Compliance is a legal obligation your organization carries — not something a vendor can sell you a certificate for. Here's what we actually provide, and what to ask any IT vendor handling PHI.
No government body or private credentialing organization issues an official "HIPAA certification" to vendors. HIPAA compliance is a legal responsibility your organization holds — third-party providers support it through signed agreements and documented safeguards, not a badge.
Phrases like "HIPAA certified software" or "certified HIPAA compliant" usually mean a vendor completed a self-assessment — not that any government agency reviewed and approved them.
A Business Associate Agreement on request, plus specific, documented controls for access, encryption, logging, and physical security — the things that actually support your compliance.
When we provide managed IT, hardware, network infrastructure, or security systems to a healthcare client, we operate as a Business Associate under HIPAA — with obligations that follow, whether or not a BAA has been signed yet. Here's what that covers.
Much of our work keeps your systems on hardware you own, on-site — which changes the compliance conversation in your favor.
| Aspect | On-Premise, ArcAngel-Managed | Cloud-Only Vendor |
|---|---|---|
| Physical Control | You own the hardware and facility; we manage it locally | Vendor controls the data center; you rely on their security |
| Data Location | Stays on-site — no cloud transmission | Travels to vendor infrastructure |
| Audit Access | You can inspect systems in person | Limited to the vendor's own audit reports |
| Vendor Lock-In | Lower risk — you can migrate providers | Higher effort to export and migrate data |
| Control Customization | Configured for your specific requirements | Generally one-size-fits-all policy |
A BAA is required by law for any vendor handling PHI on your behalf — regardless of how much you trust them. We keep a BAA ready to sign, and we'd rather you ask for it up front than discover the gap later.
We implement and document the technical, physical, and administrative safeguards for the systems we manage, sign a BAA, and notify you promptly of any incident.
HIPAA compliance is your organization's legal responsibility. You determine what PHI can be discussed where, train your staff, and notify HHS and affected individuals if required. We can advise, but we can't carry that obligation for you.
We'll walk through what our services cover, what a BAA includes, and how our on-premise approach fits your compliance program.
Request a BAA