"HIPAA compliant" gets used as a marketing label more than a technical one. Here's what the phrase should actually mean when you're choosing scheduling software for a medical or dental practice — and where the tools people default to usually fall short.
A signed Business Associate Agreement (BAA) is the legal minimum, not the technical whole story. HIPAA requires a BAA from any vendor that will touch patient data — that part is non-negotiable. But a BAA on its own doesn't tell you whether the software actually has the safeguards a compliance review will ask about: who can see what, whether changes are traceable, and what happens if someone walks away from a logged-in screen at the front desk.
This is exactly where general-purpose tools — a shared Google Calendar, a Calendly link, a spreadsheet — tend to fall short even when the underlying provider (like Google Workspace) offers a BAA. The BAA covers the infrastructure; it doesn't add an audit trail or session controls that weren't built into the product.
What to look for beyond "we're HIPAA compliant" on a vendor's homepage.
Available on request, not buried behind a top-tier plan or an enterprise sales call — and signed before any patient data is entered, not after.
A record of who created, viewed, or changed an appointment or patient record, and when. This matters for both compliance reviews and everyday accountability.
Owner and staff accounts with distinct permissions, rather than one shared login everyone uses — so access can be tied to an actual person.
A logged-in screen at an unattended front desk is a real exposure. Sessions should lock themselves after a short idle period without staff having to remember to log out.
If the software serves multiple practices (a multi-tenant SaaS product), each practice's data should be fully separated from every other practice's — not just permission-gated in a shared database.
A BAA from the underlying platform doesn't mean the scheduling workflow built on top of it is compliant.
Google Workspace and Calendly can both offer a BAA under the right plan — see the detailed breakdown of Google Calendar and Calendly specifically. But neither was built as scheduling software for healthcare: no audit trail of appointment changes, no distinct staff roles, no automatic session lock. A practice using either for patient scheduling is relying on the BAA to cover gaps the product itself doesn't address.
Built for healthcare scheduling specifically, not adapted from a general-purpose calendar.
US medical and dental practices can request a signed BAA before entering any patient data — learn more.
Every change to a patient record is logged — who, what, and when.
Invite your whole team with a single code, with distinct roles rather than one shared login.
Idle sessions lock automatically after 15 minutes, no staff action required.
Each practice's data is fully separated from every other practice on Kenko.
Compliance gets more complicated once more than one doctor shares a calendar. Here's the full guide to what matters for multi-provider scheduling.
Read the multi-provider guideNo. A signed Business Associate Agreement is a legal requirement before any patient data touches a vendor's systems, but it doesn't by itself guarantee the software has an audit trail, role-based access, or session timeouts — those are separate technical safeguards a practice should also check for.
An audit trail is a record of who created, viewed, or changed a patient's appointment or record, and when. Most general-purpose calendar and booking tools don't have one — it's a feature specific to healthcare-oriented software.
Kenko offers a signed BAA to US medical and dental practices before any patient data is entered, logs changes to patient records in an audit trail, supports owner/staff role separation, and automatically locks idle sessions after 15 minutes.