For the person who signs the vendor assessment
What “HIPAA-compliant” scheduling software actually requires
HIPAA-compliant scheduling software is a phrase vendors use and the regulation does not. HIPAA governs protected health information. A staff schedule (who works Tuesday night, whose license expires in March) is an employment record, which 45 CFR 160.103 expressly excludes from PHI. A scheduling tool needs a Business Associate Agreement only when it creates, receives, maintains or transmits PHI on a covered entity's behalf.
From $99/month per location · No sales call · No card to start
At a glance
- HIPAA governs protected health information: data that identifies a person and relates to their health, care or payment for care. A staff schedule identifies employees and describes their work. Under 45 CFR 160.103 it is an employment record, which the definition of PHI expressly excludes.
- A scheduling vendor becomes a business associate only when it creates, receives, maintains or transmits PHI on a covered entity's behalf. If no patient data enters the product, there is no PHI to govern and nothing for a Business Associate Agreement to cover.
- The technical safeguards the Security Rule names in 45 CFR 164.312 — access control, audit controls, integrity, authentication, transmission security — are still the right questions to ask any vendor, PHI or not. MedAligna is built to them: row-level tenant isolation, an append-only audit log, session expiry, a two-factor policy for owners and admins, TLS and encryption at rest.
- The one real exception is home care. A client's name and address tied to the receipt of care IS protected health information, and a deployment that enters client records is a different conversation, had before setup.
- $99–$249 per location per month, published, with a 14-day trial and no card. Everything you store can be exported to CSV or JSON at any time, including after you leave.
Is a staff schedule protected health information?
No, and the reason is in the definition rather than in anyone's opinion. PHI is individually identifiable health information: data that identifies a person and relates to their health condition, the care they receive, or payment for it.
A roster identifies people and describes their work. It says that a nurse is on nights this week, that a medical assistant's certification runs out in May, that somebody worked forty-two hours in the last pay period. None of that relates to anybody's health, and the regulation goes further than silence on the point: 45 CFR 160.103 lists four categories that PHI expressly excludes, and the third is 'employment records held by a covered entity in its role as employer'. A hospital holds its nurses' licenses as an employer, not as a provider, and the records it keeps in that role are outside HIPAA's definition even though the hospital itself is a covered entity.
The one number in a scheduling product that comes from the patient side is the census: the count a nurse-to-patient ratio is computed against. Eighteen patients on the unit tonight is a figure, not a record. It identifies nobody, relates to nobody's condition, and it is the whole of what MedAligna knows about the people your staff look after.
Where the line genuinely moves
Some schedules do carry PHI. An operating-room board lists the patient against the surgeon and the procedure. An infusion chair plan with the patient's name on it, an appointment book, a visit schedule that pairs a caregiver with a named client at a home address: each of these ties an identifiable person to the receipt of care, and each is PHI from the first row. A product built to hold one of those must be bound by a BAA, whatever else it is called.
Where MedAligna stands
The facility roster (clinic, hospital unit, physician group, long-term care) never carries a patient. There is no field for one. The home-care visit module is the exception: it schedules caregivers to named clients, that record is PHI, and a deployment that enters client records is discussed with you before any client is typed in. The security page publishes the complete table of what is stored and whether each row is PHI.
When does a scheduling vendor need a Business Associate Agreement?
When it is a business associate, and the definition of that is the PHI, not the industry. A business associate creates, receives, maintains or transmits protected health information on a covered entity's behalf. A vendor that never touches patient data is not one, however many hospitals it sells to.
The BAA is the contract the Privacy Rule requires between a covered entity and each of its business associates. It sets out what the associate may do with the PHI, the safeguards it must keep, how it reports a breach and what happens to the data when the relationship ends. Every clause in it governs PHI. Where a vendor holds none, there is nothing for the agreement to govern, and signing one anyway documents an obligation about data that does not exist. This is why the honest answer to 'will you sign a BAA?' from a vendor that holds no PHI is 'there is nothing to put under one', followed by the inventory that proves it.
The inventory is the useful artefact, and it is what to ask any vendor for. A list of every category of data the product stores, row by row, with a yes or no against 'is this PHI'. A vendor that holds PHI should then be able to show its own agreements with the hosting, database and email providers that can touch it, because a business associate must bind its subcontractors the same way it is bound. A vendor that will sign your agreement but cannot show those has signed a promise it cannot keep.
The question that replaces the badge
There is no such thing as HIPAA certification. HHS issues none and recognises none; a shield on a website is a graphic. The two questions that do the badge's job are 'what PHI do you hold?' and, if the answer is anything but none, 'show me your subprocessor agreements and your risk analysis'. MedAligna's answer to the first is none for a facility roster, and the security page is written so that your reviewer can verify it rather than take it on trust.
What the Security Rule still expects, even without PHI
The technical safeguards in 45 CFR 164.312 are written for electronic PHI, and they are also simply what a system that holds your staff's records ought to do. A vendor that skips them because it holds no patient data is telling you how it treats the data it does hold.
The rule names five standards: access control, including unique user identification and automatic logoff; audit controls; integrity; person or entity authentication; and transmission security. MedAligna is built to each of them, and each is stated here precisely enough to be checked. Every person holds exactly one of four roles (owner, admin, scheduler, staff), and the screens that carry authority (invoices, API keys, webhook secrets, pay rates, the activity log) are refused to the wrong reader by a database policy that returns nothing, not by a menu that hides a link.
Tenant isolation is enforced by row-level security in Postgres rather than by application code remembering a filter: a query with no organization clause returns zero rows, not every row, and that case is tested on every commit by authenticating as one organization's administrator and querying another's staff table. Every change to a shift, an assignment, a credential or a permission is written to an append-only audit log that nobody, including the account owner and including us, can edit. Sessions expire, so a browser left open at the nurses' station does not stay signed in. An owner can require two-factor authentication of every owner and admin, and even an admin cannot switch that requirement off. All traffic is TLS; data at rest is encrypted by the database provider; uploaded license documents sit in private storage reachable only through short-lived signed links.
How credential tracking fits
A license number is an employment record, not PHI, but it is a government identifier and it is treated as one. Credentials live in a wallet that belongs to the staff member: she uploads the license and its expiry, her employer's copy follows, and the employer can read it but cannot edit or delete it. Only the holder can change what it says. The product refuses an assignment that needs a credential nobody current holds, screens every staff member against the federal OIG exclusion list, and keeps the history of each check with the date and list version a surveyor asks for.
How access controls fit
Staff see their own shifts, their own swaps and claims, their own time clock and wallet, and the published schedule for their department, read-only. Nothing about anybody else's pay, contract or paperwork. A scheduler builds and publishes the roster and cannot invite people, change a role, or read an invoice. The nav shows every tab to every role on purpose, and a screen that is not yours says so in words; the refusal underneath is a database policy, so a scheduler with a REST client is refused the same way as a scheduler with a browser.
What to ask the vendor, and what to ask yourself
The vendor assessment is the right instrument; the first question on it is usually the wrong one. 'Will you sign a BAA?' before 'What do you hold?' lets a vendor that stores nothing look evasive and a vendor that stores everything look compliant.
Ask for the data inventory first. Ask who can see a staff member's license document, and how a document is served. Ask what the audit log records and who can edit it. Ask whether the controls are described precisely enough to be demonstrated in the live product rather than attested on a PDF, and then ask to see one demonstrated. Ask what happens to your data when you leave: every staff record, schedule, credential and hour in MedAligna exports to CSV or JSON at any time, including after you cancel, and a lapsed account becomes read-only rather than deleted.
Then ask yourself whether the schedule you need to build carries a patient. If it does, you are shopping in a different category, one whose vendors must hold PHI under a BAA, and this page has told you what to ask them. If it does not, the compliance question for a scheduling tool is the Security Rule's list of safeguards applied to your staff's records, and the price of asking it is one email: send the questionnaire, and an engineer answers it in writing.
Where the BAA question actually comes up
The security questionnaire
The practice's compliance officer sends a forty-question vendor assessment. Question one is 'Will you sign a BAA?' and question two is 'List every category of PHI you will hold.'
The answer to question two is 'none', in writing, with the table of exactly what is stored: staff names, licenses, shifts, hours, census counts. Question one then answers itself, and an engineer answers the other thirty-eight.
The agency that schedules visits
A home care agency wants caregivers scheduled to named clients at their home addresses. That record ties a person to the receipt of care, which is PHI by definition.
The honest answer is that this deployment holds PHI and is handled as one. The agency talks to a person before any client is entered, and the visit module's separate access logging (every read, not only every write) is explained rather than discovered.
The vendor that sells a badge
A competitor's site carries a shield that reads 'HIPAA certified'. No such certification exists: HHS issues none and recognises none. The practice manager has no way to check what the badge means.
She asks the two questions above instead. A vendor that holds no PHI has nothing to certify; a vendor that does should produce its subprocessor agreements and its risk analysis, not a graphic.
How to assess scheduling software for HIPAA
Six questions for any vendor in this category, including us. The last one is the one where we are sometimes not the answer, and it says so.
01Does the product hold any protected health information at all?
This is the whole question, and it is answerable from a data inventory rather than a sales call. PHI is individually identifiable health information: a name tied to a diagnosis, a visit, a chart, a bill. A roster of who works Tuesday is not it.
Where MedAligna lands: No. MedAligna stores employment data (staff names, roles, licenses and their expiry, shifts, hours worked) and a census count per unit, which is a number that identifies nobody. The security page publishes the full table of what is and is not held.
02If it does hold PHI, will the vendor sign a BAA, and has it signed its own?
A business associate must bind its subcontractors the same way it is bound. A vendor that will sign your BAA but cannot show agreements with its hosting and database providers has signed a promise it cannot keep.
Where MedAligna lands: Because no patient data enters the facility roster, there is nothing to put under a BAA and the question does not arise for a clinic, a hospital unit or a physician group. Home-care client records are the exception and are discussed with you before any client is entered.
03Are the Security Rule safeguards built, whether or not they are legally required?
Unique user identification, automatic logoff, audit controls, encryption in transit and at rest: these are the controls in 45 CFR 164.312, and they are simply good engineering. A vendor that skips them because it holds no PHI is telling you how it treats the data it does hold.
Where MedAligna lands: Built and tested on every commit: one of four roles per person, tenant isolation enforced by row-level security in the database, an append-only audit log the account owner cannot edit, sessions that expire, two-factor authentication an owner can require of every owner and admin, TLS on every request and encryption at rest.
04Who can see a staff member's license document?
A scanned nursing license is not PHI, but it is a government identifier with a photograph on it, and a product that leaves it on a guessable URL has failed a test that has nothing to do with HIPAA.
Where MedAligna lands: The person it belongs to, and the managers with a credentialing job. Documents sit in private storage reachable only through short-lived signed links, the employer can read a credential and cannot edit or delete it, and only the holder can change what it says.
05Can you get your data out, in full, without asking?
Portability is a right for patients under HIPAA and a contractual question for everyone else. A vendor that holds your roster hostage over a billing dispute has turned a payment problem into a staffing one.
Where MedAligna lands: Every staff record, schedule, credential and hour exports to CSV or JSON at any time, including after you cancel. A lapsed account becomes read-only; nothing is deleted and nothing is hidden.
06Does your schedule need to carry patient names?
Some scheduling genuinely does: an operating-room board, an infusion chair plan with the patient on it, an appointment book. That schedule is PHI from the first row, and it needs a product built to hold PHI under a signed BAA.
Where MedAligna lands: That is not this product. MedAligna schedules staff, not patients, and a facility roster never carries a patient name. If the thing you need to schedule is the patient, we will say so and point you at the right category.
What is PHI, a covered entity, a business associate, or a BAA?
The terms as the regulation defines them, because the vendor assessment is usually written by somebody who knows them and answered by somebody who does not.
- Protected health information (PHI)
- Individually identifiable health information held or transmitted by a covered entity or business associate, in any form. 45 CFR 160.103 excludes employment records held by a covered entity in its role as employer, which is what a staff schedule is.
- Covered entity
- A health plan, a health care clearinghouse, or a health care provider that transmits health information electronically for a standard transaction. A hospital, a clinic and a physician practice are covered entities; the vendor that builds their rota is not one.
- Business associate
- A person or organization that creates, receives, maintains or transmits PHI on a covered entity's behalf, other than as a member of its workforce. The test is the PHI, not the industry: a vendor that never touches patient data is not a business associate, whoever its customers are.
- Business Associate Agreement (BAA)
- The written contract the Privacy Rule requires between a covered entity and each business associate, setting out permitted uses of PHI, safeguards, breach reporting and what happens to the data at the end. It governs PHI; where there is none, there is nothing for it to govern.
- Security Rule technical safeguards
- The five standards in 45 CFR 164.312: access control (including unique user identification and automatic logoff), audit controls, integrity, person or entity authentication, and transmission security. Required for electronic PHI, and worth asking about for any system that holds your staff's records.
- Employment record
- A record a covered entity holds about a person as their employer rather than as their provider: the roster, the license on file, the hours worked, the time-off balance. Expressly outside the definition of PHI, even when the employer is a hospital.
- Census
- The number of patients or residents on a unit at a point in time. A ratio rule is computed against it. It is a count, not a record: eighteen identifies nobody.
Questions people actually ask
- Is staff scheduling software subject to HIPAA?
- Only if it holds protected health information. A staff roster is an employment record, which 45 CFR 160.103 expressly excludes from the definition of PHI, so a scheduling tool that stores who works when, which licenses they hold and how many hours they worked is holding employment data rather than PHI. A schedule that names patients (an operating-room board, an appointment book, a home-care visit plan) is PHI and the tool holding it must be bound by a BAA.
- Does MedAligna need to sign a BAA?
- For a clinic, a hospital unit, a physician group or a long-term care facility, no patient data enters the product, so there is no PHI for a Business Associate Agreement to govern and nothing to put under one. The security page lists every category of data stored and whether it is PHI. Home-care client records are the exception, and that deployment is discussed with you before any client is entered.
- What does HIPAA actually require of a scheduling tool?
- If the tool holds PHI, the Privacy Rule requires a BAA and the Security Rule requires administrative, physical and technical safeguards, including the five technical standards in 45 CFR 164.312: access control with unique user identification and automatic logoff, audit controls, integrity, authentication and transmission security. If it holds no PHI, the regulation requires nothing of it, and those same safeguards are still the right questions to ask about how it treats your staff's records.
- What about home-care client records?
- A client's name and address tied to the receipt of care is protected health information, and MedAligna's home-care visit module holds exactly that. It is a different deployment from a facility roster: every read of a client record is logged separately, not only every change, and the conversation about how it is handled happens with you before setup rather than after.
- Are staff license numbers and certifications PHI?
- No. A nursing license, a BLS card or an MA certification is a record the employer holds in its role as employer, which the definition of PHI excludes. It is still a government identifier with a photograph on it, so documents are kept in private storage behind short-lived signed links, the employer can read a credential but cannot edit or delete it, and only the person it belongs to can change what it says.
- What does it cost, and how do we try it?
- $99, $149 or $249 per month per location, published on the pricing page, with a 14-day trial of every feature and no card. Setup is self-serve: import staff from a spreadsheet, set rules once, publish. Hours export as a timesheet CSV that Gusto and ADP import, schedules sync to Google, Outlook and Apple calendars, and anything stored can be exported to CSV or JSON at any time, including after you leave.
- Who answers our security questionnaire?
- An engineer, in writing. Send it to the address on the security page. Every control described on this site is real, testable and stated precisely enough to be demonstrated in the live product rather than attested in a PDF, and if your reviewer thinks something here is wrong, that is a genuinely useful email to receive.
Sources
- 45 CFR § 160.103 — Definitions (protected health information; business associate) — Legal Information Institute, Cornell Law School (e-CFR mirror), checked 2026-10-09.
- 45 CFR § 164.312 — Technical safeguards — Legal Information Institute, Cornell Law School (e-CFR mirror), checked 2026-10-09.
Related
Nothing to put under a BAA, and everything to show
Send the questionnaire, or open the live demo and look for a patient field. Fourteen days free, no card, no sales call.