Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
HIPAA Fundamentals

Point Tool or Operating Model? A Buyer's Question

Vendors use the words software and platform interchangeably, and neither tells you anything. What separates products is capability scope — how much connects to how much. Here is how to measure it at a demo.

Share
HIPAA compliance software vs HIPAA compliance platform - definitional and operational difference for independent practices

HIPAA Software vs HIPAA Platform: What's the Real Difference? (2026)

The two words get used interchangeably across the HIPAA vendor landscape. Some vendors call themselves software in one section of the website and a platform in another. From the buyer's side, the distinction feels semantic. From an OCR investigator's side, it matters — because the difference describes whether the practice has a working compliance program or a binder of documents that prove someone bought software once.

So the definitional question is the wrong one. The useful question is how to tell, at a demo, how much of a compliance program a product actually holds together — and how much your practice needs held together. That is a capability-scope question and it is measurable. The category map sets out how the market divides; this page is about sizing one product against your own operation.

The Definitional Difference

Products in this market sit on a range, and the two ends are worth naming even though most products are somewhere in between.

A point tool does one job. Risk analysis, or policy management, or training delivery. It is bought for that job, it is good at it, and it does not know about anything outside its own scope. This is not a criticism — a focused tool is usually better at its one job than a broad system is at the same job.

An operating model holds several of those jobs and lets them see each other. Adding a vendor is visible to the risk analysis. Offboarding a workforce member is visible to training records. The value is not that any individual function is better; it is that you stop being the integration layer between four tools that each think they are the whole program.

The practical test is one question, asked at a demo: when I record a change here, does anything anywhere else move? Add a vendor and watch. If nothing else in the product reacts, you are looking at a point tool — which may be exactly what you need, at a price that reflects it.

What determines which you should buy is not the vendor's vocabulary. It is how many of those jobs you are currently holding together in your own head, and what it costs you when the person holding them leaves.

The Three Operational Tests

Three questions distinguish software from platform with very little ambiguity. Asked of any vendor, they reveal which category the product actually belongs to regardless of which word the vendor uses in marketing.

Test 1: When you record a change, does anything else move?

This is the scope question made concrete. Add a vendor to the system and watch what happens elsewhere. Does the risk analysis gain an open finding? Does anything ask whether an agreement exists? Or does the vendor simply appear in a list?

Both behaviors are legitimate products. The second is a register, and a register is genuinely useful. The first is doing integration work you would otherwise do by remembering.

One caution that applies to every vendor in this market, ourselves included. A compliance product hosted elsewhere does not observe your environment. It cannot see that a junior admin extended your Microsoft 365 auto-logoff from fifteen minutes to ninety unless something is installed in your building or credentials have been handed over — and if a vendor claims otherwise, ask exactly which system, by what mechanism, and what it reads. Patient Protect does not do this. What any of these products knows about your estate is what a person entered.

Test 2: What happens between assessments?

A software product treats compliance as a series of events: an annual risk assessment, a periodic BAA review, a quarterly training cycle. Between events, the software is idle.

A platform treats compliance as a continuous function. Between events, it is monitoring. New vendor added to the practice? The platform flags the missing BAA. New staff member onboarded? The training is auto-assigned. A vendor agreement lapses? The platform surfaces it as work. What no compliance platform does is reach into the systems it is not part of — drift inside your EHR or your file storage is still something a person has to go and look at.

The HIPAA Security Rule expects compliance to be ongoing, not episodic. Software accommodates episodic; platforms support ongoing.

Test 3: What does the artifact look like during an audit?

When OCR shows up and asks for evidence, software produces what was last entered: the most recent risk assessment, the policies as they existed at the last review, the training records up to the last batch.

A platform produces a timeline: the assessment as of last week, the policies with version history, the training records with continuous attestation, the configuration monitoring logs that show controls were enforced continuously across the period under investigation. The artifact is a story rather than a snapshot.

This is the difference between being able to show what you did and asking an investigator to take your word for it. The snapshot can be argued. The continuous timeline cannot.

Why the Terms Get Conflated

Two reasons.

First, marketing. "Platform" sounds more substantial than "software." Vendors selling software-tier products call themselves platforms because the platform label commands premium pricing. Buyers can't distinguish from the website alone.

Second, the product matures. Most platforms started as software. A company that began with a risk assessment tool added BAA tracking, then training, then policy management, and at some point the integrated whole became a platform. Some made the leap to actually integrating the parts; some still have the same tools sitting in adjacent tabs without the cross-tool monitoring that defines platform-tier behavior.

The buyer-side answer is to not trust the label. Run the three tests above and see which category the product actually belongs to.

Pricing Patterns

The pricing model is often a tell.

Software tends to bill by feature. Per-module pricing, per-user pricing, training as a separate line item, BAA execution as a paid add-on. The practice composes the price based on what they're using.

Platforms tend to bill by outcome. A flat per-practice subscription that includes everything required for compliance, with tier breaks for practice size rather than feature mix.

The reason for the difference: software has a per-unit marginal cost (training seats, modules), so it bills per unit. A platform's marginal cost is largely independent of which modules the practice activates — the integration cost is the same — so it can bill by outcome.

Practices comparing quotes often see the software offer as cheaper headline. After per-seat training, per-module add-ons, and BAA fees, the platform offer is frequently cheaper at the practice's actual headcount. Always do the math at your real numbers.

When Software Is Enough

Honest answer: some practices genuinely need software, not a platform.

A solo practitioner with three vendors, no employees, no multi-site complexity, and personal time to spend on compliance work can deploy a risk assessment tool and a policy template library and operate the compliance program manually. Software supports this. A platform is overkill at this scale.

The break-even tends to be around 3-5 employees. Below that, the time cost of managing software is less than the price difference between software and platform. Above that, the time cost compounds — and the platform's automation pays for itself in clinician hours not spent on compliance administration.

The right question is not "which is better" but "where is my practice on that curve."

How to Read a Vendor's Marketing

Three patterns that distinguish actual platforms from software with platform-flavored marketing.

Ask what happens between assessments. Not what the product contains — what runs when nobody opens it. A vendor who can answer specifically is describing something real. A vendor who answers with a feature list is answering a different question.

Ask how the functions reference each other. Can the vendor describe, concretely, what adding a vendor or offboarding a person causes elsewhere in the product? This is the scope question and most vendors can answer it in one sentence if the answer is good.

Ask what the product knows that you did not tell it. For most compliance products the honest answer is nothing, and a vendor who says so is being straight with you. A vendor claiming environmental awareness should be able to name the system, the mechanism and what it reads.

None of these questions produces a verdict about a vendor's quality. They tell you where a product sits on the scope range, which is the thing the words software and platform were never going to tell you.

How Patient Protect Is Built

Run the three questions against us. What runs between assessments: findings reopen against changes you record, agreements move through a six-state lifecycle so an expiry becomes visible rather than discovered, and Compliance Advice regenerates daily. How the functions reference each other: recording a vendor, a workforce change or a system is visible to the risk analysis and to your score. What we know that you did not tell us: nothing about your estate. Patient Protect does not connect to Microsoft 365, Google Workspace, your EHR or your network, does not read their configuration, and cannot detect drift in them. Systems appear in the inventory because a person entered them.

That last answer is the one worth comparing across vendors, because it is the one most likely to be answered loosely.

Basic is $39/month per office, Pro is $99/month per office, month to month, with no per-seat training charge and no agreement add-on.

The question was never whether a product is software or a platform. It is how much scope you need held together, and whether a given product holds that much. Ask the three questions of every vendor you are considering, including this one, and the answers will be more useful than either word.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA