defined technical control set, vendor registers, and evidence collection you can export.
  • Split the market in two: platforms where HIPAA is a mapping layer over a SOC 2 engine (Vanta, Drata) and platforms built HIPAA-first for covered entities (Compliancy Group, Accountable HQ). Which is right depends on whether anyone is also demanding SOC 2.
  • Ask every vendor one question before the demo: will you sign a BAA for your own service? A compliance platform that stores your PHI-adjacent evidence and will not sign one is disqualified by its own product category.
  • Sign.Plus is our pick for the BAA-covered signature layer these platforms assume you have: Free 3 requests, Personal $9.99/mo, Professional $19.99/mo, Business $29.99/mo, Enterprise $49.99/mo (the only tier with HIPAA and a BAA). Verified 19 August 2026.

Where the four platforms you are about to google actually sit

Positioning as we understand it on 19 August 2026. No prices appear in this table: none of these vendors publishes a figure we can read off a pricing page, and CASRAI does not print prices it has not verified. Confirm every BAA in writing.

Dimension HIPAA: mapped or native? What the product really is Best fit in a research setting What it still leaves you
Vanta Mapped — a HIPAA framework over a multi-framework engine Continuous control monitoring with deep integrations into identity, cloud and endpoint tooling, plus policy and training modules A spinout or data coordinating centre that must satisfy SOC 2 or ISO 27001 for a sponsor and HIPAA for a health system, from one control set The risk analysis, the BAA chain, and any control that lives on institutional IT you do not administer
Drata Mapped — same multi-framework model, different emphasis Continuous monitoring with strong evidence automation and audit-partner workflows Teams already heading into an audit cycle who want the auditor working inside the same system Same as above, plus a configuration burden if your estate includes unmanaged instrument PCs
Compliancy Group Native — built for covered entities and business associates A guided HIPAA programme: risk assessment workflow, policies, training, incident and BAA tracking, with human coaching alongside the software A clinical unit or practice-scale organisation with no security team and no SOC 2 requirement Little help if a sponsor also demands SOC 2; guidance is not the same as an independent risk analysis
Accountable HQ Native — HIPAA-first, lighter touch Risk assessment, policy distribution, training and vendor/BAA management aimed at smaller organisations A small research unit or a business associate that needs a defensible programme and a vendor register, fast Thinner technical control monitoring than the SOC 2-derived platforms
Your institution’s existing GRC tooling Varies — often an internal control library rather than a framework Whatever the health system or university information governance office already runs Almost always the first thing to check, and frequently free at point of use to your unit May not cover systems your unit administers itself, which is exactly where the gaps are
A spreadsheet and a shared drive Not a framework, but not automatically inadequate Manual evidence collection, manual attestation chasing, manual version control A unit under about fifteen people with one disciplined owner and no audit deadline Breaks at the first staff turnover, and produces evidence auditors distrust because nothing is dated at source

The split that matters is the first column. If nobody has asked you for SOC 2, a HIPAA-native platform will fit your workflow better and ask fewer questions you cannot answer. If a sponsor has asked for both, buying two systems is worse than buying one that maps.

The three things the platform will ask you to prove — and what to buy for them

Every platform in the table above generates a task list, and three items on it recur in every clinical research deployment we have looked at: signed attestations and consent, PHI in transit to organisations that still run fax lines, and demonstrable endpoint protection. These are the pieces you buy separately, and unlike the platforms they have prices we can print.

#1 Sign.Plus — our winner

The signature and attestation layer, with a BAA available and prices you can actually read before a sales call.

Best for: Policy attestations, training acknowledgements, executed BAAs, delegation logs and consent documentation

Price: From $9.99/mo · unlimited requests at $19.99/mo

A compliance platform tracks whether your workforce has attested to the sanction policy and whether every business associate has a countersigned agreement on file. It does not execute either. Sign.Plus is the tool that does, and it does the boring part properly: an audit trail and eIDAS-grade records on every tier, including the free one, so a signature you collected in a pilot is still defensible a year later. The tier that matters for PHI is Enterprise at $49.99/mo — the only one carrying HIPAA cover and a BAA. Below that, Free gives you 3 signature requests, Personal is $9.99/mo for 10 a month, Professional $19.99/mo for unlimited requests and Business $29.99/mo. Verified 19 August 2026. The sensible sequence for a research unit is to run non-PHI internal attestations on a lower tier while you write the policies, then move to Enterprise before the first document containing participant information is routed.

Strengths

  • Audit trails on every tier including free, so pilot evidence is not thrown away
  • HIPAA cover and a BAA at a published $49.99/mo rather than a quote
  • Free tier lets you test the attestation workflow with no card and no PHI

Trade-offs

  • HIPAA is Enterprise-only — the cheaper tiers are for non-PHI work
  • It is a signature tool, not a policy management system; the platform still owns versioning

Try Sign.Plus free CASRAI referral link — disclosed on this page

#2 Fax.Plus

The unglamorous control: PHI still moves by fax to hospitals, laboratories and payers, and the free tier is not covered.

Best for: Study teams exchanging records with sites, referring clinicians and central laboratories

Price: From $6.99/mo — HIPAA/BAA on Enterprise ($79.99/mo)

Every HIPAA programme review turns up at least one fax route nobody documented. Fax.Plus is the tool we point research units at, with one caveat that decides the whole purchase: only Enterprise at $79.99/mo for 4,000 pages carries HIPAA and a BAA. The lower tiers — Free at 10 pages, Basic $6.99/mo for 200 pages, Premium $13.99/mo for 500 and Business $27.99/mo for 1,000 — are not for PHI, whatever your coordinator is currently doing with them. Annual billing runs about 22% off. Verified 19 August 2026. Our <a href=”/software/hipaa-compliant-fax-service/”>HIPAA-compliant fax service guide</a> covers the configuration mistakes that void the protection.

Strengths

  • Removes the physical machine in a shared corridor, which is a genuine privacy exposure
  • Published pricing across all tiers, so the HIPAA step-up is visible before you commit

Trade-offs

  • The HIPAA tier is a substantial step up from the plans people typically start on
  • Volume-capped: a high-throughput site may find 4,000 pages tight

Try Fax.Plus free CASRAI referral link — disclosed on this page

#3 Bitdefender GravityZone

The technical safeguard the monitoring dashboard checks for but never supplies.

Best for: Units with their own managed laptops, analysis workstations or instrument PCs outside central IT

Price: Per-device annual licensing — see current offer

Continuous control monitoring works by asking your endpoint console whether protection is present and current on every device, then flagging drift. If your unit administers machines that central IT does not, there is nothing for it to ask. Bitdefender GravityZone is our standing recommendation for that gap because one console produces exportable, dated reports rather than screenshots assembled the week before an assessment, and it scales down to a thirty-machine unit. It has no public list price — it is quoted at checkout by endpoint count, so treat any figure you see elsewhere as a guess. It is a consistent top performer in independent AV-Comparatives and AV-TEST business endpoint testing. Start with our <a href=”/software/best-endpoint-security-small-business/”>endpoint security guide</a> if you are sizing this for the first time.

Strengths

  • Produces the exportable evidence continuous monitoring actually consumes
  • Independently tested rather than self-certified

Trade-offs

  • No published price — you cannot budget it without a quote
  • Instrument PCs on vendor-locked builds will still need segregation and documented risk acceptance

See GravityZone pricing CASRAI referral link — disclosed on this page

What HIPAA compliance software genuinely automates

Strip the marketing away and this category does four things well. Understanding which four is the difference between a subscription that saves a research coordinator a day a week and one that becomes a second place to file the same documents.

Policy management and attestation. A library of HIPAA policies you can edit, version, publish, and push to named individuals for acknowledgement — with a record of who attested to which version on which date. This is the single most valuable module for an academic unit, because policy drift is endemic where staff are appointed on grant cycles and the last full review was written by someone who left in 2023. The platform holds the canonical version and chases the signatures.

Workforce training tracking. HIPAA requires training for members of the workforce, and the awkward part in a research setting is not delivering it but proving completion for a population that includes postdocs, rotating students, honorary contract holders and visiting researchers. Platforms handle enrolment, reminders and completion records. Most ship generic HIPAA awareness content; some accept your institutional module instead, which is what you want if your health system already mandates one. Our note on security awareness training for staff covers how to avoid buying the same training twice.

Continuous control monitoring. The genuinely automated part. The platform connects to your identity provider, cloud tenancies, endpoint console and device management, then checks defined conditions on a schedule: is multi-factor authentication enforced, is disk encryption on for every enrolled laptop, was this leaver disabled within the window your policy claims, has anyone been granted administrative rights without an approval record. When something drifts, you get an alert rather than a discovery during an assessment. The value here is real, and it is directly proportional to how many of your systems the platform can actually reach.

Vendor and evidence registers. A structured list of business associates with the status and expiry of each agreement, plus a repository where every artefact is dated at source and exportable. When a sponsor or a health system security review asks for evidence, you produce a package instead of a fortnight of archaeology.

Four capabilities, all administrative. Notice what is absent: none of them is a safeguard. The platform does not encrypt anything, protect an endpoint or restrict access to a record. It observes the systems that do.

Three things that stay yours, whichever platform you buy

The Security Rule risk analysis. The requirement at §164.308(a)(1)(ii)(A) is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic PHI your organisation holds. Every platform in this category offers a risk assessment workflow. Every one of them is a questionnaire, and a questionnaire is not an analysis. It cannot know that your imaging workstation writes an unencrypted cache to a local drive, that a laboratory information system exports to a shared folder nobody owns, or that a study team keeps a re-identification key in a spreadsheet because the sponsor portal will not accept the format. Those are the findings that matter, and they come from someone walking the data flows with the people who operate them. Use the tool to structure and document the analysis. Do not let it replace the walk.

The BAA chain. A vendor register is a list. Someone still has to identify every organisation that creates, receives, maintains or transmits PHI on your behalf, obtain a signed agreement from each, read the terms rather than filing them, and re-check when a subcontractor changes. Research estates are unusually bad at this because tools arrive through grants, departmental cards and pilot projects rather than procurement. Our guide to business associate agreements in research sets out how to build the register before you automate tracking it — the order matters, because a dashboard reflecting an incomplete list is worse than no dashboard at all.

Breach notification. When something goes wrong, a human performs the four-factor risk assessment, decides whether the presumption of breach is rebutted, and notifies within the statutory windows. Software holds your incident log and reminds you of a deadline; it cannot make that judgement, and no vendor claims it can once you read past the homepage.

Do not buy a HIPAA compliance platform if you are buying it to be able to tell a sponsor or an IRB that you are compliant. There is no certification behind that word — HIPAA has no accredited certificate, and a vendor badge saying otherwise carries no regulatory weight. If your genuine problem is that you cannot list your vendors, cannot find your policies and have never done a risk analysis, spend the first quarter doing those three things on paper. Then buy the platform to keep them current, which is the job it is actually good at.

HIPAA as a checkbox versus a real HIPAA control set

Roughly half the products sold as HIPAA compliance software were built as SOC 2 automation platforms and later grew a HIPAA framework. That is not a criticism — it is an architecture, and it suits some buyers precisely. But it has consequences you should be able to spot in a demo.

A mapped HIPAA framework takes an existing control library and cross-references it to the Administrative, Physical and Technical Safeguards. What you get is excellent technical monitoring, strong integration coverage, and a control set whose centre of gravity is a cloud-native software company: access reviews, code deployment, infrastructure configuration. What you may not get is depth on the parts of HIPAA with no SOC 2 analogue — minimum necessary determinations, the workforce sanction policy, accounting of disclosures, patient rights of access, physical safeguards for a records room. If a demo cannot show those without switching to a text field labelled “custom control”, you are looking at a mapping rather than a control set.

A HIPAA-native platform inverts that. Compliancy Group and Accountable HQ are structured around the Rules themselves: they will walk a covered entity through the required and addressable implementation specifications, chase BAAs as a first-class object, and generally assume the buyer has no security engineer. The trade is thinner technical monitoring — fewer integrations, less continuous checking, more assertion. For a clinical research unit whose infrastructure is largely operated by a hospital or university, that trade is often correct, because most of the technical controls a mapped platform wants to monitor are not yours to monitor anyway.

Then ask the disqualifying question, in writing, before the second call: will you sign a BAA for your own service? A compliance platform holds incident records, risk analyses naming systems and, if anyone uploads carelessly, documents containing PHI. Vendors serving covered entities generally will sign, sometimes on a specific tier. Vendors whose HIPAA offering is a reporting template sometimes will not, and that answer tells you which of the two categories above you are in faster than any feature comparison. The same question is the one that decides your point tools, which is why our HIPAA-compliant form builders comparison is organised entirely around it.

Why a clinical research unit is a harder buyer than a health-tech startup

Almost every review of this category assumes the buyer is a digital health startup: it owns its whole stack, its people are permanent, and one team can turn on every integration in an afternoon. A clinical research unit inside an academic medical centre differs in four ways that change the purchase.

You do not administer most of your controls. Identity, network, backup and often endpoint management belong to the health system or the university. A continuous monitoring platform is only as valuable as the systems it can connect to, and if central IT will not issue you API credentials for the identity provider, half the automation you are paying for produces nothing. Establish this before you sign, not during onboarding. The corollary is more cheerful: institutional controls may already be evidenced by your information governance office, and your unit-level programme only has to cover the gap.

Your workforce churns on grant cycles. Postdocs, PhD students, research nurses on fixed-term contracts, honorary appointments and site staff at partner organisations rotate constantly. Training completion and access reviews are therefore the two controls most likely to show an exception, and the automation that chases them is the module you will get the most from. Check that the platform can handle people who are in your workforce for HIPAA purposes but are not in your HR system — a surprising number cannot.

HIPAA is not your only regime. The Common Rule, IRB determinations, sponsor contracts, data use agreements and, for anything touching Europe, the GDPR all overlap the same data. A HIPAA-only dashboard showing green tells you nothing about whether your limited data set is covered by an executed DUA. Treat the platform as one register among several and keep the IRB relationship human.

Your funding is lumpy. Multi-year subscriptions sit badly against grant accounting and post-award cost rules, so speak to research finance before signing anything annual and check whether the cost can be recovered or charged to the study that triggered the requirement. If a sponsor also demands SOC 2, our breakdown of what SOC 2 actually costs a research group is the companion budget exercise.

A fortnight’s sequence that stops you buying the wrong thing

  1. Find out what your institution already runs. Information governance may hold a licence, a policy library and a mandated training module that covers your unit at no cost. Buying a second one is the most common wasted spend in this category.
  2. List every system and vendor touching PHI. One page, no tooling. Include the fax line, the survey tool, the transcription service, the cloud storage a student set up, and the e-signature account nobody remembers opening.
  3. Ask each vendor on that list for a BAA and record which tier it requires. Two of ours make this explicit and cheap to check: HIPAA-compliant e-signature and HIPAA-compliant fax.
  4. Establish who administers your technical controls. If central IT will not give you integration credentials, discount every continuous monitoring feature in the demos accordingly.
  5. Decide whether anyone is demanding SOC 2 or ISO 27001. Yes points to a mapped platform. No points to a HIPAA-native one. This single answer eliminates half your shortlist.
  6. Book demos and ask each vendor to show the risk analysis workflow and the BAA object — not the dashboard. Then ask, in writing, whether they will sign a BAA for their own service.
  7. Buy the point tools you already know you need, since they have published prices and free tiers and do not need a procurement cycle. The platform can wait a quarter; a fax machine in a shared corridor cannot.

Run in that order, the purchase gets smaller and better specified as you go. Run in reverse — platform first, register last — and you will spend a year discovering that the dashboard was accurate about the systems you told it about.

Test the attestation workflow this week, without spending anything

Whichever platform you shortlist, it will ask you to produce signed policy attestations, training acknowledgements and executed BAAs. Sign.Plus gives you audit trails on every tier including the free one, so you can run internal, non-PHI attestations now and move to the Enterprise tier at $49.99/mo — the only tier with HIPAA cover and a BAA — before any participant information is routed. Verified 19 August 2026.

From $9.99/mo · unlimited requests at $19.99/mo

Start free with Sign.Plus Opens on the vendor’s site · CASRAI referral link

Frequently asked questions

Does HIPAA compliance software actually make us HIPAA compliant?

No, and any vendor implying otherwise should drop off your shortlist. HIPAA has no accredited certification. Software can hold your policies, chase attestations, monitor a defined technical control set and store dated evidence — all genuinely useful. It cannot perform the Security Rule risk analysis, cannot obtain your business associate agreements, and cannot make the breach notification judgement. Those three obligations sit with the covered entity permanently.

Is HIPAA compliance software worth it for a small clinical research unit?

It depends almost entirely on two things: whether your institution already provides equivalent tooling, and how many technical systems you administer yourself. A unit of ten people whose identity, endpoints and backups are all run by the hospital gets limited value from continuous control monitoring, because there is little for it to monitor — but may still get real value from policy versioning and training tracking. A unit that runs its own cloud tenancy and its own laptops gets substantially more. Check what information governance already licenses before you budget anything.

Vanta, Drata, Compliancy Group or Accountable HQ — which should we shortlist?

Answer one question first: has anyone asked you for SOC 2 or ISO 27001 as well as HIPAA? If yes, a multi-framework platform such as Vanta or Drata lets one control set serve both, and buying two systems would be worse. If no, a HIPAA-native platform such as Compliancy Group or Accountable HQ will match how the Rules are actually structured and will assume less security expertise on your side. We publish no prices for any of them because none publishes a figure we can read off a pricing page, and CASRAI only prints prices it has verified.

Why will you not quote annual price bands for these platforms?

Because every band we could find traces back to either a vendor sales page that no longer shows it or a guess repeated across affiliate sites, and a number invented here would become the figure someone is held to. Ask each vendor for a written quote against your headcount and integration list instead: about a week, and defensible.

What is a HIPAA risk assessment tool actually doing?

Structuring and documenting an analysis you perform. It presents the required and addressable implementation specifications, records your answers, tracks remediation tasks and produces a dated report. That is worth having, because the documentation requirement is real and few units meet it unaided. What it does not do is discover the risks — those come from walking the data flows with the people who operate them, which routinely surfaces exposures no questionnaire asks about, such as an unencrypted local cache on an imaging workstation or a re-identification key living in a spreadsheet.

Will these platforms sign a BAA for their own service?

Ask in writing, per tier, before the second sales call. Vendors serving covered entities generally will, sometimes only on a specific plan; vendors whose HIPAA offering is essentially a reporting template sometimes will not. The answer is diagnostic — it tells you which half of the market you are talking to. Apply the same test to every tool in your estate: with e-signature the BAA is typically gated behind the top tier, which is why Sign.Plus Enterprise at $49.99/mo is our pick and why its free tier is useful for testing the workflow on non-PHI documents first. Verified 19 August 2026.

Can we do this with a spreadsheet instead?

For a while, yes — for a unit under about fifteen people with one disciplined owner and no audit deadline, it is often the right call for the first year. It breaks at the first staff turnover, and evidence assembled retrospectively is evidence an assessor distrusts. The signal that you have outgrown it is chasing training completions by email, or finding an expired BAA after the fact.

Related on CASRAI

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →