CareCloud is a cloud-based healthcare technology platform offering electronic health records, practice management, revenue cycle management, patient engagement, telehealth, and clinical documentation tools.
Is CareCloud HIPAA compliant? Yes, based on our research, CareCloud can be HIPAA compliant when the applicable services within certain conditions.
What changed this year?
As of July 2026, our review did not identify any publicly disclosed changes that ended CareCloud’s BAA availability or narrowed the HIPAA scope of its services.
CareCloud updated its website privacy policy on May 13, 2026. However, that policy describes the personal information collected through CareCloud’s public website and does not replace or explain the company’s customer BAA.
CareCloud also disclosed a cybersecurity incident in March 2026. The incident temporarily affected functionality and data access in one of its six electronic health record environments for approximately eight hours. CareCloud said the affected environment stored patient information and that it was investigating whether anyone had accessed or exfiltrated data.
The disclosure does not state that CareCloud stopped signing BAAs or ceased offering HIPAA-regulated services. Nevertheless, healthcare organizations should consider the incident when conducting vendor risk assessments and review the breach-notification and security provisions in their individual agreements.
Will CareCloud sign a business associate agreement (BAA)?
Yes, CareCloud makes a business associate agreement available to clients.
One of CareCloud’s publicly available customer agreements states, “Company shall make available to Client a Business Associate Agreement (‘BAA’) which complies with the requirements of HIPAA.”
CareCloud also states in its 2026 annual report that it is a business associate of its healthcare customers because of its contractual obligations to provide services for them.
However, CareCloud does not appear to publish a universal customer BAA covering every product. Prospective customers should obtain the latest BAA directly from CareCloud and confirm that it covers every service, integration, and CareCloud product their organization intends to use.
What does the CareCloud BAA cover?
CareCloud does not publish the complete text of its standard customer BAA, so its exact coverage cannot be independently reviewed through public terms.
CareCloud’s HIPAA compliant cloud storage page states, “CareCloud’s cloud-based healthcare software is HIPAA compliant, meeting government security standards for data transmission and storage.”
Based on CareCloud’s public HIPAA materials and regulatory filings, its contractual HIPAA obligations cover:
- The use, storage, transmission, and disclosure of PHI when providing contracted services
- Administrative, physical, and technical safeguards for electronic PHI
- Encryption of customer data during transmission
- Controls intended to prevent unauthorized access
- Notification obligations following breaches of unsecured PHI
- Business associate agreements with third parties that receive access to PHI
- CareCloud’s direct responsibilities as a business associate under HIPAA and the HITECH Act
CareCloud’s HIPAA FAQ also notes that customers remain responsible for their own HIPAA compliance. Therefore, signing a BAA does not automatically make every use of CareCloud compliant. Healthcare organizations must configure and use the platform in accordance with HIPAA and the terms of their agreement.
What does the CareCloud BAA exclude?
CareCloud’s public materials do not identify a comprehensive list of products, data types, or activities excluded from its BAA.
However, CareCloud’s 2026 annual report ties its business associate status to its “contractual obligations to perform certain services” for healthcare customers. It means organizations should not assume that the BAA automatically covers every CareCloud product, optional feature, third-party integration, developer application, or service not identified in their contract.
CareCloud’s public website privacy policy also applies to information collected through carecloud.com and should not be treated as a substitute for the BAA governing PHI processed through CareCloud’s healthcare services.
Customers should review the executed BAA and service agreement to confirm which services are covered, what uses of PHI are permitted, which subcontractors may process PHI, and what happens to PHI when the agreement ends.
Conclusion
CareCloud can be HIPAA compliant because it makes a BAA available and publicly identifies itself as a business associate of its healthcare customers. However, organizations should obtain and review CareCloud’s current BAA, confirm that all intended products and integrations are covered, and consider the company’s March 2026 cybersecurity incident as part of their vendor risk assessment.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of the agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
The Health Insurance Portability and Accountability Act sets national standards for protecting the privacy and security of certain health information, known as PHI.
HIPAA is designed to protect the privacy and security of individuals’ health information and ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities and business associates.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include health plans, healthcare clearinghouses, and healthcare providers that conduct certain standard electronic transactions. It also applies to business associates that perform certain functions or activities involving PHI on behalf of covered entities.
