# HIPAA-compliant?

**URL:** <https://community.open-emr.org/t/hipaa-compliant/13462>\
**Category:** Security\
**Created:** [January 10, 2020, 7:07pm UTC](https://community.open-emr.org/t/hipaa-compliant/13462 "2020-01-10T19:07:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JDD](https://community.open-emr.org/letter_avatar_proxy/v4/letter/j/db5fbb/32.png) [@JDD](https://community.open-emr.org/u/JDD)\
**Post date:** [January 10, 2020, 7:07pm UTC](https://community.open-emr.org/t/hipaa-compliant/13462/1 "2020-01-10T19:07:15Z")

</div>

Is OpenEMR HIPAA-compliant?

Does OpenEMR time-date stamp everything?

---

<div class="post-metadata">

**Author:** ![juggernautsei](https://community.open-emr.org/user_avatar/community.open-emr.org/juggernautsei/32/10764_2.png) [@juggernautsei](https://community.open-emr.org/u/juggernautsei)\
**Post date:** [January 11, 2020, 3:53pm UTC](https://community.open-emr.org/t/hipaa-compliant/13462/2 "2020-01-11T15:53:55Z")

</div>

@JDD  
OpenEMR is HIPAA compliant.

HIPAA simply states that everyone must use industry standard measures to protect patients private health information. But it is not only the software, it is the environment that you run the software within. If your environment is not secure, then the software is at risk. OpenEMR community of developers has vastly improved the internal security design of OpenEMR so that it exceeds the requirement of HIPAA to use industry standard security measures.
