glossgenius.com
Every answer that reached for this page while answering Catalytics Automation's prompts. back to glossgenius.com
Answers it shaped
12
12 citations
Prompts
7
Avg. sloti
37.3
You namedi
0/12
Impact
1.7%
Answers (12)i
ChatGPT (Web)AbsentIs Knack HIPAA compliant?slot 14Aug 21, 01:59 PM
Yes — **Knack can be used in a HIPAA-compliant environment**, but there’s an important distinction: **a normal Knack account is not automatically HIPAA compliant.**
According to Knack's current documentation:
- **HIPAA plans are available** specifically for organizations handling PHI. [docs.knack.com](https://docs.knack.com/v3/docs/knack-health-hipaa-plans?utm_source=chatgpt.com)
- Knack provides a **Business Associate Agreement (BAA)** with its HIPAA plans. A signed BAA is required before storing PHI. [docs.knack.com](https://docs.knack.com/docs/business-associate-agreements?utm_source=chatgpt.com)[www.knack.com](https://www.knack.com/terms-of-service/?utm_source=chatgpt.com)
- HIPAA plans include controls such as **encryption in transit and at rest, role-based access, audit/change logs, 2FA, inactivity timeouts, backups, and monitoring**. [www.knack.com](https://www.knack.com/health/hipaa/?utm_source=chatgpt.com)
- Knack explicitly says that **your application and workflows still have to be configured and operated appropriately**; using Knack doesn't by itself make your organization HIPAA compliant. [www.knack.com](https://www.knack.com/health/how-hipaa-compliance-works/?utm_source=chatgpt.com)
- Knack's Terms of Service state that PHI may only be used with Knack when you're in a **HIPAA Environment and have the HIPAA Customer Addendum and BAA in place**. [www.knack.com](https://www.knack.com/terms-of-service/?utm_source=chatgpt.com)
- Third-party integrations are a particular concern: if PHI leaves Knack through an integration/API, **that third party needs to be appropriately HIPAA compliant and have a BAA with you where required**. [docs.knack.com](https://docs.knack.com/docs/business-associate-agreements?utm_source=chatgpt.com)[www.knack.com](https://www.knack.com/terms-of-service/?utm_source=chatgpt.com)
### Bottom line
If you're considering Knack for something like a **patient database, intake system, case-management app, or patient portal**, I'd consider it **HIPAA-eligible**, provided you purchase the appropriate HIPAA plan, execute the BAA, and configure the application correctly.
If you tell me **what you're planning to store in Knack and what integrations you're using**, I can also assess the setup for the major HIPAA risk points (PHI, access controls, audit logs, email/SMS, Zapier/Make, AI, file uploads, etc.).
ChatGPT (Web)AbsentIs ChatGPT HIPAA compliant?slot 2Aug 21, 01:56 PM
**Not all ChatGPT use is HIPAA compliant.** As of August 2026, OpenAI offers specific ChatGPT products and configurations that are **HIPAA-eligible**, but HIPAA compliance depends on the product, your configuration, and having the appropriate **Business Associate Agreement (BAA)** with OpenAI. [help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)[cdn.openai.com](https://cdn.openai.com/osa/hipaa-guide.pdf?utm_source=chatgpt.com)
### If you're handling PHI
OpenAI currently lists these as HIPAA-eligible with a BAA:
- **ChatGPT for Healthcare**
- **ChatGPT for Clinicians**
- **ChatGPT Enterprise with Regulated Workspace**
- Certain **OpenAI API** configurations with Modified Retention
- Certain FedRAMP offerings [help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)
OpenAI specifically says that **without a BAA, you may not use its services to process Protected Health Information (PHI)** under its HIPAA implementation guide. [help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)[cdn.openai.com](https://cdn.openai.com/osa/hipaa-guide.pdf?utm_source=chatgpt.com)
### What about regular ChatGPT?
If you're using an ordinary **personal Free, Plus, or Pro ChatGPT account**, you should **not enter patient PHI into it for a HIPAA-regulated workflow**. The newer **Health in ChatGPT** feature also explicitly says it is *not* HIPAA-eligible and does not offer a BAA. [help.openai.com](https://help.openai.com/en/articles/20001036-what-is-chatgpt-health%20?utm_source=chatgpt.com)
For an organization that needs to process PHI, the safest path is to use an eligible offering and execute the appropriate BAA with OpenAI. OpenAI says Enterprise/Edu customers with sales-managed accounts can be eligible for a ChatGPT BAA, while its healthcare offerings have dedicated HIPAA support. [help.openai.com](https://help.openai.com/en/articles/8660679-how-can-i-get-a-business-associate?utm_source=chatgpt.com)
If you tell me **which ChatGPT plan/product you're using (e.g., Plus, Business, Enterprise, Healthcare, or API)** and what you want to do with patient information, I can tell you whether that particular setup is appropriate for HIPAA.
ChatGPT (Web)AbsentCan I use a no-code front end with a HIPAA compliant backend?slot 18Aug 21, 01:00 PM
Yes. **A no-code front end can work with a HIPAA-compliant backend**, but the key issue is not whether the front end is “no-code.” It’s **where PHI/ePHI flows and which vendors can access it**.
For example:
**No-code UI → secure API → HIPAA-capable backend/database**
That architecture can be perfectly reasonable. HHS explicitly allows cloud services to store or process ePHI when the appropriate safeguards are in place and a **Business Associate Agreement (BAA)** is executed with the cloud provider handling the ePHI. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### The important catch
If your no-code front end itself:
- receives patient names, diagnoses, medications, records, etc.
- stores that information
- sends it to analytics/AI services
- logs it
- exposes it to the no-code platform's support/admin systems
then **the no-code platform may itself be a business associate** and you'll generally need an appropriate BAA and HIPAA-capable configuration.
You can't simply make the backend HIPAA-compliant and assume the rest of the stack is covered. HHS notes that a cloud provider can be a business associate even when it only maintains **encrypted** ePHI and cannot decrypt it. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### A safer pattern
I'd generally design it like this:
```text
┌─────────────────────┐
│ No-code frontend │
│ │
│ UI / forms / views │
└──────────┬──────────┘
│
Authenticated API
│
▼
┌─────────────────────┐
│ HIPAA-capable API │
│ / application layer │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ HIPAA-capable DB │
│ + ePHI │
└─────────────────────┘
```
Ideally, the no-code layer contains **as little PHI as possible**, while the backend controls authorization, audit logging, data access, encryption, and business logic.
Also remember that **HIPAA compliance isn't a property you can simply buy from a vendor**. Your organization still has risk-analysis and other HIPAA responsibilities, while vendors handling ePHI may have their own obligations. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
If you tell me **which no-code frontend** you're considering (Bubble, FlutterFlow, WeWeb, Retool, Softr, Glide, Webflow, etc.) and **which backend** (Supabase, Firebase, AWS, Azure, custom API, etc.), I can tell you whether that specific combination is viable for HIPAA and what I'd change.
ChatGPT (Web)AbsentIs Softr HIPAA compliant?slot 14Aug 20, 02:34 PM
The short answer is: **not by default, and you should verify carefully before using it for PHI.**
Softr markets features for healthcare applications (such as patient portals) and states that it provides security features like encryption, role-based permissions, and SOC 2 Type II compliance. However, **SOC 2 compliance is not the same as HIPAA compliance**. [www.softr.io](https://www.softr.io/blog/soc2-certification?utm_source=chatgpt.com)
If you need to build an application that stores or processes **protected health information (PHI)**, you should confirm all of the following before using Softr:
- **Business Associate Agreement (BAA):** A HIPAA-compliant cloud service handling PHI must be willing to sign a BAA with you. This is a core HIPAA requirement. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
- **HIPAA-specific safeguards:** Encryption, access controls, audit logging, breach notification procedures, and administrative controls must all be in place—not just secure infrastructure. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
- **Your data source:** If you're connecting Softr to Airtable, Google Sheets, SQL, or another backend, **every service that stores or transmits PHI must also be HIPAA-eligible and covered by a BAA**. A compliant frontend does not make a non-compliant backend compliant. [www.softr.io](https://www.softr.io/blog/soc2-certification?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)[www.softr.io](https://www.softr.io/create/patient-portal?utm_source=chatgpt.com)
One nuance is that Softr's healthcare marketing pages now refer to "HIPAA-conscious" permissions and even mention "HIPAA-compliant authentication" for certain healthcare templates. These are marketing claims rather than a blanket statement that **the entire platform is HIPAA compliant for all customers and plans**. [www.softr.io](https://www.softr.io/blog/soc2-certification?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)[www.softr.io](https://www.softr.io/create/patient-portal?utm_source=chatgpt.com)
**My recommendation:** If you're planning to handle real patient data, ask Softr these questions before proceeding:
1. Will you sign a **Business Associate Agreement (BAA)**?
2. Which plans include HIPAA support?
3. Which components of the platform are covered by the BAA?
4. What subprocessors are involved, and are they also HIPAA-compliant?
5. What audit logging, access controls, and retention features are available?
If Softr **will not sign a BAA** for your intended use, you should assume it is **not suitable for storing or processing PHI**, regardless of its SOC 2 certification. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
If you tell me your use case (e.g., patient portal, intake forms, scheduling, internal admin app, etc.), I can help determine whether Softr is an appropriate choice or suggest HIPAA-ready alternatives.
ChatGPT (Web)AbsentIs ChatGPT HIPAA compliant?slot 8Aug 20, 02:30 PM
The short answer is: **it depends on which ChatGPT product you're using.**
- **Consumer ChatGPT (Free, Plus, and most personal accounts):** **No**, you should **not** treat it as HIPAA-compliant for handling protected health information (PHI). These products are not intended for processing PHI under HIPAA. [www.aptible.com](https://www.aptible.com/hipaa-compliant-ai-tools/openai-baa?utm_source=chatgpt.com)[help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)[cdn.openai.com](https://cdn.openai.com/osa/hipaa-guide.pdf?utm_source=chatgpt.com)
- **HIPAA-eligible OpenAI offerings:** OpenAI offers specific products that are designed to support HIPAA-compliant use **when configured appropriately and used under a signed Business Associate Agreement (BAA)**. These include:
- ChatGPT for Healthcare
- ChatGPT for Enterprise with a Regulated Workspace
- ChatGPT for Clinicians
- Certain OpenAI API configurations with Modified Retention (or other eligible configurations specified by OpenAI) [help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)[cdn.openai.com](https://cdn.openai.com/osa/hipaa-guide.pdf?utm_source=chatgpt.com)
It's important to distinguish between **being HIPAA compliant** and **supporting HIPAA-compliant use**. HIPAA compliance depends on the entire environment, including:
- Having a signed **Business Associate Agreement (BAA)** with OpenAI.
- Using a HIPAA-eligible product.
- Configuring security controls appropriately (such as access controls, audit logging, and retention settings).
- Following your organization's own HIPAA policies and procedures. OpenAI explicitly notes that customers remain responsible for their overall HIPAA compliance. [www.aptible.com](https://www.aptible.com/hipaa-compliant-ai-tools/openai-baa?utm_source=chatgpt.com)[help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)[cdn.openai.com](https://cdn.openai.com/osa/hipaa-guide.pdf?utm_source=chatgpt.com)
**If you're using ChatGPT personally (such as Free or Plus):**
- Avoid entering patient names, medical record numbers, dates of birth, or other PHI.
- If you need AI assistance with healthcare data, de-identify the information first, or use a HIPAA-eligible OpenAI product under a BAA. [www.aptible.com](https://www.aptible.com/hipaa-compliant-ai-tools/openai-baa?utm_source=chatgpt.com)[help.openai.com](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality?utm_source=chatgpt.com)[cdn.openai.com](https://cdn.openai.com/osa/hipaa-guide.pdf?utm_source=chatgpt.com)
If your question is about a specific use case—such as using ChatGPT in a hospital, private practice, or healthcare startup—I can explain what would be required in that context.
ChatGPT (Web)AbsentWhat are the best HIPAA compliant client portal solutions for small healthcare practices?slot 98Aug 18, 01:33 PM
For a small healthcare practice, I’d prioritize a **full practice-management/EHR platform with a built-in patient portal**, rather than buying a standalone portal. That keeps secure messaging, forms, scheduling, documents, payments, and clinical records in one place.
One important caveat: **“HIPAA compliant” is not a certification or a guarantee that your practice is compliant.** If a vendor handles ePHI for you, HHS says you generally need a HIPAA-compliant **Business Associate Agreement (BAA)** with that vendor, and your practice still has its own HIPAA obligations and risk analysis. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### My top picks
| Platform | Best for | Portal strengths | My take |
|---|---|---|---|
| **SimplePractice** | Therapists, counselors, behavioral health | Secure messaging, forms, scheduling, documents, telehealth | **Best overall for mental/behavioral health** |
| **Practice Better** | Nutrition, functional medicine, health/wellness | Messaging, intake, scheduling, programs, journals, resources, payments | **Best overall for client engagement** |
| **Healthie** | Dietitians, nutritionists, wellness practices | Portal, charting, scheduling, telehealth, payments, mobile apps | **Best value for a small solo practice** |
| **Carepatron** | Budget-conscious practices | Portal, forms, scheduling, messaging, records, automation | **Best low-cost modern option** |
| **Jane App** | PT, chiropractic, multidisciplinary clinics | Scheduling, forms, messaging, charting, online booking | **Best for multi-provider clinics** |
| **TherapyNotes** | Behavioral-health practices | Secure client portal, documentation, billing, telehealth | **Best for insurance-heavy therapy practices** |
| **Tebra** | Medical practices wanting broader RCM/EHR | Patient engagement, scheduling, billing, communications | **Best when billing/RCM is a major priority** |
#### 1. [SimplePractice](https://www.simplepractice.com/?utm_source=chatgpt.com) — best for behavioral health
This would be my first look for a therapist, psychologist, counselor, or similar small behavioral-health practice. It combines the portal with scheduling, intake paperwork, documentation, billing, and telehealth rather than treating the portal as a separate product.
SimplePractice says it adheres to HIPAA requirements and has a BAA in place with all customers. [www.simplepractice.com](https://www.simplepractice.com/trust-center/faqs/?utm_source=chatgpt.com)
**Choose it if:** you want something mature, polished, and relatively turnkey.
#### 2. [Practice Better](https://practicebetter.io/?utm_source=chatgpt.com) — best for ongoing client engagement
This is particularly compelling for **nutritionists, dietitians, functional medicine, health coaches, and wellness-oriented practices**. The portal supports secure messaging, intake forms, scheduling, programs/resources, food and lifestyle journals, and client progress tracking. [practicebetter.io](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
Practice Better says HIPAA compliance is included across its plans and that a BAA is available. [practicebetter.io](https://practicebetter.io/teams?utm_source=chatgpt.com)
**Choose it if:** clients need to interact with you between appointments rather than simply book appointments and receive documents.
#### 3. [Healthie](https://www.gethealthie.com/?utm_source=chatgpt.com) — excellent for solo practices
Healthie is another strong option for nutrition and wellness practices. Its current Core plan is listed at **$19.99/month** and includes scheduling, payments, charting, telehealth, and a client portal, although it's limited to 10 active clients. Essentials is listed at $49.99/month with substantially higher client capacity. Healthie states that it is HIPAA and SOC 2 compliant. [www.gethealthie.com](https://www.gethealthie.com/healthie-pricing?utm_source=chatgpt.com)
**Choose it if:** you're a solo practitioner and want a relatively inexpensive all-in-one system that can grow with you.
#### 4. [Carepatron](https://www.carepatron.com/?utm_source=chatgpt.com) — best budget-friendly option
Carepatron is worth a serious look if price and ease of setup are important. It advertises **HIPAA compliance, a BAA, SOC 2 certification, and encryption at rest and in transit** as standard rather than requiring extensive configuration. [www.carepatron.com](https://www.carepatron.com/features/compliance-and-security?utm_source=chatgpt.com)
**Choose it if:** you're a small practice that wants modern workflow/automation without committing to a more expensive enterprise-oriented system.
### How I'd narrow it down
- **Therapist / psychologist:** SimplePractice or TherapyNotes
- **Dietitian / nutritionist:** Healthie or Practice Better
- **Functional medicine / wellness:** Practice Better
- **PT / chiropractor / multidisciplinary clinic:** Jane App
- **Small medical practice with significant insurance billing:** Tebra
- **Solo practice on a tight budget:** Carepatron or Healthie
- **Practice where client engagement between visits is central:** Practice Better
### What to verify before signing up
Don't rely solely on a vendor's “HIPAA compliant” badge. Ask these questions:
1. **Will you sign a BAA with my practice?**
2. Does the BAA cover **the specific plan/features I'm purchasing**?
3. Is patient-to-provider messaging encrypted?
4. Are uploaded documents and forms encrypted **at rest and in transit**?
5. Is **MFA/2FA** available for every staff account?
6. Are there audit logs showing access to PHI?
7. Can I control staff access based on roles?
8. What happens to my data if I cancel?
9. Can I export the complete patient record?
10. Which integrations also require separate BAAs?
HHS specifically cautions that even if a cloud provider encrypts ePHI and cannot decrypt it, it can still be a business associate; the BAA requirement doesn't disappear simply because the data is encrypted. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
**If I were choosing for a typical 1–5 person practice today, my shortlist would be _SimplePractice, Practice Better, Healthie, and Carepatron_.** The best one depends heavily on whether you're primarily behavioral health, medical, or wellness/nutrition.
If you tell me **your specialty, number of providers, approximate patient count, and whether you need insurance billing**, I can narrow this to the **top 2–3 and compare current pricing, portal features, EHR/charting, telehealth, forms, and integrations**.
[SimplePractice](https://www.simplepractice.com/?utm_source=chatgpt.com)
[Practice Better](https://practicebetter.io/?utm_source=chatgpt.com)
[Healthie](https://www.gethealthie.com/?utm_source=chatgpt.com)
[Carepatron](https://www.carepatron.com/?utm_source=chatgpt.com)
| Platform | Best for | Portal strengths | My take |
|---|---|---|---|
| **SimplePractice** | Therapists, counselors, behavioral health | Secure messaging, forms, scheduling, documents, telehealth | **Best overall for mental/behavioral health** |
| **Practice Better** | Nutrition, functional medicine, health/wellness | Messaging, intake, scheduling, programs, journals, resources, payments | **Best overall for client engagement** |
| **Healthie** | Dietitians, nutritionists, wellness practices | Portal, charting, scheduling, telehealth, payments, mobile apps | **Best value for a small solo practice** |
| **Carepatron** | Budget-conscious practices | Portal, forms, scheduling, messaging, records, automation | **Best low-cost modern option** |
| **Jane App** | PT, chiropractic, multidisciplinary clinics | Scheduling, forms, messaging, charting, online booking | **Best for multi-provider clinics** |
| **TherapyNotes** | Behavioral-health practices | Secure client portal, documentation, billing, telehealth | **Best for insurance-heavy therapy practices** |
| **Tebra** | Medical practices wanting broader RCM/EHR | Patient engagement, scheduling, billing, communications | **Best when billing/RCM is a major priority** |
#### 1. [SimplePractice](https://www.simplepractice.com/?utm_source=chatgpt.com) — best for behavioral health
This would be my first look for a therapist, psychologist, counselor, or similar small behavioral-health practice. It combines the portal with scheduling, intake paperwork, documentation, billing, and telehealth rather than treating the portal as a separate product.
SimplePractice says it adheres to HIPAA requirements and has a BAA in place with all customers. [www.simplepractice.com](https://www.simplepractice.com/trust-center/faqs/?utm_source=chatgpt.com)
**Choose it if:** you want something mature, polished, and relatively turnkey.
#### 2. [Practice Better](https://practicebetter.io/?utm_source=chatgpt.com) — best for ongoing client engagement
This is particularly compelling for **nutritionists, dietitians, functional medicine, health coaches, and wellness-oriented practices**. The portal supports secure messaging, intake forms, scheduling, programs/resources, food and lifestyle journals, and client progress tracking. [practicebetter.io](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
Practice Better says HIPAA compliance is included across its plans and that a BAA is available. [practicebetter.io](https://practicebetter.io/teams?utm_source=chatgpt.com)
**Choose it if:** clients need to interact with you between appointments rather than simply book appointments and receive documents.
#### 3. [Healthie](https://www.gethealthie.com/?utm_source=chatgpt.com) — excellent for solo practices
Healthie is another strong option for nutrition and wellness practices. Its current Core plan is listed at **$19.99/month** and includes scheduling, payments, charting, telehealth, and a client portal, although it's limited to 10 active clients. Essentials is listed at $49.99/month with substantially higher client capacity. Healthie states that it is HIPAA and SOC 2 compliant. [www.gethealthie.com](https://www.gethealthie.com/healthie-pricing?utm_source=chatgpt.com)
**Choose it if:** you're a solo practitioner and want a relatively inexpensive all-in-one system that can grow with you.
#### 4. [Carepatron](https://www.carepatron.com/?utm_source=chatgpt.com) — best budget-friendly option
Carepatron is worth a serious look if price and ease of setup are important. It advertises **HIPAA compliance, a BAA, SOC 2 certification, and encryption at rest and in transit** as standard rather than requiring extensive configuration. [www.carepatron.com](https://www.carepatron.com/features/compliance-and-security?utm_source=chatgpt.com)
**Choose it if:** you're a small practice that wants modern workflow/automation without committing to a more expensive enterprise-oriented system.
### How I'd narrow it down
- **Therapist / psychologist:** SimplePractice or TherapyNotes
- **Dietitian / nutritionist:** Healthie or Practice Better
- **Functional medicine / wellness:** Practice Better
- **PT / chiropractor / multidisciplinary clinic:** Jane App
- **Small medical practice with significant insurance billing:** Tebra
- **Solo practice on a tight budget:** Carepatron or Healthie
- **Practice where client engagement between visits is central:** Practice Better
### What to verify before signing up
Don't rely solely on a vendor's “HIPAA compliant” badge. Ask these questions:
1. **Will you sign a BAA with my practice?**
2. Does the BAA cover **the specific plan/features I'm purchasing**?
3. Is patient-to-provider messaging encrypted?
4. Are uploaded documents and forms encrypted **at rest and in transit**?
5. Is **MFA/2FA** available for every staff account?
6. Are there audit logs showing access to PHI?
7. Can I control staff access based on roles?
8. What happens to my data if I cancel?
9. Can I export the complete patient record?
10. Which integrations also require separate BAAs?
HHS specifically cautions that even if a cloud provider encrypts ePHI and cannot decrypt it, it can still be a business associate; the BAA requirement doesn't disappear simply because the data is encrypted. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
**If I were choosing for a typical 1–5 person practice today, my shortlist would be _SimplePractice, Practice Better, Healthie, and Carepatron_.** The best one depends heavily on whether you're primarily behavioral health, medical, or wellness/nutrition.
If you tell me **your specialty, number of providers, approximate patient count, and whether you need insurance billing**, I can narrow this to the **top 2–3 and compare current pricing, portal features, EHR/charting, telehealth, forms, and integrations**.
ChatGPT (Web)AbsentIs Knack HIPAA compliant?slot 19Aug 18, 01:21 PM
Yes — **Knack can be used for HIPAA-compliant applications**, but there’s an important distinction: **not every Knack account/plan is HIPAA compliant**.
According to Knack’s current documentation:
- **HIPAA plans are available** for organizations handling PHI.
- Knack will provide/sign a **Business Associate Agreement (BAA)** on its HIPAA plans. [www.knack.com](https://www.knack.com/health/hipaa/?utm_source=chatgpt.com)[docs.knack.com](https://docs.knack.com/docs/your-responsibilities-as-a-covered-entity?utm_source=chatgpt.com)
- The HIPAA environment includes safeguards such as **encryption in transit and at rest, role-based access controls, audit/change logs, 2FA, IP allowlisting, backups, and monitoring**. [www.knack.com](https://www.knack.com/health/security/?utm_source=chatgpt.com)
- **You must have the BAA in place before putting PHI into Knack.** Knack specifically says not to upload PHI during its non-HIPAA trial. [docs.knack.com](https://docs.knack.com/v3/docs/knack-health-hipaa-plans?utm_source=chatgpt.com)
- Your organization is still responsible for configuring the application and maintaining its own HIPAA policies and procedures. [docs.knack.com](https://docs.knack.com/docs/your-responsibilities-as-a-covered-entity?utm_source=chatgpt.com)
- **Third-party integrations are a major caveat:** if PHI leaves Knack through an API, Flow, webhook, email service, etc., that third party also needs to be appropriately HIPAA compliant and have a BAA with you. [docs.knack.com](https://docs.knack.com/docs/flows-and-third-party-compliance?utm_source=chatgpt.com)
So, if you're asking **"Can I store PHI in Knack?"** the answer is **yes, provided you're on a HIPAA plan and have the BAA executed, and you configure/use the system appropriately.**
If you tell me **what you're planning to build in Knack** (e.g., patient intake, case management, client portal, medical records), I can also tell you whether the particular setup is likely to satisfy HIPAA requirements and what to watch out for.
ChatGPT (Web)AbsentHow do I choose a vendor to build a HIPAA compliant client portal for a small healthcare practice?slot 21Aug 18, 12:47 PM
For a small healthcare practice, I’d choose the vendor **less like a normal software-development shop and more like a security/compliance partner**. “HIPAA compliant” is not a certification that makes a product automatically safe; your practice still has responsibilities, including risk analysis and appropriate safeguards. HHS specifically says the Security Rule is scalable to the size and circumstances of the organization. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html?form=MG0AV3&utm_source=chatgpt.com)
### 1. First decide whether you actually need a custom portal
Before hiring anyone, define what the portal must do:
- Patient registration/intake
- Secure messaging
- Appointment requests
- Forms and document exchange
- Lab/results delivery
- Billing/payment information
- Telehealth
- Integration with your EHR/EMR
- Staff-to-patient communication
- Patient identity verification
If an established healthcare platform already provides most of these functions, **buying/configuring it is usually much lower risk than commissioning a custom application**.
Custom development makes more sense when your workflow is genuinely unusual or you need integrations/functionality existing products can't provide.
### 2. Make the BAA a hard requirement
If the vendor will create, receive, maintain, or transmit ePHI for the practice, it will generally be a HIPAA business associate. HHS says a covered entity needs a HIPAA-compliant **Business Associate Agreement (BAA)** with such a provider. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)
Ask every vendor:
> **“Will you sign our BAA before we provide you with any PHI, and does the BAA cover all of your subcontractors that will handle ePHI?”**
Don't accept “our platform is HIPAA compliant” as an answer.
The agreement should address, among other things, permitted uses/disclosures, security safeguards, breach reporting, return/destruction of PHI, and subcontractors. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html?utm_source=chatgpt.com)
### 3. Evaluate the actual security architecture
Have a technically knowledgeable person review the architecture—not just the sales presentation.
At minimum, ask about:
| Area | What I'd want to see |
|---|---|
| **Encryption** | Encryption in transit and at rest; understand key management |
| **Authentication** | Strong authentication, preferably MFA for staff |
| **Authorization** | Role-based/least-privilege access |
| **Audit logs** | Who accessed/changed what, when, and from where |
| **Session security** | Automatic timeout, secure sessions, account recovery |
| **Backups** | Encrypted backups, tested restoration, disaster recovery |
| **Monitoring** | Security monitoring and incident detection |
| **Development** | Code review, dependency management, vulnerability scanning |
| **Testing** | Penetration testing and remediation process |
| **Availability** | Uptime commitments and disaster-recovery objectives |
| **Data deletion** | What happens to PHI when you terminate the contract |
| **Subprocessors** | Complete list and how they are governed |
These aren't arbitrary technical preferences: HIPAA's Security Rule includes access controls, audit controls, authentication, integrity protections and transmission security. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html?form=MG0AV3&utm_source=chatgpt.com)
### 4. Ask for evidence, not promises
A good vendor should be comfortable answering questions such as:
- Do you have a current **SOC 2 Type II** report?
- Can we review the report under NDA?
- When was your last penetration test?
- Can we receive an executive summary of the findings?
- What critical/high vulnerabilities are currently outstanding?
- What is your incident-response process?
- When will we be notified of a security incident?
- Who has production access to our data?
- Are production engineers able to see patient records?
- What cloud providers and subprocessors do you use?
- How are encryption keys managed?
- How do you segregate customers' data?
- How do you securely delete our data?
- Can we export all of our data in a usable format?
Importantly, **HIPAA doesn't itself require a vendor to give you its security documentation or permit customer audits**. HHS notes that you can nevertheless negotiate additional assurances through the BAA, SLA, or other contractual documentation. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
So make the evidence part of vendor selection rather than discovering later that the vendor won't provide it.
### 5. Pay particular attention to integrations
This is where otherwise good portal projects can become dangerous.
Draw the data flow:
**Patient → Portal → Application → EHR → Labs/Pharmacy/etc.**
For every arrow, ask:
- Is PHI being transmitted?
- Who operates that system?
- Is there a BAA where required?
- Is the connection encrypted?
- What authentication mechanism is used?
- What happens if the integration fails?
- Is PHI cached or stored outside the primary system?
- Are logs themselves potentially containing PHI?
Your vendor should be able to produce a clear architecture/data-flow diagram.
### 6. Don't let the vendor define "HIPAA compliant" for you
I'd give vendors a requirements document containing **specific acceptance criteria**.
For example:
> The application must support unique user identification, appropriate access controls, MFA for administrative users, audit logging of access to ePHI, encryption of ePHI in transit and at rest, documented backup/recovery procedures, security incident response, and contractual BAA obligations.
That turns “HIPAA compliant” from a marketing claim into something you can actually evaluate.
### 7. Score vendors rather than choosing based on price
For a small practice, I'd use something roughly like:
| Criterion | Weight |
|---|---:|
| Security architecture & controls | **25%** |
| HIPAA/BAA maturity | **20%** |
| Healthcare experience | **15%** |
| Reliability & disaster recovery | **10%** |
| EHR/integration capability | **10%** |
| Product usability | **10%** |
| Total cost | **10%** |
I'd deliberately give **price only 10%**. A $20,000 cheaper project isn't cheaper if you later have to rebuild the authentication, logging, integrations, backup architecture, or security controls.
### 8. Look for these vendor red flags
I'd walk away—or at least investigate very carefully—if you hear:
- “We're HIPAA compliant because we use AWS/Azure.”
- “HIPAA doesn't require a BAA because we can't see the data.”
- “We're HIPAA certified.”
- “Encryption means you're covered.”
- “We don't need audit logs.”
- “We can figure security out after development.”
- “Our developers are HIPAA trained, so that's sufficient.”
- “We don't provide penetration-test information.”
- “We don't have a formal incident-response process.”
- “You don't need a risk assessment.”
- “We can use whatever third-party tools we want.”
- “You don't need to worry about our subcontractors.”
For example, HHS explicitly says that a cloud provider can still be a business associate even when it stores only encrypted ePHI and cannot decrypt it. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2076/if-a-csp-stores-only-encrypted-ephi-and-does-not-have-a-decryption-key-is-it-a-hipaa-business-associate/index.html?utm_source=chatgpt.com)
### 9. Make the contract protect the practice
The development/SaaS agreement should cover more than the BAA:
- Ownership of the application and data
- Source-code ownership or escrow, if appropriate
- Data portability/export
- Security obligations
- BAA
- Subprocessor requirements
- Breach/incident notification
- Uptime/SLA
- Backup and recovery
- Disaster recovery
- Vulnerability remediation
- Penetration testing
- Change-management procedures
- Termination assistance
- Secure deletion/return of PHI
- Liability/indemnification
- Insurance, including appropriate cyber coverage
HHS specifically notes that an SLA can address availability, backup/recovery, data return after termination, security responsibilities, and data retention/disclosure. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2076/if-a-csp-stores-only-encrypted-ephi-and-does-not-have-a-decryption-key-is-it-a-hipaa-business-associate/index.html?utm_source=chatgpt.com)
### 10. Do your own HIPAA risk analysis
Don't outsource your entire compliance responsibility to the developer.
HHS calls risk analysis **foundational** to the Security Rule, and its Security Risk Assessment Tool is specifically intended to help small and medium-sized healthcare practices. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=chatgpt.com)
A sensible process is:
**Practice requirements → risk analysis → vendor requirements → architecture review → vendor selection → BAA/contract → security testing → launch → ongoing monitoring**
I'd also have a **healthcare/privacy attorney or HIPAA consultant review the BAA and contract**, particularly if the portal will store clinical records rather than merely facilitate communications.
### My preferred vendor-selection process
For a small practice, I'd shortlist **3–5 vendors**, then give each exactly the same requirements and security questionnaire. Have them provide:
1. Architecture/data-flow diagram
2. BAA
3. Security documentation
4. SOC 2 report or equivalent assurance
5. Pen-test summary
6. Subprocessor list
7. Disaster-recovery/backup description
8. Data-export/deletion procedure
9. Sample SLA
10. Three healthcare customer references
Then score them using the same rubric.
**The biggest mistake I'd avoid:** choosing a developer first and asking them to “make it HIPAA compliant” afterward. Security, identity, logging, data architecture, integrations, backups, and contractual responsibilities need to be designed into the system from the beginning.
If you tell me **the practice size, what the portal needs to do, whether you already use an EHR (e.g., Epic, athenahealth, Jane, etc.), and whether you want custom development or are open to an existing platform**, I can narrow this into a practical vendor-selection strategy and a set of questions you can send to prospective vendors.
| Area | What I'd want to see |
|---|---|
| **Encryption** | Encryption in transit and at rest; understand key management |
| **Authentication** | Strong authentication, preferably MFA for staff |
| **Authorization** | Role-based/least-privilege access |
| **Audit logs** | Who accessed/changed what, when, and from where |
| **Session security** | Automatic timeout, secure sessions, account recovery |
| **Backups** | Encrypted backups, tested restoration, disaster recovery |
| **Monitoring** | Security monitoring and incident detection |
| **Development** | Code review, dependency management, vulnerability scanning |
| **Testing** | Penetration testing and remediation process |
| **Availability** | Uptime commitments and disaster-recovery objectives |
| **Data deletion** | What happens to PHI when you terminate the contract |
| **Subprocessors** | Complete list and how they are governed |
These aren't arbitrary technical preferences: HIPAA's Security Rule includes access controls, audit controls, authentication, integrity protections and transmission security. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html?form=MG0AV3&utm_source=chatgpt.com)
### 4. Ask for evidence, not promises
A good vendor should be comfortable answering questions such as:
- Do you have a current **SOC 2 Type II** report?
- Can we review the report under NDA?
- When was your last penetration test?
- Can we receive an executive summary of the findings?
- What critical/high vulnerabilities are currently outstanding?
- What is your incident-response process?
- When will we be notified of a security incident?
- Who has production access to our data?
- Are production engineers able to see patient records?
- What cloud providers and subprocessors do you use?
- How are encryption keys managed?
- How do you segregate customers' data?
- How do you securely delete our data?
- Can we export all of our data in a usable format?
Importantly, **HIPAA doesn't itself require a vendor to give you its security documentation or permit customer audits**. HHS notes that you can nevertheless negotiate additional assurances through the BAA, SLA, or other contractual documentation. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
So make the evidence part of vendor selection rather than discovering later that the vendor won't provide it.
### 5. Pay particular attention to integrations
This is where otherwise good portal projects can become dangerous.
Draw the data flow:
**Patient → Portal → Application → EHR → Labs/Pharmacy/etc.**
For every arrow, ask:
- Is PHI being transmitted?
- Who operates that system?
- Is there a BAA where required?
- Is the connection encrypted?
- What authentication mechanism is used?
- What happens if the integration fails?
- Is PHI cached or stored outside the primary system?
- Are logs themselves potentially containing PHI?
Your vendor should be able to produce a clear architecture/data-flow diagram.
### 6. Don't let the vendor define "HIPAA compliant" for you
I'd give vendors a requirements document containing **specific acceptance criteria**.
For example:
> The application must support unique user identification, appropriate access controls, MFA for administrative users, audit logging of access to ePHI, encryption of ePHI in transit and at rest, documented backup/recovery procedures, security incident response, and contractual BAA obligations.
That turns “HIPAA compliant” from a marketing claim into something you can actually evaluate.
### 7. Score vendors rather than choosing based on price
For a small practice, I'd use something roughly like:
| Criterion | Weight |
|---|---:|
| Security architecture & controls | **25%** |
| HIPAA/BAA maturity | **20%** |
| Healthcare experience | **15%** |
| Reliability & disaster recovery | **10%** |
| EHR/integration capability | **10%** |
| Product usability | **10%** |
| Total cost | **10%** |
I'd deliberately give **price only 10%**. A $20,000 cheaper project isn't cheaper if you later have to rebuild the authentication, logging, integrations, backup architecture, or security controls.
### 8. Look for these vendor red flags
I'd walk away—or at least investigate very carefully—if you hear:
- “We're HIPAA compliant because we use AWS/Azure.”
- “HIPAA doesn't require a BAA because we can't see the data.”
- “We're HIPAA certified.”
- “Encryption means you're covered.”
- “We don't need audit logs.”
- “We can figure security out after development.”
- “Our developers are HIPAA trained, so that's sufficient.”
- “We don't provide penetration-test information.”
- “We don't have a formal incident-response process.”
- “You don't need a risk assessment.”
- “We can use whatever third-party tools we want.”
- “You don't need to worry about our subcontractors.”
For example, HHS explicitly says that a cloud provider can still be a business associate even when it stores only encrypted ePHI and cannot decrypt it. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2076/if-a-csp-stores-only-encrypted-ephi-and-does-not-have-a-decryption-key-is-it-a-hipaa-business-associate/index.html?utm_source=chatgpt.com)
### 9. Make the contract protect the practice
The development/SaaS agreement should cover more than the BAA:
- Ownership of the application and data
- Source-code ownership or escrow, if appropriate
- Data portability/export
- Security obligations
- BAA
- Subprocessor requirements
- Breach/incident notification
- Uptime/SLA
- Backup and recovery
- Disaster recovery
- Vulnerability remediation
- Penetration testing
- Change-management procedures
- Termination assistance
- Secure deletion/return of PHI
- Liability/indemnification
- Insurance, including appropriate cyber coverage
HHS specifically notes that an SLA can address availability, backup/recovery, data return after termination, security responsibilities, and data retention/disclosure. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html?utm_source=chatgpt.com)[www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2076/if-a-csp-stores-only-encrypted-ephi-and-does-not-have-a-decryption-key-is-it-a-hipaa-business-associate/index.html?utm_source=chatgpt.com)
### 10. Do your own HIPAA risk analysis
Don't outsource your entire compliance responsibility to the developer.
HHS calls risk analysis **foundational** to the Security Rule, and its Security Risk Assessment Tool is specifically intended to help small and medium-sized healthcare practices. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html?utm_source=chatgpt.com)
A sensible process is:
**Practice requirements → risk analysis → vendor requirements → architecture review → vendor selection → BAA/contract → security testing → launch → ongoing monitoring**
I'd also have a **healthcare/privacy attorney or HIPAA consultant review the BAA and contract**, particularly if the portal will store clinical records rather than merely facilitate communications.
### My preferred vendor-selection process
For a small practice, I'd shortlist **3–5 vendors**, then give each exactly the same requirements and security questionnaire. Have them provide:
1. Architecture/data-flow diagram
2. BAA
3. Security documentation
4. SOC 2 report or equivalent assurance
5. Pen-test summary
6. Subprocessor list
7. Disaster-recovery/backup description
8. Data-export/deletion procedure
9. Sample SLA
10. Three healthcare customer references
Then score them using the same rubric.
**The biggest mistake I'd avoid:** choosing a developer first and asking them to “make it HIPAA compliant” afterward. Security, identity, logging, data architecture, integrations, backups, and contractual responsibilities need to be designed into the system from the beginning.
If you tell me **the practice size, what the portal needs to do, whether you already use an EHR (e.g., Epic, athenahealth, Jane, etc.), and whether you want custom development or are open to an existing platform**, I can narrow this into a practical vendor-selection strategy and a set of questions you can send to prospective vendors.
ChatGPT (Web)AbsentHow do I build a HIPAA compliant client portal without writing code?slot 22Aug 18, 12:46 PM
Yes. You can build a **HIPAA-compliant client portal without writing code**, but the key is to use a no-code platform that is designed to handle PHI—not simply a generic website builder with a password.
### A practical no-code architecture
Think of the portal as four pieces:
1. **Client-facing portal**
- Secure login
- Client profile
- Secure messaging
- Forms/intake questionnaires
- Document upload/download
- Appointment information
- Payment information, if needed
2. **Secure database**
- Stores client records and submitted forms
- Role-based access so clients only see their own information
3. **Automation**
- Notifications when a client submits a form
- Staff alerts
- Appointment workflows
- Document-routing workflows
4. **Your existing systems**
- EHR/EMR
- Scheduling
- Billing
- Email/SMS
- Electronic signatures
### The most important HIPAA requirement
Don't start by asking, "Is this platform HIPAA compliant?"
Instead ask:
> **Will this vendor sign a Business Associate Agreement (BAA) with me, and does the specific product/configuration I'm using support HIPAA requirements?**
If a cloud service creates, receives, maintains, or transmits ePHI on your behalf, HHS says it generally qualifies as a business associate and you need a HIPAA-compliant BAA. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
A vendor merely saying "we're secure" isn't enough. HHS specifically notes that encryption by itself doesn't satisfy all HIPAA Security Rule requirements. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### A good no-code build pattern
I'd structure it like this:
**Client → Secure portal → HIPAA-capable database → Staff dashboard**
For example:
- **Login:** individual client accounts + MFA
- **Portal:** dashboard showing only that client's information
- **Forms:** intake, consent, questionnaires
- **Files:** encrypted document storage
- **Messaging:** secure portal messaging rather than ordinary email
- **Staff:** role-based access
- **Audit trail:** log important access/changes
- **Notifications:** avoid putting PHI in email/SMS notifications
The portal itself doesn't need to be complicated. The security architecture behind it is what matters.
### What to avoid
I would **not** build a PHI-containing portal by simply combining:
- a normal website builder
- Google Sheets/Airtable
- ordinary Gmail
- generic form software
- Zapier-style automations
- Dropbox/Google Drive
- a random membership/login plugin
…and assume that putting passwords on top makes it HIPAA compliant.
Every service in the chain that handles PHI needs to be evaluated. HHS also emphasizes that your organization remains responsible for conducting its own risk analysis and determining how responsibilities are divided between you and your vendors. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### The easiest route
If you're a small practice or service business, I'd generally recommend **buying a HIPAA-oriented portal platform rather than assembling one from generic no-code components**.
If you specifically want a *custom-branded* portal, then use a no-code platform whose **specific plan supports HIPAA and provides a BAA**, and keep the architecture deliberately simple.
Before going live, I'd verify:
- [ ] Vendor will execute a BAA
- [ ] Every service that touches PHI is covered by a BAA where required
- [ ] Unique user accounts
- [ ] Strong authentication/MFA
- [ ] Role-based permissions
- [ ] Encryption in transit and at rest
- [ ] Audit logging
- [ ] Secure backups/recovery
- [ ] Secure file uploads
- [ ] Session/logout controls
- [ ] Data-retention/deletion procedures
- [ ] Breach/incident procedures
- [ ] HIPAA risk analysis
- [ ] Privacy/security policies and workforce training
HHS provides sample BAA provisions covering things such as permitted uses of PHI, safeguards, breach reporting, access to PHI, subcontractors, and return/destruction of PHI. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html?utm_source=chatgpt.com)
**One important distinction:** "HIPAA compliant" isn't a certification you can simply obtain for a portal. HIPAA compliance involves the technology **plus your configuration, policies, procedures, contracts, risk analysis, and how your organization actually operates**.
If you tell me **what kind of business/practice this is and what you want clients to be able to do** (e.g., intake forms + messaging + documents + appointments), I can recommend a **specific no-code stack and show you exactly how I'd build the portal step-by-step without programming**.
ChatGPT (Web)AbsentWhat are the best HIPAA compliant client portal solutions for small healthcare practices?slot 104Aug 17, 04:19 PM
For a **small healthcare practice**, I’d focus on portals that combine secure messaging, forms, scheduling, document exchange, payments, and ideally an EHR/practice-management system. A portal can’t simply be labeled “HIPAA compliant” by the vendor and make your practice compliant; if the vendor handles ePHI on your behalf, you generally need a **Business Associate Agreement (BAA)** and your practice still has its own HIPAA risk-management obligations. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### My top choices
| Platform | Best for | Strengths | Watch-outs |
|---|---|---|---|
| **SimplePractice** | Therapists, counselors, behavioral health | Excellent portal, secure messaging, forms, scheduling, telehealth, billing; HITRUST certified | Primarily optimized for behavioral/mental health |
| **Practice Better** | Nutrition, functional medicine, wellness, coaching | Excellent client engagement, messaging, intake, programs, journals, scheduling and payments | Less ideal for traditional medical practices with complex insurance workflows |
| **Healthie** | Dietitians, nutritionists, wellness | Strong portal, nutrition tracking, messaging, telehealth and billing | Can become expensive as the practice grows |
| **Tebra** | Physicians and general medical practices | EHR + patient portal + billing + scheduling; designed specifically for independent practices | More comprehensive—and potentially more system than a very small practice needs |
| **Spruce Health** | Practices prioritizing communication | Secure messaging, phone, SMS, fax, video and patient app; very good patient communication experience | More of a communications platform than a full EHR |
### 1. SimplePractice — best overall for behavioral health
[SimplePractice client portal](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
This would be my **#1 choice for a small therapy, counseling, psychology, or social-work practice**. The portal handles appointment requests, forms/documents, payments and communication, while secure messaging keeps PHI out of ordinary email/text. SimplePractice says it is HIPAA compliant and HITRUST certified, and its BAA is in place with customers. [www.simplepractice.com](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
**Best if:** you want an established, polished system that patients can figure out without much hand-holding.
---
### 2. Practice Better — best client experience for wellness practices
[Practice Better client portal](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
Practice Better is particularly compelling for **dietitians, nutritionists, functional medicine, health coaches, and integrative practices**. The portal combines secure messaging, appointments, intake forms, documents, programs, protocols, journals and progress tracking. Its current documentation says HIPAA compliance and a BAA are available across its plans. [practicebetter.io](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
**Best if:** your relationship with patients continues between visits and you want them tracking food, symptoms, habits, goals, etc.
---
### 3. Healthie — strong alternative for nutrition/wellness
[Healthie](https://www.gethealthie.com/?utm_source=chatgpt.com)
Healthie is another strong option for **dietitians, nutrition practices and wellness providers**. It combines a client portal with secure messaging, scheduling, telehealth, tracking and practice-management capabilities. Industry comparisons highlight its nutrition-specific tracking and meal-planning capabilities. [practicebetter.io](https://practicebetter.io/blog/best-hipaa-compliant-telehealth-platforms?utm_source=chatgpt.com)
**Best if:** nutrition data and client tracking are central to your workflow.
---
### 4. Tebra — best for a conventional medical practice
[Tebra](https://www.tebra.com/?utm_source=chatgpt.com)
If you're running a **primary-care, specialty, or multi-provider medical practice**, I'd look at Tebra before a wellness-oriented portal. It combines EHR, practice management, billing and a secure patient portal. Tebra specifically positions the platform around independent practices and says its patient portal supports secure access to records and messaging. [www.tebra.com](https://www.tebra.com/hipaa-compliance?utm_source=chatgpt.com)
**Best if:** you need the portal to be part of a broader medical-office operating system rather than a standalone client-engagement tool.
---
### 5. Spruce Health — best for secure communication
[Spruce Health](https://sprucehealth.com/?utm_source=chatgpt.com)
Spruce is particularly interesting if your biggest problem is **patients texting, calling, emailing and faxing your staff through different channels**. It brings phone, texting, secure messaging, fax, video and team communication into one platform. Spruce says eligible organizations automatically receive a BAA and that its communications are HIPAA compliant. [sprucehealth.com](https://sprucehealth.com/patients?utm_source=chatgpt.com)
**Best if:** communication is the pain point and you already have an EHR you like.
---
## What I'd choose
**For a 1–5 person practice:**
- 🧠 **Therapy / behavioral health:** **SimplePractice**
- 🥗 **Dietitian / nutrition:** **Practice Better or Healthie**
- 🩺 **Primary care / medical specialty:** **Tebra**
- 💬 **Already have an EHR and mainly need secure communication:** **Spruce**
- 🌱 **Functional medicine / health coaching / wellness:** **Practice Better**
### One important HIPAA caveat
Don't evaluate these solely on a “HIPAA compliant” badge. Before signing up, verify:
1. **A BAA is actually available for your account/plan**
2. Secure messaging and file sharing are included—not just encrypted infrastructure
3. Patient authentication/access controls are appropriate
4. There are audit logs for access to PHI
5. You can export your patient data if you leave
6. The vendor explains breach notification, backups and data retention
7. Any integrations you add also have appropriate HIPAA arrangements
HHS specifically notes that OCR **does not certify or endorse individual products as “HIPAA compliant.”** [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
If you tell me **what type of practice you run (e.g., primary care, psychiatry, therapy, chiropractic, dental, dietitian), number of providers, and whether you already have an EHR**, I can narrow this to the **best 2–3 options and compare their current pricing and features**.
[SimplePractice client portal](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
[Practice Better client portal](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
[Healthie](https://www.gethealthie.com/?utm_source=chatgpt.com)
[Tebra](https://www.tebra.com/?utm_source=chatgpt.com)
[Spruce Health](https://sprucehealth.com/?utm_source=chatgpt.com)
SimplePractice
Practice Better
Tebra
Spruce Health
| Platform | Best for | Strengths | Watch-outs |
|---|---|---|---|
| **SimplePractice** | Therapists, counselors, behavioral health | Excellent portal, secure messaging, forms, scheduling, telehealth, billing; HITRUST certified | Primarily optimized for behavioral/mental health |
| **Practice Better** | Nutrition, functional medicine, wellness, coaching | Excellent client engagement, messaging, intake, programs, journals, scheduling and payments | Less ideal for traditional medical practices with complex insurance workflows |
| **Healthie** | Dietitians, nutritionists, wellness | Strong portal, nutrition tracking, messaging, telehealth and billing | Can become expensive as the practice grows |
| **Tebra** | Physicians and general medical practices | EHR + patient portal + billing + scheduling; designed specifically for independent practices | More comprehensive—and potentially more system than a very small practice needs |
| **Spruce Health** | Practices prioritizing communication | Secure messaging, phone, SMS, fax, video and patient app; very good patient communication experience | More of a communications platform than a full EHR |
### 1. SimplePractice — best overall for behavioral health
[SimplePractice client portal](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
This would be my **#1 choice for a small therapy, counseling, psychology, or social-work practice**. The portal handles appointment requests, forms/documents, payments and communication, while secure messaging keeps PHI out of ordinary email/text. SimplePractice says it is HIPAA compliant and HITRUST certified, and its BAA is in place with customers. [www.simplepractice.com](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
**Best if:** you want an established, polished system that patients can figure out without much hand-holding.
---
### 2. Practice Better — best client experience for wellness practices
[Practice Better client portal](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
Practice Better is particularly compelling for **dietitians, nutritionists, functional medicine, health coaches, and integrative practices**. The portal combines secure messaging, appointments, intake forms, documents, programs, protocols, journals and progress tracking. Its current documentation says HIPAA compliance and a BAA are available across its plans. [practicebetter.io](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
**Best if:** your relationship with patients continues between visits and you want them tracking food, symptoms, habits, goals, etc.
---
### 3. Healthie — strong alternative for nutrition/wellness
[Healthie](https://www.gethealthie.com/?utm_source=chatgpt.com)
Healthie is another strong option for **dietitians, nutrition practices and wellness providers**. It combines a client portal with secure messaging, scheduling, telehealth, tracking and practice-management capabilities. Industry comparisons highlight its nutrition-specific tracking and meal-planning capabilities. [practicebetter.io](https://practicebetter.io/blog/best-hipaa-compliant-telehealth-platforms?utm_source=chatgpt.com)
**Best if:** nutrition data and client tracking are central to your workflow.
---
### 4. Tebra — best for a conventional medical practice
[Tebra](https://www.tebra.com/?utm_source=chatgpt.com)
If you're running a **primary-care, specialty, or multi-provider medical practice**, I'd look at Tebra before a wellness-oriented portal. It combines EHR, practice management, billing and a secure patient portal. Tebra specifically positions the platform around independent practices and says its patient portal supports secure access to records and messaging. [www.tebra.com](https://www.tebra.com/hipaa-compliance?utm_source=chatgpt.com)
**Best if:** you need the portal to be part of a broader medical-office operating system rather than a standalone client-engagement tool.
---
### 5. Spruce Health — best for secure communication
[Spruce Health](https://sprucehealth.com/?utm_source=chatgpt.com)
Spruce is particularly interesting if your biggest problem is **patients texting, calling, emailing and faxing your staff through different channels**. It brings phone, texting, secure messaging, fax, video and team communication into one platform. Spruce says eligible organizations automatically receive a BAA and that its communications are HIPAA compliant. [sprucehealth.com](https://sprucehealth.com/patients?utm_source=chatgpt.com)
**Best if:** communication is the pain point and you already have an EHR you like.
---
## What I'd choose
**For a 1–5 person practice:**
- 🧠 **Therapy / behavioral health:** **SimplePractice**
- 🥗 **Dietitian / nutrition:** **Practice Better or Healthie**
- 🩺 **Primary care / medical specialty:** **Tebra**
- 💬 **Already have an EHR and mainly need secure communication:** **Spruce**
- 🌱 **Functional medicine / health coaching / wellness:** **Practice Better**
### One important HIPAA caveat
Don't evaluate these solely on a “HIPAA compliant” badge. Before signing up, verify:
1. **A BAA is actually available for your account/plan**
2. Secure messaging and file sharing are included—not just encrypted infrastructure
3. Patient authentication/access controls are appropriate
4. There are audit logs for access to PHI
5. You can export your patient data if you leave
6. The vendor explains breach notification, backups and data retention
7. Any integrations you add also have appropriate HIPAA arrangements
HHS specifically notes that OCR **does not certify or endorse individual products as “HIPAA compliant.”** [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
If you tell me **what type of practice you run (e.g., primary care, psychiatry, therapy, chiropractic, dental, dietitian), number of providers, and whether you already have an EHR**, I can narrow this to the **best 2–3 options and compare their current pricing and features**.
ChatGPT (Web)AbsentHow do I build a HIPAA compliant client portal without writing code?slot 24Aug 17, 02:33 PM
Yes. You can build a **no-code HIPAA-compliant client portal**, but the important distinction is that you’re not making the portal “HIPAA compliant” merely by choosing a no-code platform. You need a compliant **technology stack + configuration + policies + contracts + operational safeguards**.
HHS specifically says that if a cloud provider creates, receives, maintains, or transmits ePHI on your behalf, it is generally a **business associate**, and you need a HIPAA-compliant BAA with it. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### A practical no-code architecture
Think of the portal as five pieces:
1. **Client login**
- Individual accounts
- Strong authentication/MFA
- Automatic session expiration
- Role-based access
2. **Secure client dashboard**
- Profile information
- Secure messages
- Documents
- Forms/questionnaires
- Appointment information
3. **PHI database/storage**
- Use only a platform that explicitly supports HIPAA use for the relevant service.
- Execute its **BAA before putting PHI into it**.
- Don't assume that a platform's encryption or SOC 2 certification by itself makes it HIPAA compliant. HHS notes that encryption alone isn't sufficient. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
4. **Secure communications**
- Keep PHI inside the authenticated portal.
- Email/SMS notifications should generally say something like “You have a new message” rather than containing the patient's information.
5. **Administrative/security layer**
- Audit/access logs
- Backups and recovery
- Access provisioning/deprovisioning
- Incident response
- Risk analysis
- Written policies and workforce training
HHS requires covered entities and business associates to address risks to the confidentiality, integrity, and availability of ePHI; the responsibility isn't outsourced simply because you've selected a cloud platform. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### The easiest route
For a nontechnical organization, I'd avoid assembling a portal from a generic website builder + database + email service + automation platform.
Instead, look for a **healthcare-focused no-code portal platform** where:
- the vendor will sign a BAA;
- the exact features you're using are covered by that BAA;
- PHI is encrypted in transit and at rest;
- users have individual accounts;
- MFA is available;
- permissions can restrict one client's records from another's;
- access/activity logging is available;
- data export/deletion/retention is controllable;
- backups and disaster recovery are documented;
- the vendor explains its subcontractors/subprocessors.
The BAA matters because it establishes permitted uses/disclosures and requires appropriate safeguards. HHS provides sample BAA provisions you can use as a reference. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html?utm_source=chatgpt.com)
### A simple MVP
You could start with:
**Client**
→ Sign in
→ Dashboard
→ Secure messages
→ Documents
→ Forms
→ Appointments
→ Profile
**Staff**
→ Staff login
→ Client directory
→ Individual client record
→ Messages
→ Documents
→ Form responses
→ Audit history
Then add payments, telehealth, intake automation, etc. later.
### One important warning
Don't put PHI into tools such as ordinary forms, spreadsheets, website analytics, CRM systems, automation tools, AI services, or email platforms merely because they advertise themselves as "secure."
If a service handles ePHI for you, determine whether it is a business associate and obtain the appropriate BAA before using it for PHI. HHS explicitly says that even a cloud provider storing **only encrypted ePHI** can still be a business associate. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
Also, there's no HHS "HIPAA-certified" product designation; HHS says it does not endorse, certify, or recommend specific technology products. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com)
### If you tell me what you're building
I can give you a **specific no-code stack and architecture**—for example, *“patient portal for a 3-person therapy practice”* or *“client portal for a home-health company”*—including which platforms to use, what should/shouldn't contain PHI, the BAA requirements, and an implementation sequence.
ChatGPT (Web)AbsentWhat are the best HIPAA compliant client portal solutions for small healthcare practices?slot 104Aug 16, 03:53 PM
For a **small healthcare practice**, I’d prioritize a portal that is not merely “HIPAA compliant,” but also gives you a **signed BAA, secure messaging, intake/forms, scheduling, document sharing, payments, and a good patient experience**.
One important distinction: **HIPAA compliance is a shared responsibility**. A vendor can provide HIPAA-compliant infrastructure and a BAA, but your practice still has to configure and use the system appropriately.
### My top picks for 2026
| Solution | Best for | Biggest strength | Watch-out |
|---|---|---|---|
| **SimplePractice** | Behavioral health, therapists, SLPs | Excellent all-in-one client experience | Less suited to traditional medical specialties |
| **CharmHealth** | Primary care & small medical practices | Full EHR + portal at relatively small-practice scale | Interface can feel more complex |
| **Practice Better** | Dietitians, wellness, functional/integrative care | Outstanding client engagement | Not a traditional physician EHR |
| **DrChrono** | Solo/small medical practices | Mobile-first EHR + patient portal | More clinical/administrative complexity |
| **Tebra** | Independent practices wanting growth tools | Portal + practice management + marketing | Pricing is generally quote-based |
| **AdvancedMD** | Growing practices needing robust billing | Strong practice management/RCM | More expensive and sophisticated |
| **Jane** | PT, chiropractic, allied health | Very easy scheduling/client experience | Canadian-origin platform; verify U.S.-specific requirements for your workflow |
### 1. SimplePractice — best overall for behavioral health
If you're a therapist, counselor, psychologist, social worker, SLP, or similar provider, **SimplePractice would probably be my first demo**.
Its portal supports secure communication, documents, billing, appointment management, and online intake. SimplePractice explicitly describes its client portal and messaging as HIPAA compliant, and it has a strong reputation among small practices. [www.simplepractice.com](https://www.simplepractice.com/features/client-portal/?device=c&matchtype=e&network=o&utm_source=chatgpt.com)
Its current market positioning is particularly strong for behavioral-health practices; independent 2026 comparisons also put it near the top for solo and small practices. [www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
[SimplePractice client portal](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
**Best if:** you want something relatively easy to implement and don't need a highly specialized medical EHR.
---
### 2. CharmHealth — best value for a small medical practice
For **primary care, family medicine, integrative medicine, and other physician-led practices**, I'd put CharmHealth very high on the list.
Its patient portal supports appointment booking, questionnaires, secure messaging, documents, lab results, prescriptions/refills, visit summaries, invoices and payments. Charm explicitly states that its portal is HIPAA compliant. [www.charmhealth.com](https://www.charmhealth.com/resources/phr-user-guide/introduction.html?utm_source=chatgpt.com)
It also integrates the portal into a broader EHR/practice-management system rather than treating the portal as a standalone add-on. [www.charmhealth.com](https://www.charmhealth.com/practice-management/?utm_source=chatgpt.com)
[CharmHealth patient engagement](https://www.charmhealth.com/patient-engagement/?utm_source=chatgpt.com)
**Best if:** you want a genuine medical EHR + patient portal without jumping immediately to an enterprise platform.
---
### 3. Practice Better — best client experience for wellness practices
This is particularly compelling for **dietitians, nutritionists, health coaches, functional medicine, naturopathic providers, and similar practices**.
The portal combines secure messaging, scheduling, intake forms, documents, programs, journals and health/lifestyle tracking. [practicebetter.io](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
Practice Better also emphasizes that HIPAA compliance, encryption and a BAA are important parts of evaluating a portal—not merely whether a vendor puts a "HIPAA compliant" badge on its website. [practicebetter.io](https://practicebetter.io/blog/best-secure-client-portal-for-wellness-practitioners?utm_source=chatgpt.com)
[Practice Better client portal](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
**Best if:** the patient relationship continues substantially between appointments.
---
### 4. DrChrono — best mobile-oriented medical option
DrChrono is worth considering if you're a **solo physician or small medical group** and want the portal tightly connected to your EHR and clinical workflow.
It tends to make more sense than a standalone portal when you need clinical documentation, scheduling, billing and patient engagement in the same system.
**Best if:** you want an EHR first and a portal integrated into it.
---
### 5. Tebra — best for growth-oriented independent practices
Tebra combines patient communication, scheduling, digital forms and practice-management capabilities. Current 2026 comparisons specifically position it toward independent practices and growth-oriented clinics. [xchange.avixa.org](https://xchange.avixa.org/posts/10-best-hipaa-compliant-patient-portal-solutions-for-secure-healthcare-communication-in-2026?utm_source=chatgpt.com)[pabau.com](https://pabau.com/blog/patient-portal-software/?utm_source=chatgpt.com)[www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
**Best if:** you're building a practice and want patient acquisition/marketing and practice operations alongside the portal.
---
### 6. AdvancedMD — best for more sophisticated practices
AdvancedMD makes more sense once your needs extend beyond "I need a secure patient portal."
It's geared toward practices that need substantial **billing, claims, scheduling, reporting and practice-management functionality** in addition to patient self-service. Current comparisons identify it as particularly useful for independent practices that want the portal connected to billing and claims. [xchange.avixa.org](https://xchange.avixa.org/posts/10-best-hipaa-compliant-patient-portal-solutions-for-secure-healthcare-communication-in-2026?utm_source=chatgpt.com)[pabau.com](https://pabau.com/blog/patient-portal-software/?utm_source=chatgpt.com)[www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
**Best if:** billing/RCM is a major concern and you're willing to accept more complexity.
---
## What I'd choose by practice type
**Therapist / psychologist / counselor:**
→ **SimplePractice**
**Dietitian / nutritionist / wellness:**
→ **Practice Better**
**Solo physician / primary care:**
→ **CharmHealth** or **DrChrono**
**Growing multi-provider medical practice:**
→ **Tebra** or **AdvancedMD**
**PT / chiropractic / allied health:**
→ **Jane** or **Practice Better**
**Need only secure messaging/telehealth rather than an EHR:**
→ Consider a dedicated platform such as **Doxy.me**, rather than paying for an entire practice-management system. Current comparisons note that Doxy.me can provide a BAA even on its free plan, but it isn't a replacement for an EHR, billing or scheduling system. [practicebetter.io](https://practicebetter.io/blog/best-hipaa-compliant-telehealth-platforms?utm_source=chatgpt.com)
## The HIPAA checklist I'd use before signing
Don't rely solely on a vendor saying "HIPAA compliant." Ask each vendor:
1. **Will you execute a Business Associate Agreement (BAA) with my practice?**
2. Is the **patient portal itself** covered by the BAA?
3. Is PHI encrypted **in transit and at rest**?
4. Does the system provide **audit logs**?
5. Is **MFA/2FA** available for staff?
6. Can administrators enforce **role-based access**?
7. Can patients securely upload/download documents?
8. Is messaging contained within the authenticated portal rather than ordinary email/SMS?
9. How are **patient notifications** handled without exposing PHI?
10. Can patients complete **intake, consent and signatures** electronically?
11. Can you export the patient's data if you leave?
12. What happens to your data when you terminate the account?
A particularly important point: **a secure portal can still create a HIPAA problem if your staff accidentally sends PHI through ordinary email or unprotected text messages.** The workflow matters as much as the software.
### My short list
If I were narrowing this to **three demos for a typical small practice**, I'd start with:
**SimplePractice → easiest overall**
**CharmHealth → strongest small medical-practice value**
**Practice Better → best modern client-engagement experience**
The right winner depends heavily on whether you're a **physician practice, behavioral-health practice, or allied/wellness practice**. Current software comparisons similarly find that specialty is a major determinant of which platform is actually the best fit. [xchange.avixa.org](https://xchange.avixa.org/posts/10-best-hipaa-compliant-patient-portal-solutions-for-secure-healthcare-communication-in-2026?utm_source=chatgpt.com)[pabau.com](https://pabau.com/blog/patient-portal-software/?utm_source=chatgpt.com)[www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
If you tell me your **specialty, number of providers, approximate patient volume, and whether you already have an EHR**, I can narrow this to the **best 2–3 options and compare their current pricing, BAA terms, portal features, and integrations**.
[SimplePractice client portal](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
[CharmHealth patient engagement](https://www.charmhealth.com/patient-engagement/?utm_source=chatgpt.com)
SimplePractice
CharmHealth
Practice Better
DrChrono
Tebra
AdvancedMD
| Solution | Best for | Biggest strength | Watch-out |
|---|---|---|---|
| **SimplePractice** | Behavioral health, therapists, SLPs | Excellent all-in-one client experience | Less suited to traditional medical specialties |
| **CharmHealth** | Primary care & small medical practices | Full EHR + portal at relatively small-practice scale | Interface can feel more complex |
| **Practice Better** | Dietitians, wellness, functional/integrative care | Outstanding client engagement | Not a traditional physician EHR |
| **DrChrono** | Solo/small medical practices | Mobile-first EHR + patient portal | More clinical/administrative complexity |
| **Tebra** | Independent practices wanting growth tools | Portal + practice management + marketing | Pricing is generally quote-based |
| **AdvancedMD** | Growing practices needing robust billing | Strong practice management/RCM | More expensive and sophisticated |
| **Jane** | PT, chiropractic, allied health | Very easy scheduling/client experience | Canadian-origin platform; verify U.S.-specific requirements for your workflow |
### 1. SimplePractice — best overall for behavioral health
If you're a therapist, counselor, psychologist, social worker, SLP, or similar provider, **SimplePractice would probably be my first demo**.
Its portal supports secure communication, documents, billing, appointment management, and online intake. SimplePractice explicitly describes its client portal and messaging as HIPAA compliant, and it has a strong reputation among small practices. [www.simplepractice.com](https://www.simplepractice.com/features/client-portal/?device=c&matchtype=e&network=o&utm_source=chatgpt.com)
Its current market positioning is particularly strong for behavioral-health practices; independent 2026 comparisons also put it near the top for solo and small practices. [www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
[SimplePractice client portal](https://www.simplepractice.com/features/client-portal/?utm_source=chatgpt.com)
**Best if:** you want something relatively easy to implement and don't need a highly specialized medical EHR.
---
### 2. CharmHealth — best value for a small medical practice
For **primary care, family medicine, integrative medicine, and other physician-led practices**, I'd put CharmHealth very high on the list.
Its patient portal supports appointment booking, questionnaires, secure messaging, documents, lab results, prescriptions/refills, visit summaries, invoices and payments. Charm explicitly states that its portal is HIPAA compliant. [www.charmhealth.com](https://www.charmhealth.com/resources/phr-user-guide/introduction.html?utm_source=chatgpt.com)
It also integrates the portal into a broader EHR/practice-management system rather than treating the portal as a standalone add-on. [www.charmhealth.com](https://www.charmhealth.com/practice-management/?utm_source=chatgpt.com)
[CharmHealth patient engagement](https://www.charmhealth.com/patient-engagement/?utm_source=chatgpt.com)
**Best if:** you want a genuine medical EHR + patient portal without jumping immediately to an enterprise platform.
---
### 3. Practice Better — best client experience for wellness practices
This is particularly compelling for **dietitians, nutritionists, health coaches, functional medicine, naturopathic providers, and similar practices**.
The portal combines secure messaging, scheduling, intake forms, documents, programs, journals and health/lifestyle tracking. [practicebetter.io](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
Practice Better also emphasizes that HIPAA compliance, encryption and a BAA are important parts of evaluating a portal—not merely whether a vendor puts a "HIPAA compliant" badge on its website. [practicebetter.io](https://practicebetter.io/blog/best-secure-client-portal-for-wellness-practitioners?utm_source=chatgpt.com)
[Practice Better client portal](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
**Best if:** the patient relationship continues substantially between appointments.
---
### 4. DrChrono — best mobile-oriented medical option
DrChrono is worth considering if you're a **solo physician or small medical group** and want the portal tightly connected to your EHR and clinical workflow.
It tends to make more sense than a standalone portal when you need clinical documentation, scheduling, billing and patient engagement in the same system.
**Best if:** you want an EHR first and a portal integrated into it.
---
### 5. Tebra — best for growth-oriented independent practices
Tebra combines patient communication, scheduling, digital forms and practice-management capabilities. Current 2026 comparisons specifically position it toward independent practices and growth-oriented clinics. [xchange.avixa.org](https://xchange.avixa.org/posts/10-best-hipaa-compliant-patient-portal-solutions-for-secure-healthcare-communication-in-2026?utm_source=chatgpt.com)[pabau.com](https://pabau.com/blog/patient-portal-software/?utm_source=chatgpt.com)[www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
**Best if:** you're building a practice and want patient acquisition/marketing and practice operations alongside the portal.
---
### 6. AdvancedMD — best for more sophisticated practices
AdvancedMD makes more sense once your needs extend beyond "I need a secure patient portal."
It's geared toward practices that need substantial **billing, claims, scheduling, reporting and practice-management functionality** in addition to patient self-service. Current comparisons identify it as particularly useful for independent practices that want the portal connected to billing and claims. [xchange.avixa.org](https://xchange.avixa.org/posts/10-best-hipaa-compliant-patient-portal-solutions-for-secure-healthcare-communication-in-2026?utm_source=chatgpt.com)[pabau.com](https://pabau.com/blog/patient-portal-software/?utm_source=chatgpt.com)[www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
**Best if:** billing/RCM is a major concern and you're willing to accept more complexity.
---
## What I'd choose by practice type
**Therapist / psychologist / counselor:**
→ **SimplePractice**
**Dietitian / nutritionist / wellness:**
→ **Practice Better**
**Solo physician / primary care:**
→ **CharmHealth** or **DrChrono**
**Growing multi-provider medical practice:**
→ **Tebra** or **AdvancedMD**
**PT / chiropractic / allied health:**
→ **Jane** or **Practice Better**
**Need only secure messaging/telehealth rather than an EHR:**
→ Consider a dedicated platform such as **Doxy.me**, rather than paying for an entire practice-management system. Current comparisons note that Doxy.me can provide a BAA even on its free plan, but it isn't a replacement for an EHR, billing or scheduling system. [practicebetter.io](https://practicebetter.io/blog/best-hipaa-compliant-telehealth-platforms?utm_source=chatgpt.com)
## The HIPAA checklist I'd use before signing
Don't rely solely on a vendor saying "HIPAA compliant." Ask each vendor:
1. **Will you execute a Business Associate Agreement (BAA) with my practice?**
2. Is the **patient portal itself** covered by the BAA?
3. Is PHI encrypted **in transit and at rest**?
4. Does the system provide **audit logs**?
5. Is **MFA/2FA** available for staff?
6. Can administrators enforce **role-based access**?
7. Can patients securely upload/download documents?
8. Is messaging contained within the authenticated portal rather than ordinary email/SMS?
9. How are **patient notifications** handled without exposing PHI?
10. Can patients complete **intake, consent and signatures** electronically?
11. Can you export the patient's data if you leave?
12. What happens to your data when you terminate the account?
A particularly important point: **a secure portal can still create a HIPAA problem if your staff accidentally sends PHI through ordinary email or unprotected text messages.** The workflow matters as much as the software.
### My short list
If I were narrowing this to **three demos for a typical small practice**, I'd start with:
**SimplePractice → easiest overall**
**CharmHealth → strongest small medical-practice value**
**Practice Better → best modern client-engagement experience**
The right winner depends heavily on whether you're a **physician practice, behavioral-health practice, or allied/wellness practice**. Current software comparisons similarly find that specialty is a major determinant of which platform is actually the best fit. [xchange.avixa.org](https://xchange.avixa.org/posts/10-best-hipaa-compliant-patient-portal-solutions-for-secure-healthcare-communication-in-2026?utm_source=chatgpt.com)[pabau.com](https://pabau.com/blog/patient-portal-software/?utm_source=chatgpt.com)[www.getpracticehelp.com](https://www.getpracticehelp.com/ehr/best-ehr-small-practices/?utm_source=chatgpt.com)
If you tell me your **specialty, number of providers, approximate patient volume, and whether you already have an EHR**, I can narrow this to the **best 2–3 options and compare their current pricing, BAA terms, portal features, and integrations**.
[Practice Better client portal](https://practicebetter.io/features/client-portal?utm_source=chatgpt.com)
First cited Aug 16, most recently Aug 21.