Guide

Why the HIPAA-compliant tier costs more, and how to price the stack

Summary

A software vendor's HIPAA-compliant plan costs more because it is the tier on which the vendor will sign a business associate agreement and take on the legal duties that follow, and you need it for any tool that creates, receives, maintains or transmits patient information on your practice's behalf. Tools that never touch patient information can stay on the cheap tier. Sort the stack by where the data goes, then budget the compliant tools as a monthly line.

By Gale Editorial · Updated 2026-09-02. Every figure cited to a dated source. How we write.

What the extra money is buying

The compliant tier is the tier on which the vendor agrees to become your business associate, and that status carries legal duties the cheaper tier does not create. HIPAA makes a vendor a business associate whenever it creates, receives, maintains, or transmits protected health information on a covered entity's behalf, whatever kind of company it is 1. The price gap is the vendor charging for that.

Before a practice may hand patient information to a vendor at all, the Privacy Rule requires the practice to obtain satisfactory assurance, recorded in a contract, that the vendor will appropriately safeguard the information 2. The contract has to do real work: it must restrict the vendor from using or further disclosing the information other than as the contract or law permits, and it must cover safeguards, breach reporting, access, and the return or destruction of the information when the relationship ends 2.

Electronic records pull in a second provision with its own number. The Security Rule sets a parallel satisfactory-assurances condition for electronic protected health information, in accordance with the contract-content rule at 45 CFR 164.314(a) 3. A vendor holding your notes is answering to both.

None of that is free to the vendor.

Which of your tools genuinely need it

The test is whether patient information reaches the tool, and it turns on the service the vendor performs, not the kind of company it is. ONC's guide for small practices puts it in one line: many contractors that perform services for a covered entity are not business associates, because the services do not involve the use or disclosure of PHI 4. Sort the stack by where the data goes and a fair share of it stays on the ordinary tier.

ONC's own worked pair is a practice website designer. A designer with ongoing access to patient records, running a portal, is a business associate. A designer who touches only the public marketing site, with no access to PHI, is not 4.

ToolDoes patient information reach it?Tier
Video platform used for visitsYes, the visit itselfBusiness associate agreement required
Scheduling that stores names and visit reasonsYesBusiness associate agreement required
Ambient note-taking over visit audioYesBusiness associate agreement required
Intake and screening formsYes, from the first answerBusiness associate agreement required
Public marketing site carrying no patient dataNoOrdinary tier
Accounting software holding revenue totals onlyNoOrdinary tier

The right-hand column moves. An intake form added to a scheduler, a transcription feature switched on by default, a support inbox that starts receiving records: each of those carries a tool across the line without anyone buying anything.

Telehealth is the one place this used to be softer. The enforcement discretion that covered telehealth platforms during the COVID-19 emergency has ended, and OCR's current telehealth guidance, as of July 2026, describes the HIPAA-compliant arrangement providers are expected to run on, audio-only sessions included 5. A video tool used for visits sits on the agreement side of the line.

Why one signature may not cover the whole stack

A vendor's own suppliers sit inside the obligation. The Privacy Rule requires a business associate to ensure that any subcontractor that creates, receives, maintains, or transmits protected health information on its behalf agrees in writing to the same restrictions that bind the vendor 2. So the agreement a platform signs is a claim about a chain: its hosting provider, its transcription service, whatever analytics run behind the product.

That is answerable on a sales call, in writing. Ask which subcontractors touch patient data, whether the vendor holds an agreement with each, and what happens if it swaps one out mid-contract. If the vendor cannot name them, it cannot show you the agreements either.

Where the flow is genuinely ambiguous, the determination belongs to the practice, and it is worth an hour with counsel who will read the contract. Put that hour in the same budget line as the tier.

What skipping it costs

Operating without a required agreement is a violation in its own right, exposed to the same civil money penalty schedule as any other HIPAA violation. The regulation sets four culpability tiers, and at the 2009 baseline written into the section, each tier caps at $1,500,000 for identical violations during a calendar year 6. Those dollar amounts are adjusted annually for inflation and republished separately at 45 CFR part 102, so the section itself is not the live table 6.

Look the current figures up at 45 CFR part 102 before quoting them, including to yourself. The number printed in the penalty section is a 2009 baseline and the adjusted figures run above it.

But the penalty schedule is the least likely of these costs to arrive. The ordinary version is quieter. Breach reporting is one of the terms the rule requires the agreement to contain, so a vendor that never signed one has committed to nothing in writing about a breach on its side 2. Without one there is no agreed timeline, no defined process and no contractual recourse, so whatever notice arrives comes on the vendor's terms.

The second quiet cost is the record. A practice that can produce a signed agreement for every tool that held patient data is answering an easier set of questions, in an audit or a complaint, than one that cannot.

Pricing the stack

Put the compliant tier in the recurring column and size it for a year. The SBA's startup-cost method separates one-time costs from the monthly expenses a business carries after it opens, and advises counting at least a year of the monthly ones 7. A business-associate-tier subscription is exactly that shape. Price the difference between the two tiers, since the tool was going to cost something either way.

Write the delta per tool per month, add it up, multiply by twelve, and carry the annual figure into the startup budget as its own line. It then feeds the price floor you compute from cost, and it is one input when you sit down to pricing the tiers you offer patients.

Three moves shrink the number without pretending. Cut the count of tools that touch patient information at all, since every one you remove is a subscription, a chain and a contract you no longer maintain. Take annual billing only where the discount is real and the vendor is one you expect to still be using in a year. And check for duplication, because two tools each paying a compliant tier to do one job is a common way for a small stack to cost like a large one.

What happens when a compliant tool goes down is a different question. It belongs to the contingency plan.

What to ask before you upgrade

Ask four things and get the answers in writing. Whether the vendor will sign a business associate agreement at the tier you are actually buying, since the signature is sometimes gated above the plan the sales page implies. Which subcontractors touch patient data. What breach notification timeline the agreement commits the vendor to. And what happens to your records at termination, since return or destruction is one of the terms the rule requires 2.

Order matters more than it looks. Settle the signature question before you compare prices, because a tier that will not produce an agreement is not competing on price with one that will.

Two more belong on the list when the tool holds clinical records. Ask how you export those records if you leave, in what format, and whether the export costs money. And ask what the vendor does with practice data for its own product development, which is a question about permitted uses, and the agreement is where it gets answered.

Redo the sort every year. Tools drift across the line quietly, and the stack you sorted last January is not the one running now.

Common questions

The regulatory trigger is creating, receiving, maintaining or transmitting protected health information on a covered entity's behalf, and readability is not one of the words in the definition. A vendor that claims encryption puts it outside the definition is making a legal argument about its own status. Get that claim in writing and put it in front of counsel before you rely on it.

Only where the vendor will sign a business associate agreement at that plan, which some will and many will not. The obligation attaches to the data flow, so the price of the plan changes nothing about whether the agreement is required. If the free tier cannot produce a signed agreement, the tool is not a candidate for anything patient-facing.

The ones that acquired a patient-data feature after you bought them. An intake form bolted onto a scheduler, a transcription option enabled by default, a shared inbox that starts receiving records from patients. None of these announce themselves as a change of category, and the tool sat on the ordinary tier the whole time. Re-sort the stack yearly.

It depends on what the site does. A public marketing site with no access to patient records is the standard example of a service that does not involve PHI, and its designer is not a business associate. A site running a patient portal, intake forms or messaging is a different animal, and so is the person with ongoing access to it.

Price only the delta. For each tool that needs an agreement, write down the monthly difference between the tier you would otherwise buy and the compliant one, total it, and multiply by twelve. That annual number goes in the recurring column of the budget and feeds the cost-based price floor.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Health and Human Services (2024). § 160.103 Definitions. Electronic Code of Federal Regulations (eCFR), Title 45, Subtitle A, Subchapter C, Part 160, Subpart A. linkThe regulatory definition of a business associate and its trigger: creating, receiving, maintaining or transmitting protected health information on a covered entity's behalf, regardless of the vendor's category or the plan a practice bought.
  2. 2.U.S. Department of Health and Human Services (2024). § 164.504 Uses and disclosures: Organizational requirements. Electronic Code of Federal Regulations (eCFR), Title 45, Subtitle A, Subchapter C, Part 164, Subpart E. linkThe Privacy Rule's satisfactory-assurance precondition before PHI may be disclosed to a vendor, the required contract terms (permitted uses, safeguards, breach reporting, access, return or destruction at termination), and the subcontractor flow-down obligation.
  3. 3.U.S. Department of Health and Human Services (2024). § 164.308 Administrative safeguards. Electronic Code of Federal Regulations (eCFR), Title 45, Subtitle A, Subchapter C, Part 164, Subpart C. linkThe Security Rule's parallel satisfactory-assurances condition for electronic PHI and its cross-reference to the contract-content rule at 45 CFR 164.314(a).
  4. 4.Office of the National Coordinator for Health Information Technology (ONC), U.S. Department of Health and Human Services (2015). Guide to Privacy and Security of Electronic Health Information. HealthIT.gov (Version 2.0, April 2015). linkThe plain-language test that many contractors serving a practice are not business associates because the service does not involve the use or disclosure of PHI, and ONC's website-designer pair distinguishing a vendor with record access from one without.
  5. 5.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat telehealth now runs on HIPAA-compliant arrangements following the end of the COVID-era enforcement discretion, including OCR's guidance on audio-only telehealth, as of July 2026.
  6. 6.U.S. Department of Health and Human Services (2024). § 160.404 Amount of a civil money penalty. Electronic Code of Federal Regulations (eCFR), Title 45, Subtitle A, Subchapter C, Part 160, Subpart D. linkThe existence and four-tier structure of HIPAA civil money penalties, the $1,500,000 per-calendar-year cap for identical violations as the 2009 baseline, and the fact that the dollar amounts are adjusted annually and republished at 45 CFR part 102 rather than stated in this section.
  7. 7.U.S. Small Business Administration (2026). Plan your business — Calculate your startup costs. SBA.gov. linkOrganising practice overhead into one-time startup costs versus recurring monthly expenses, and the guidance to count at least a year of the monthly ones when budgeting.

https://www.gale.care/for-providers/se-baa-plan-tier-pricing · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)