Questions? Talk to a Real Person via our Live Chat
Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)
By Alicia Kelley, , HIPAA Blog, Resources, Vibe Coding

Is Windsurf HIPAA Compliant? The Vibe-Coding Tool athenahealth Actually Uses (2026)

Short answer: Windsurf has the strongest HIPAA story of any AI coding tool examined in this series — and it’s the only one with a named healthcare customer to back it up. Windsurf’s own security documentation states plainly that it will “entertain a Business Associate Agreement (BAA) to confirm HIPAA compliance” for significant implementations. And... Continue reading
Is Slack HIPAA Compliant?
By Alicia Kelley, , HIPAA Blog, HIPAA Compliance, Resources

Is Slack HIPAA Compliant?

Slack can support HIPAA compliance — but only on Business+ and Enterprise+ plans, and only when properly configured. Free and Pro plans do not support HIPAA compliance, as confirmed on Slack’s own pricing page. Even on qualifying plans, HIPAA compliance is not automatic — it requires enabling specific security controls, executing a Business Associate Agreement... Continue reading
HIPAA Compliant File Sharing: What Healthcare Organizations Need to Know in 2026
By Alicia Kelley, , HIPAA Blog, Resources, sFTP

HIPAA Compliant File Sharing: What Healthcare Organizations Need to Know in 2026

In plain terms:: File sharing can be HIPAA compliant — but only when it uses a solution that encrypts data in transit and at rest, provides audit logging, enforces access controls, and is backed by a signed Business Associate Agreement (BAA). Standard file sharing tools like email attachments, consumer Dropbox, Google Drive through a personal... Continue reading
HIPAA Compliant Fax: What Healthcare Providers Need to Know in 2026
By Alicia Kelley, , HIPAA Blog, HIPAA Fax, Resources

HIPAA Compliant Fax: What Healthcare Providers Need to Know in 2026

Faxing can be HIPAA compliant — but only when done through a secure cloud fax service that signs a Business Associate Agreement (BAA) and encrypts transmissions. Traditional analog fax machines, consumer internet fax services, and free online fax tools are not HIPAA compliant. Using a non-compliant fax method to transmit protected health information (PHI) is... Continue reading
HIPAA 2026 Security Rule Updates: What Healthcare Organizations Need to Do Now
By Alicia Kelley, , HIPAA Blog, Resources, Security

HIPAA 2026 Security Rule Updates: What Healthcare Organizations Need to Do Now

The HIPAA compliance landscape is changing. As cyberattacks against healthcare organizations continue to increase, federal regulators are pushing for stronger security requirements designed to better protect electronic protected health information (ePHI). The proposed HIPAA Security Rule updates could eliminate many of the compliance loopholes organizations have relied on for years while introducing mandatory encryption, annual... Continue reading
Find Reliable HIPAA sFTP Solutions with Exceptional Support for Medical Offices
By Alicia Kelley, , HIPAA Blog, Resources, sFTP

Find Reliable HIPAA sFTP Solutions with Exceptional Support for Medical Offices

Healthcare organizations exchange sensitive patient information every day. From medical imaging files and insurance records to lab reports and billing data, healthcare teams constantly move protected health information (PHI) between providers, labs, insurers, and third-party vendors. Without secure transfer methods in place, those file exchanges can expose organizations to major HIPAA compliance risks. That is... Continue reading