How it plays out on a deal
Health care deals, clinical trial partnerships and some insurance transactions put patient data in the room, sometimes only by accident inside a spreadsheet. If that data is protected health information, the room provider handles it as a business associate.
There is no official HIPAA certification. What a buyer needs is a signed business associate agreement and evidence of the relevant safeguards. Many sellers also prefer to redact or remove patient-level data before upload, which reduces the problem at the source.
What to check in a review or demo
- 1Whether the vendor will sign a business associate agreement, and on which plans.
- 2Which safeguards the vendor documents for health data, such as access logging and encryption.
- 3Whether redaction tools can remove patient identifiers before documents are shared.
HIPAA: where the reviewed providers stand
Based on the certifications and attestations each provider lists publicly, as recorded in our review data. Ask for the current report or certificate and check its scope before relying on it.
Yes (2)
No (16)
ElltySOC 2 Infrastructure9.2/10
iDealsSOC 2 and ISO 270019.1/10
DatasiteSOC 2 and ISO 270018.9/10
AnsaradaSOC 2 and ISO 270018.6/10
IntralinksSOC 2 and ISO 270018.6/10
FirmexSOC 2 and ISO 270018.5/10
DroomsSOC 2 and ISO 270018.3/10
SmartRoomSOC 2 and ISO 270018.2/10
DealRoomSOC 2 and ISO 270018.0/10
CapLinkedSOC 27.7/10
SecureDocsSOC 27.7/10
ShareVaultSOC 2 and ISO 270017.7/10
OnehubSOC 27.5/10
Venue by DFINSOC 2 and ISO 270017.2/10
DigifySOC 26.9/10
DocSendSOC 26.6/10
2 of 18 reviewed providers qualify. Each chip shows the provider's overall review score.
Read alongside
- RedactionBlacking out names, figures or personal details so they are gone from the shared copy itself, not just hidden behind a box.
- SOC 2An attestation from a licensed CPA firm, under AICPA rules, that a software company's security controls are designed well (Type I) or also worked over several months (Type II).
- Data processing agreement (DPA)The contract annex in which the room vendor promises how it will treat personal information on your behalf: safeguards, who else it may use, cross-border moves and deletion at the end.
- Audit trailThe room's running log of who did what and when.