Skip to content
MegAligna

Product

HIPAA compliant practice management software

HIPAA compliant practice management software means a vendor that signs a business associate agreement and implements the required safeguards: encryption in transit and at rest, role-based access, audit logging, multi-factor authentication and backup. MegAligna signs an agreement with every customer and shows each safeguard as a control inside the product.

What buyers check first

Do you sign a business associate agreement?
Yes, with every customer, as part of signup rather than as a separate manual process. You can download the signed copy at any time from the compliance area of the product.
Can software be certified for HIPAA?
No. HIPAA has no certifying body and no certification program, so no product can hold that credential, and a vendor claiming one is describing something that does not exist. What a vendor can show you is a signed business associate agreement, a set of implemented safeguards, and evidence that those safeguards work.
What about your infrastructure provider?
Our database and storage run on a provider we hold a business associate agreement with, under their HIPAA configuration. That relationship is sub-processor status. Their audit reports are theirs and do not describe our application, so we do not present them as ours.
Can we see what a staff member accessed?
Yes, self-serve rather than by support ticket. The Compliance Center reports what a chosen staff member did over a chosen number of days, including the records they opened. Querying the other way round — everyone who touched one patient — and exporting the report are not built yet.

HIPAA safeguards and the control behind each one

  • Roadmap · M6

    Business associate agreement

    Onboarding will not treat a practice as live for patient data until the agreement step is complete. Electronic signature and countersigned PDF are not built yet — the agreement is still exchanged with us directly.

  • Included

    Encryption in transit and at rest

    Transport security enforced on every connection by a two-year HSTS policy; data encrypted at rest by the platform. No patient data appears in any URL — record addresses carry an opaque identifier and nothing else.

  • Included

    Role-based access, enforced in the database

    Access rules live in database row-level policies rather than in screen logic, so a permission cannot be bypassed by calling the API directly. Technicians see their own assigned clients only, and read back only the notes they wrote.

  • Included

    Audit log

    Append-only, hash-chained per practice, written by a database trigger rather than by application code, so it cannot be skipped. Reads are events in their own right: opening a chart, opening a note and pulling billing history each write a row.

  • Included

    Multi-factor authentication for staff

    Time-based one-time codes, enrolled per staff account from Settings. Offboarding takes effect on the departing user's next request rather than their next sign-in: the token already in their browser stops resolving to your practice immediately. Signed-in devices also sign out after an idle period the practice sets.

  • Included

    Patient right-of-access export

    A full per-patient record export, as JSON for another system to ingest and as a readable HTML document for the family, with the request written to the audit log — so responding to a records request inside the required window is one action.

Case management, client management, patient management

Buyers searching for this substitute those three terms for “practice management” more or less freely, and the substitution is not sloppiness — it reflects what the organization calls the person it serves. A behavioral health agency has clients, a paediatric clinic has patients, a school-based or state-programme provider has cases.

The compliance question underneath is identical in all three, and it is worth stating plainly: HIPAA obligations follow the protected health information, not the vocabulary. If a system stores identifiable health information on behalf of a covered entity, the vendor is a business associate, must sign an agreement, and must implement the safeguards above. Whether its screens say “client” or “patient” changes nothing about that.

What the terms do signal is scope, and there the answer differs. This is practice management software: scheduling, intake, clinical documentation, charge capture and billing for a healthcare practice. It is not general-purpose case management for a social services agency, and it is not a CRM with a compliance wrapper — see the healthcare CRM page for where that boundary sits.

A practice that needs the first will find the vocabulary adapts. An organization that needs the second should evaluate something else, and it is cheaper to establish that now than after a trial.

What we do not claim

We do not hold ONC health IT certification. Physician practices billing Medicare may need a certified system for certain programs, while behavior-analytic and cash-pay practices generally do not. If certification is a requirement in your setting, MegAligna is not the right system, and that is worth establishing before a trial rather than during one.

Compliance controls you can open and check

Each safeguard above corresponds to a screen the practice owner can open rather than a statement to be taken on trust. The product exposes the audit log, per-user access and multi-factor status, a quarterly access-review flow, workforce training records and one-click offboarding as ordinary parts of the interface.

That matters at audit time: a HIPAA risk assessment asks what you implemented and how you know it works, and both answers come from screens you can print.

The controls behind these claims are itemised on the security and data commitments page, and the surfaces patients themselves touch are covered in the patient portal and intake.

Review the compliance controls in a trial

14 days, no card required. Use made-up patients while you evaluate — real patient information waits until a business associate agreement is in place.