Compliance
HIPAA compliant document storage
HIPAA requires administrative, physical and technical safeguards over protected health information. In a document management system the technical ones are unique user identification, automatic logoff, encryption, audit controls that record every access, integrity checks, and transmission security — all evidenced under a business associate agreement.
What HIPAA requires of a document system
The Security Rule sets out administrative, physical and technical safeguards for electronic protected health information. Of these, the technical safeguards at 45 CFR §164.312 are the ones a document management system implements directly: unique user identification, automatic logoff, encryption and decryption, audit controls, integrity controls and person or entity authentication.
The requirement that most often disqualifies a general-purpose file store is audit controls. §164.312(b) requires mechanisms that record and examine activity in systems containing protected health information — activity, not merely modification. A system that logs edits but not reads cannot tell you who saw a record before it was disclosed, which is the first question asked in a breach investigation.
Unique user identification is the other common failure. Shared departmental logins are excluded outright, because a record of "the reception account" opening a file is not attributable to anyone.
Technical safeguards, mapped
| Safeguard | Requirement | Control |
|---|---|---|
| §164.312(a)(1) Access control | Technical policies limiting access to authorised persons | Role-based access per module, with preview-only distinct from preview-and-download |
| §164.312(a)(2)(i) Unique user identification | Assign a unique name or number for tracking user identity | Named accounts with OIDC single sign-on; no shared logins |
| §164.312(a)(2)(iii) Automatic logoff | Terminate a session after a predetermined time of inactivity | Configurable session lifetime with refreshable tokens |
| §164.312(a)(2)(iv) Encryption and decryption | Mechanism to encrypt and decrypt electronic PHI | 256-bit encryption at rest, TLS in transit; customer-managed keys on customer storage backends |
| §164.312(b) Audit controls | Record and examine activity in systems containing PHI | Append-only audit trail recording views and downloads, not editable by any role |
| §164.312(c)(1) Integrity | Protect PHI from improper alteration or destruction | Version history with no overwrite, administrator-only recycle bin, content hashing |
| §164.312(d) Person or entity authentication | Verify that a person seeking access is who they claim | Two-factor authentication enforceable per role, plus OIDC single sign-on |
| §164.312(e)(1) Transmission security | Guard against unauthorised access to PHI in transit | TLS for all transport; IP restrictions per user or role |
What sits outside a document system
The administrative safeguards — risk analysis, workforce training, sanction policy, contingency planning, and the business associate agreements you hold with your own vendors — are organisational obligations that no product satisfies. Physical safeguards for your own facilities and workstations are likewise yours.
Retention is also more yours than ours. HIPAA itself requires six years for compliance documentation such as policies and risk analyses, but medical record retention is set by state law and varies substantially, with a longer clock for records of minors. A vendor page cannot tell you your period, and one that offers a single number is not being careful.
FAQ
HIPAA questions
Will you sign a business associate agreement?
Yes, on every tier, and we execute it before any protected health information is uploaded rather than after. A vendor that stores or transmits PHI for a covered entity is a business associate as a matter of law, so this is a threshold question rather than a negotiating point, and treating it as one would tell you something. Until a BAA is signed, the tenant is not configured for PHI and we will say so rather than let it be loaded quietly.
Does encryption mean a breach is not notifiable?
It can. HIPAA’s breach notification obligation applies to unsecured protected health information, and PHI encrypted to the standard in HHS guidance may fall outside that definition. It is a meaningful protection but not an absolute one — an encrypted store accessed through a compromised authorised account is not protected by the encryption at all.
How long must we keep medical records?
HIPAA sets six years for compliance documentation. Clinical record retention is set by state law, commonly six to ten years from last treatment, with extended periods for minors running from the age of majority. Verify per state — this is the retention question we see misconfigured most often in healthcare.
Can we restrict a document to preview only?
Yes, and it is a genuinely useful control for the minimum-necessary standard: a billing clerk confirming a procedure took place does not need a downloadable copy of the clinical narrative. It prevents download through the application; it cannot prevent a photograph of a screen, and we would not suggest otherwise.
Última revisão: 2026-09-01