It is a fair question with an unfair shape. There is no HIPAA certification. No agency audits software and issues a badge. Which means a vendor can answer yes truthfully, answer yes meaninglessly, and you cannot tell which from the answer alone.
What you can do is stop asking for the adjective and start asking for the documents and specifications that actually exist.
What HIPAA actually requires of a coaching platform
HIPAA does not regulate software. It regulates organizations that hold protected health information, and the vendors they hand it to.
A platform that creates, receives, maintains or transmits PHI on your behalf is a business associate, defined at 45 CFR 160.103 in HHS guidance. That triggers two obligations, and only two are worth arguing about in an evaluation.
The first is the agreement. The covered entity has to obtain satisfactory assurances, in the form of a written contract, that the business associate will appropriately safeguard the information (45 CFR 164.502(e)). No signed BAA means the arrangement is out of compliance, however good the vendor's encryption is.
The second is the Security Rule: administrative, physical and technical safeguards, covering risk analysis, workforce training, facility and device controls, access control, audit mechanisms, integrity, authentication and transmission security. Business associates carry direct liability for these under HITECH, not merely a contractual one.
HIPAA-compliant coaching platforms: six things to verify
Compliance lives in the answers, not the adjective. Ask for these six in writing, before a demo.
A signed BAA, not a claim on a website
"HIPAA-compliant" on a marketing page commits a vendor to nothing. A countersigned BAA does. Ask who signs it, how long it takes, and whether it comes with the standard plan or only an enterprise contract. A vendor who will not sign one cannot hold your PHI, and that ends the evaluation early, which is a gift.
Where the data lives, and who certified the environment
Ask for the hosting provider, the region, and the certifications that apply. Then ask the follow-up that separates most vendors: which of those certifications belong to the cloud provider, and which belong to the vendor's own audited controls? Azure and AWS carry ISO 27001 and SOC 2 attestations for their infrastructure. That is real, and it is not the same thing as the software company on top of it having been audited.
Encryption stated as versions, not adjectives
"Bank-level encryption" is not a specification. AES-256 at rest and TLS 1.2 or higher in transit are. Ask for the versions, ask whether TLS 1.0 and 1.1 are disabled, and ask what happens to data in backups and in exports, which is where a surprising amount of PHI quietly ends up.
Role-based access, and audit logs you can actually pull
Two questions do the work here. Can a coach be scoped to only their own members, and can an administrator produce a record of who viewed what and when? The first is daily hygiene. The second is what you need during an incident, and it is the one nobody tests until the day it matters.
A testing cadence with dates attached
Penetration testing, vulnerability scanning, security training that covers contractors as well as staff, phishing simulation. Ask for the frequency of each and the date of the most recent one. A vendor who cannot name a date has not had one recently.
The vendor's breach history, which is already public
Breaches of unsecured PHI affecting 500 or more individuals are reported to the HHS Office for Civil Rights, which investigates every one of them and publishes them in the OCR breach portal. Search the vendor's name before the call rather than after. An empty result is not a guarantee and an entry is not automatically disqualifying; how the vendor talks about it unprompted is the actual signal.
What Avidon answers
Ours, stated plainly enough to paste into a questionnaire. The full detail lives on our security and compliance page.
- BAAs: in place, with full alignment to HIPAA regulations.
- Certifications: SOC 2 Type II, and ISO 27001 certified. Both are Avidon's own, not inherited from the hosting provider.
- Hosting: Microsoft Azure, containerized microservices, in a HIPAA-compliant environment.
- Access: role-based access control for internal and external users, with detailed reporting and audit logs available to administrators.
- Testing: annual penetration testing, weekly vulnerability scans, hardened environment monitoring.
- People: annual security training for employees, contractors and interns, plus ongoing phishing simulations.
- Identity and integration: SSO with SAML 2.0 and user provisioning, REST APIs, secure webhook support.
- Privacy: clear consent, data portability and user control built in, for GDPR.
Where we fit, and where we do not
A compliance page that only says yes is not much use, so here are two limits worth stating.
And no platform can secure a workflow it cannot see. PHI in a coach's personal text thread, a roster kept in a spreadsheet beside the system, a screenshot pasted into email: none of that sits inside any vendor's controls. Consolidating where the member record lives is the security change, which is often the same reason a team is already choosing coaching software. Fewer places for the member record to live means fewer places to secure, which is the argument for a coaching-team platform.
In practice the security review is frequently the longer half, which is an argument for asking for the BAA and the questionnaire on the first call instead of the last.
Compliance is not a claim you can evaluate. It is a set of documents and specifications you can request by name, and every one of them can be answered in writing before anybody schedules a demo. A vendor who resists putting it in writing has already told you something useful.
