Skip to main content
DocumentMS

Compliance

HIPAA compliant document storage

HIPAA requires administrative, physical and technical safeguards over protected health information. In a document management system the technical ones are unique user identification, automatic logoff, encryption, audit controls that record every access, integrity checks, and transmission security — all evidenced under a business associate agreement.

What HIPAA requires of a document system

The Security Rule sets out administrative, physical and technical safeguards for electronic protected health information. Of these, the technical safeguards at 45 CFR §164.312 are the ones a document management system implements directly: unique user identification, automatic logoff, encryption and decryption, audit controls, integrity controls and person or entity authentication.

The requirement that most often disqualifies a general-purpose file store is audit controls. §164.312(b) requires mechanisms that record and examine activity in systems containing protected health information — activity, not merely modification. A system that logs edits but not reads cannot tell you who saw a record before it was disclosed, which is the first question asked in a breach investigation.

Unique user identification is the other common failure. Shared departmental logins are excluded outright, because a record of "the reception account" opening a file is not attributable to anyone.

Technical safeguards, mapped

What §164.312 asks for, and the product control that addresses it.
HIPAA Security Rule technical safeguards in DocumentMS
SafeguardRequirementControl
§164.312(a)(1) Access controlTechnical policies limiting access to authorised personsRole-based access per module, with preview-only distinct from preview-and-download
§164.312(a)(2)(i) Unique user identificationAssign a unique name or number for tracking user identityNamed accounts with OIDC single sign-on; no shared logins
§164.312(a)(2)(iii) Automatic logoffTerminate a session after a predetermined time of inactivityConfigurable session lifetime with refreshable tokens
§164.312(a)(2)(iv) Encryption and decryptionMechanism to encrypt and decrypt electronic PHI256-bit encryption at rest, TLS in transit; customer-managed keys on customer storage backends
§164.312(b) Audit controlsRecord and examine activity in systems containing PHIAppend-only audit trail recording views and downloads, not editable by any role
§164.312(c)(1) IntegrityProtect PHI from improper alteration or destructionVersion history with no overwrite, administrator-only recycle bin, content hashing
§164.312(d) Person or entity authenticationVerify that a person seeking access is who they claimTwo-factor authentication enforceable per role, plus OIDC single sign-on
§164.312(e)(1) Transmission securityGuard against unauthorised access to PHI in transitTLS for all transport; IP restrictions per user or role

What sits outside a document system

The administrative safeguards — risk analysis, workforce training, sanction policy, contingency planning, and the business associate agreements you hold with your own vendors — are organisational obligations that no product satisfies. Physical safeguards for your own facilities and workstations are likewise yours.

Retention is also more yours than ours. HIPAA itself requires six years for compliance documentation such as policies and risk analyses, but medical record retention is set by state law and varies substantially, with a longer clock for records of minors. A vendor page cannot tell you your period, and one that offers a single number is not being careful.

FAQ

HIPAA questions

Will you sign a business associate agreement?

Yes, on every tier, and we execute it before any protected health information is uploaded rather than after. A vendor that stores or transmits PHI for a covered entity is a business associate as a matter of law, so this is a threshold question rather than a negotiating point, and treating it as one would tell you something. Until a BAA is signed, the tenant is not configured for PHI and we will say so rather than let it be loaded quietly.

Does encryption mean a breach is not notifiable?

It can. HIPAA’s breach notification obligation applies to unsecured protected health information, and PHI encrypted to the standard in HHS guidance may fall outside that definition. It is a meaningful protection but not an absolute one — an encrypted store accessed through a compromised authorised account is not protected by the encryption at all.

How long must we keep medical records?

HIPAA sets six years for compliance documentation. Clinical record retention is set by state law, commonly six to ten years from last treatment, with extended periods for minors running from the age of majority. Verify per state — this is the retention question we see misconfigured most often in healthcare.

Can we restrict a document to preview only?

Yes, and it is a genuinely useful control for the minimum-necessary standard: a billing clerk confirming a procedure took place does not need a downloadable copy of the clinical narrative. It prevents download through the application; it cannot prevent a photograph of a screen, and we would not suggest otherwise.

Send the questionnaire. We will answer the BAA question first, because everything else depends on it.