Security and Compliance

HIPAA-Compliant Coaching Platforms: What to Verify

Every coaching organization that touches health data gets the same question, usually buried in a spreadsheet with forty others on it: is your platform HIPAA-compliant?

Program director taking notes while reviewing platform security requirements
No software is HIPAA-compliant on its own. A coaching platform is compliant in use when the vendor signs a business associate agreement and implements the Security Rule safeguards: access controls, audit logs, encryption in transit and at rest, and a documented risk analysis. Ask for the signed BAA first, before any feature conversation.

It is a fair question with an unfair shape. There is no HIPAA certification. No agency audits software and issues a badge. Which means a vendor can answer yes truthfully, answer yes meaninglessly, and you cannot tell which from the answer alone.

What you can do is stop asking for the adjective and start asking for the documents and specifications that actually exist.

What HIPAA actually requires of a coaching platform

HIPAA does not regulate software. It regulates organizations that hold protected health information, and the vendors they hand it to.

A platform that creates, receives, maintains or transmits PHI on your behalf is a business associate, defined at 45 CFR 160.103 in HHS guidance. That triggers two obligations, and only two are worth arguing about in an evaluation.

The first is the agreement. The covered entity has to obtain satisfactory assurances, in the form of a written contract, that the business associate will appropriately safeguard the information (45 CFR 164.502(e)). No signed BAA means the arrangement is out of compliance, however good the vendor's encryption is.

The second is the Security Rule: administrative, physical and technical safeguards, covering risk analysis, workforce training, facility and device controls, access control, audit mechanisms, integrity, authentication and transmission security. Business associates carry direct liability for these under HITECH, not merely a contractual one.

Here is the part most security questionnaires get backwards. Encryption is not mandated by the Security Rule; it is an addressable implementation specification under 45 CFR 164.306(d), which means the vendor decides whether it is reasonable and appropriate, implements an equivalent alternative, or documents why not. "We encrypt" is a good answer, but it is not proof of compliance, and its absence is not proof of a violation.

HIPAA-compliant coaching platforms: six things to verify

Compliance lives in the answers, not the adjective. Ask for these six in writing, before a demo.

A signed BAA, not a claim on a website

"HIPAA-compliant" on a marketing page commits a vendor to nothing. A countersigned BAA does. Ask who signs it, how long it takes, and whether it comes with the standard plan or only an enterprise contract. A vendor who will not sign one cannot hold your PHI, and that ends the evaluation early, which is a gift.

Where the data lives, and who certified the environment

Ask for the hosting provider, the region, and the certifications that apply. Then ask the follow-up that separates most vendors: which of those certifications belong to the cloud provider, and which belong to the vendor's own audited controls? Azure and AWS carry ISO 27001 and SOC 2 attestations for their infrastructure. That is real, and it is not the same thing as the software company on top of it having been audited.

Encryption stated as versions, not adjectives

"Bank-level encryption" is not a specification. AES-256 at rest and TLS 1.2 or higher in transit are. Ask for the versions, ask whether TLS 1.0 and 1.1 are disabled, and ask what happens to data in backups and in exports, which is where a surprising amount of PHI quietly ends up.

Role-based access, and audit logs you can actually pull

Two questions do the work here. Can a coach be scoped to only their own members, and can an administrator produce a record of who viewed what and when? The first is daily hygiene. The second is what you need during an incident, and it is the one nobody tests until the day it matters.

A testing cadence with dates attached

Penetration testing, vulnerability scanning, security training that covers contractors as well as staff, phishing simulation. Ask for the frequency of each and the date of the most recent one. A vendor who cannot name a date has not had one recently.

The vendor's breach history, which is already public

Breaches of unsecured PHI affecting 500 or more individuals are reported to the HHS Office for Civil Rights, which investigates every one of them and publishes them in the OCR breach portal. Search the vendor's name before the call rather than after. An empty result is not a guarantee and an entry is not automatically disqualifying; how the vendor talks about it unprompted is the actual signal.

What Avidon answers

Ours, stated plainly enough to paste into a questionnaire. The full detail lives on our security and compliance page.

AES-256 at rest for PII and sensitive data
TLS 1.2 enforced for data in transit
99.9% uptime SLA
  • BAAs: in place, with full alignment to HIPAA regulations.
  • Certifications: SOC 2 Type II, and ISO 27001 certified. Both are Avidon's own, not inherited from the hosting provider.
  • Hosting: Microsoft Azure, containerized microservices, in a HIPAA-compliant environment.
  • Access: role-based access control for internal and external users, with detailed reporting and audit logs available to administrators.
  • Testing: annual penetration testing, weekly vulnerability scans, hardened environment monitoring.
  • People: annual security training for employees, contractors and interns, plus ongoing phishing simulations.
  • Identity and integration: SSO with SAML 2.0 and user provisioning, REST APIs, secure webhook support.
  • Privacy: clear consent, data portability and user control built in, for GDPR.

Where we fit, and where we do not

A compliance page that only says yes is not much use, so here are two limits worth stating.

We are a business associate, not your compliance program. The BAA and our safeguards cover the platform. Your own risk analysis, workforce training, sanction policy and access decisions remain yours, and those are what an investigation asks about first.

And no platform can secure a workflow it cannot see. PHI in a coach's personal text thread, a roster kept in a spreadsheet beside the system, a screenshot pasted into email: none of that sits inside any vendor's controls. Consolidating where the member record lives is the security change, which is often the same reason a team is already choosing coaching software. Fewer places for the member record to live means fewer places to secure, which is the argument for a coaching-team platform.

2 to 4 weeks
for an enterprise implementation

In practice the security review is frequently the longer half, which is an argument for asking for the BAA and the questionnaire on the first call instead of the last.

Compliance is not a claim you can evaluate. It is a set of documents and specifications you can request by name, and every one of them can be answered in writing before anybody schedules a demo. A vendor who resists putting it in writing has already told you something useful.

Frequently Asked Questions

What coaching teams ask before they sign a BAA.

Is any coaching platform HIPAA certified?+
No. There is no HIPAA certification and no agency issues one, so any badge claiming otherwise is a vendor's own creation. What exists is a signed business associate agreement plus documented Security Rule safeguards, and those are what a reviewer should ask to see.
What is a business associate agreement, and do we need one?+
It is the written contract in which a vendor handling PHI on your behalf commits to safeguarding it. HHS requires the covered entity to obtain it before PHI changes hands (45 CFR 164.502(e)). If a platform stores your members' health information and there is no signed BAA, that is a compliance gap regardless of the platform's security.
Does HIPAA require encryption?+
Not explicitly. Encryption is an addressable specification under 45 CFR 164.306(d), meaning the organization decides whether it is reasonable and appropriate, implements an equivalent safeguard, or documents its reasoning. In practice almost every serious platform encrypts, and you should still ask for the specific versions rather than accepting "encrypted."
What should we verify before buying a coaching platform?+
Six things, all answerable in writing: a signed BAA, where the data is hosted and whose certifications those are, encryption versions at rest and in transit, role-based access with retrievable audit logs, a testing cadence with recent dates, and the vendor's history in the HHS OCR breach portal.
Is Avidon HIPAA-compliant?+
Avidon states full alignment with HIPAA regulations and has BAAs in place, holds SOC 2 Type II and ISO 27001 certification, hosts on Microsoft Azure, encrypts PII at rest with AES-256 and enforces TLS 1.2 in transit, and runs role-based access control with administrator audit logs. Compliance is shared, so your own risk analysis, training and access decisions stay with your organization.

See It Before You Decide Anything

Start with a free demo, or look through how it works at whatever depth suits you: a live walkthrough, a two-minute video, an interactive tour, or a conversation with an expert.

Author

  • The Avidon Health logo.

    Avidon Health is transforming how organizations promote healthier lifestyles through behavior change science and technology-driven coaching. Our mission is to empower individuals to achieve better health outcomes while driving measurable business success for our clients.

    With over 20 years of expertise in health coaching and cognitive behavioral training, we’ve built a platform that delivers personalized, 1-to-1 well-being experiences at scale.

    Today, organizations use Avidon to reimagine engagement, enhance health, and create lasting behavior change—making wellness more accessible, impactful, and results-driven.

Looking to join our team? Click here for an important message