HIPAA-compliant scheduling software: what actually makes it compliant

"HIPAA compliant" gets used as a marketing label more than a technical one. Here's what the phrase should actually mean when you're choosing scheduling software for a medical or dental practice — and where the tools people default to usually fall short.

Start your 14-day free trial See pricing
No credit card required to start.

A signed Business Associate Agreement (BAA) is the legal minimum, not the technical whole story. HIPAA requires a BAA from any vendor that will touch patient data — that part is non-negotiable. But a BAA on its own doesn't tell you whether the software actually has the safeguards a compliance review will ask about: who can see what, whether changes are traceable, and what happens if someone walks away from a logged-in screen at the front desk.

This is exactly where general-purpose tools — a shared Google Calendar, a Calendly link, a spreadsheet — tend to fall short even when the underlying provider (like Google Workspace) offers a BAA. The BAA covers the infrastructure; it doesn't add an audit trail or session controls that weren't built into the product.

The actual checklist

What to look for beyond "we're HIPAA compliant" on a vendor's homepage.

📄

A signed BAA before data goes in

Available on request, not buried behind a top-tier plan or an enterprise sales call — and signed before any patient data is entered, not after.

🔍

An audit trail

A record of who created, viewed, or changed an appointment or patient record, and when. This matters for both compliance reviews and everyday accountability.

👥

Role-based access

Owner and staff accounts with distinct permissions, rather than one shared login everyone uses — so access can be tied to an actual person.

🔒

Automatic session timeout

A logged-in screen at an unattended front desk is a real exposure. Sessions should lock themselves after a short idle period without staff having to remember to log out.

🏢

Data isolation between practices

If the software serves multiple practices (a multi-tenant SaaS product), each practice's data should be fully separated from every other practice's — not just permission-gated in a shared database.

Where general-purpose tools fall short

A BAA from the underlying platform doesn't mean the scheduling workflow built on top of it is compliant.

Google Workspace and Calendly can both offer a BAA under the right plan — see the detailed breakdown of Google Calendar and Calendly specifically. But neither was built as scheduling software for healthcare: no audit trail of appointment changes, no distinct staff roles, no automatic session lock. A practice using either for patient scheduling is relying on the BAA to cover gaps the product itself doesn't address.

How Kenko approaches this

Built for healthcare scheduling specifically, not adapted from a general-purpose calendar.

📄

HIPAA BAA available

US medical and dental practices can request a signed BAA before entering any patient data — learn more.

🔍

Full audit trail

Every change to a patient record is logged — who, what, and when.

👥

Owner and staff roles

Invite your whole team with a single code, with distinct roles rather than one shared login.

🔒

Automatic session lock

Idle sessions lock automatically after 15 minutes, no staff action required.

🏢

Isolated per practice

Each practice's data is fully separated from every other practice on Kenko.

See how this applies to a multi-provider practice

Compliance gets more complicated once more than one doctor shares a calendar. Here's the full guide to what matters for multi-provider scheduling.

Read the multi-provider guide

Frequently asked questions

Does having a HIPAA BAA mean software is fully compliant?

No. A signed Business Associate Agreement is a legal requirement before any patient data touches a vendor's systems, but it doesn't by itself guarantee the software has an audit trail, role-based access, or session timeouts — those are separate technical safeguards a practice should also check for.

What is an audit trail, and does every scheduling tool have one?

An audit trail is a record of who created, viewed, or changed a patient's appointment or record, and when. Most general-purpose calendar and booking tools don't have one — it's a feature specific to healthcare-oriented software.

Is Kenko HIPAA compliant?

Kenko offers a signed BAA to US medical and dental practices before any patient data is entered, logs changes to patient records in an audit trail, supports owner/staff role separation, and automatically locks idle sessions after 15 minutes.

Try it with your own schedule

14-day free trial. No credit card required.

Start your free trial