HIPAA Compliance for Legal Technology Tools
What law firms must know before entrusting protected health information to legal-technology software: BAAs, data-security baselines, audit controls, and what to look for in a vendor.
When a law firm sends medical records to any third-party software — for review, for storage, or for AI-assisted analysis — those records remain Protected Health Information (PHI) under HIPAA. The attorney–client relationship does not insulate the firm from HIPAA's requirements. This guide explains what HIPAA compliance means for legal technology, what a Business Associate Agreement does, and what to look for when evaluating a vendor.
Does HIPAA Apply to Law Firms?
The short answer is: it depends on the role. Law firms are not "Covered Entities" under HIPAA in the same way that hospitals and health plans are. However, when a law firm receives Protected Health Information from a Covered Entity — typically through litigation discovery or a client authorization — it may become a Business Associate of that Covered Entity, which brings specific HIPAA obligations.
More practically: any software vendor that processes, stores, or transmits PHI on behalf of a law firm is a Business Associate under HIPAA. Before that software can touch medical records, the vendor must sign a Business Associate Agreement (BAA) — a contract that establishes how PHI will be protected, what uses are permitted, and what happens in the event of a breach.
The practical implication for law firms: if you upload medical records to any cloud-based software — document management, AI review, chronology tools — and that vendor has not signed a BAA with your firm, the arrangement is potentially non-compliant with HIPAA.
What Is a Business Associate Agreement?
A BAA is a legally required contract between a Covered Entity (or a Business Associate that subcontracts to another entity) and a vendor that will handle PHI. Under 45 CFR §164.504(e), a BAA must, at minimum:
- Describe the permitted and required uses and disclosures of PHI by the Business Associate.
- Require the Business Associate to use appropriate safeguards to prevent unauthorized use or disclosure.
- Require the Business Associate to report any security incidents or breaches.
- Require the Business Associate to return or destroy PHI at the termination of the arrangement.
- State that the Business Associate will comply with the applicable requirements of the HIPAA Security Rule.
A vendor that refuses to sign a BAA, or whose BAA contains significant carve-outs from these requirements, should be treated as a significant compliance risk. Chronos provides a signed BAA with every account — no custom negotiation required.
The HIPAA Security Rule Baseline
The Security Rule (45 CFR Part 164, Subpart C) requires that Business Associates implement administrative, physical, and technical safeguards to protect electronic PHI (ePHI). In practical terms, this means evaluating a vendor on:
Technical safeguards
- Encryption at rest and in transit: PHI should be encrypted using modern standards (AES-256 at rest; TLS 1.2+ in transit). Confirm these are implemented, not just promised.
- Access controls: Only authorized users should be able to access PHI, with role-based permissions that can be audited.
- Audit logs: The Security Rule requires audit controls — logs of who accessed PHI, when, and what action was taken. A vendor that cannot provide access logs is non-compliant.
- Automatic session termination: Inactive sessions should time out to prevent unauthorized access.
Administrative safeguards
- Security Risk Analysis: The Security Rule requires periodic risk analyses. Ask vendors when their last formal risk analysis was conducted and whether findings were remediated.
- Workforce training: Vendor employees who handle PHI should be trained on HIPAA requirements.
- Incident response: A documented breach notification process is required. Vendors must notify affected parties within 60 days of discovering a breach.
Third-party assurance
The most reliable indicator of a vendor's security posture is third-party verification. Look for:
- SOC 2 Type II: An audit by an independent CPA firm assessing the vendor's security controls over a period of time (not just a point-in-time snapshot).
- HITRUST CSF Certification: A framework specifically designed for healthcare data security.
- Penetration testing: Evidence of periodic external testing of the vendor's infrastructure.
Chronos operates on Aptible's HIPAA-eligible infrastructure, which is purpose-built for HIPAA-regulated workloads. See the Chronos security page for full technical details.
Data Residency and the Cloud
HIPAA does not prohibit cloud storage of PHI — but it does require that cloud providers implement the same safeguards as any other Business Associate. Confirm that your legal-tech vendor can state:
- Where data is stored (which cloud regions and datacenters)
- Whether data crosses international borders (important for state-specific privacy law compliance)
- What happens to your data if you cancel the service — and whether deletion is verifiable
Practical Vendor Evaluation Checklist
When evaluating any legal-technology tool that will process medical records, ask these questions before signing a contract:
Will you sign a Business Associate Agreement, and is it available without custom negotiation?
What encryption standards do you use for data at rest and in transit?
Do you maintain audit logs of PHI access, and are those logs available to our firm?
When was your last security risk analysis, and what was remediated?
Do you hold a SOC 2 Type II or equivalent third-party certification?
Where is data stored, and does it cross international borders?
What is your breach notification process and timeline?
How is PHI handled at account termination — and can deletion be verified?
State Privacy Laws and HIPAA Interaction
HIPAA sets a federal floor for PHI protection. Many states have enacted privacy laws that are more stringent — California, New York, and Texas among them. A vendor that is HIPAA-compliant may still create compliance risk if your firm handles records subject to stricter state requirements. Review your state bar's ethics guidance on data security for client files, and confirm that your vendor's practices align with those obligations.
This article is general information, not legal advice. HIPAA compliance questions specific to your firm's practice should be reviewed with qualified healthcare privacy counsel. The regulatory landscape changes; confirm current requirements with counsel before making compliance decisions.
For a broader view of the chronology workflow these compliance requirements apply to, see the Complete Guide to Medical Chronologies for Law Firms.
Related guides
See Chronos in action
Upload your records and get an AI-built, citation-linked chronology — ready for demand or deposition. Your first case is free.
Start free trial →