HIPAA Compliant EHR Hosting: Cloud EHR, Self-Hosted OpenEMR, or a Managed Server? (2026)
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/hipaa-compliant-ehr-hosting
Last updated: October 8, 2026
HIPAA compliant EHR hosting depends on who runs what: a cloud EHR vendor, your team, or a managed server host. Each route puts the Business Associate Agreement (BAA) with a different party. Self-hosting OpenEMR or OpenMRS leaves you running the server, database, backups and logs. For HIPAA compliant EHR hosting, choose a cloud EHR vendor if you want no servers. Teams with cloud engineers can self-host on AWS, Microsoft Azure or Google Cloud. Without them, a managed host runs the servers while you run the EHR. We sell managed hosting for the third route, so weigh our view as a disclosure.
TL;DR: Quick answer
HIPAA compliant EHR hosting needs a signed BAA with whoever stores or processes the record (45 CFR § 164.308(b)). Self-hosters in the cloud take the provider's BAA, which covers only its layer.
HHS says a cloud host storing only encrypted electronic protected health information (ePHI), without the key, is still a business associate (guidance reviewed December 23, 2022).
The Security Rule requires backup, disaster recovery and emergency mode plans (§ 164.308(a)(7)) and audit controls (§ 164.312(b)). The January 2025 proposed update is not final as of October 8, 2026.
ONC certification covers software, not hosting. OpenEMR 8 was certified on January 30, 2026, per the OpenEMR project.
Plan the exit first. DrChrono's terms (last modified October 5, 2026) say content may be kept 30 days after termination, then destroyed. Tebra's terms say it keeps data 60 days after termination.
Three ways to run an EHR or EMR, and who signs each BAA

The three routes are a vendor cloud EHR, self-hosting and a managed server. ONC prefers the term EHR and calls an EMR "a digital version of the paper charts" (ONC blog, January 4, 2011). Hosting duties are the same for both.
Route 1: a vendor cloud EHR. athenaOne, eClinicalWorks Cloud, DrChrono, Elation, Practice Fusion and Tebra host the record. The vendor is your business associate, and its BAA usually sits inside its terms. DrChrono's BAA is Exhibit A of its terms, and Tebra's is incorporated by reference. The vendor's cloud is its subcontractor; eClinicalWorks says its cloud runs on Microsoft Azure. Through Epic's Community Connect, independent groups use another organization's Epic EHR; ask that organization who signs your BAA. For the website and forms around it, see HIPAA hosting for small businesses.
Route 2: a self-hosted open-source EHR. Self-hosted OpenEMR and OpenMRS come with no BAA. On an office server, nobody signs and every safeguard is yours. In the cloud, you take the provider's BAA yourself. AWS offers it in AWS Artifact, per account or organization. Microsoft Azure includes it in its Product Terms by default. Google Cloud asks you to accept it. OpenEMR's AWS install includes "executing a Business Associate Agreement with AWS" (OpenEMR blog, July 21, 2026). Start with whether AWS is HIPAA compliant.
Route 3: managed hosting of your EHR server. The host signs your BAA for the servers and services it runs, and binds its own subcontractors (§ 164.308(b)(2)). HHS says a software company that accesses patient information "when troubleshooting" is a business associate. So an EHR support partner that can reach patient data signs its own BAA too. Our single-tenant ePHI hosting follows this model; our HIPAA business associate agreement guide lists the clauses.
On every route, HIPAA compliant EHR hosting comes down to who touches the servers and who signs.
HIPAA compliant EHR hosting options compared

The routes to HIPAA compliant EHR hosting differ in who signs, who patches the EHR and how you leave.
Question | Vendor cloud EHR | Self-hosted open-source EHR | Managed hosting of your EHR server |
|---|---|---|---|
Who signs your BAA | The EHR vendor, usually inside its terms | The cloud provider, for its layer; nobody for an office server | The host, for the servers and services it runs |
Who else signs | None for the EHR; the vendor's cloud is its subcontractor | Any support partner that touches patient data | Your EHR vendor or support partner, separately |
Who runs servers, OS and backups | The vendor | You | The host |
Who installs and upgrades the EHR | The vendor | You | You or your EHR support partner |
Audit logs | The vendor's EHR log; ask what you can export | You turn them on and review them | Host keeps server logs; the EHR log stays in the app |
Leaving | Export before termination; check retention days | You hold the database | You hold the database |
ONC certification | The vendor's CHPL listing | Only your exact release and setup | Hosting certifies nothing |
Best fit | Practices that want no servers | Teams with engineers who want to own the stack | Practices running their own EHR without a cloud team |
Choose HIPAA compliant EHR hosting by who will do the work. The middle column needs the most staff. Our managed vs self-managed HIPAA hosting guide weighs that choice. Unsure where you stand? Our 8-question HIPAA readiness check covers your BAA, backups and logs.
What does HIPAA require of an EHR's hosting?

For HIPAA compliant EHR hosting, the Security Rule requires a BAA, backups, access controls and audit controls, split among the host, the EHR and your practice. The HHS Office for Civil Rights (OCR) enforces the Security Rule, which sits in 45 CFR Part 164, Subpart C.
What the rule requires | 45 CFR section | Where it lives for an EHR |
|---|---|---|
A BAA with anyone who stores or processes ePHI | § 164.308(b); § 164.314(a) | Every business associate; the host binds its subcontractors |
Risk analysis and risk management | § 164.308(a)(1)(ii)(A) and (B) | The practice; the host supplies evidence |
Backup, disaster recovery and emergency mode plans (Required); plan testing (Addressable) | § 164.308(a)(7)(ii)(A) to (D) | Host runs and tests restores; practice owns the plan |
Facility access and media disposal | § 164.310(a)(1); § 164.310(d)(2)(i) | The data center, or your office for an office server |
Unique user IDs, emergency access, automatic logoff | § 164.312(a)(2)(i) to (iii) | EHR settings the practice manages |
Encryption at rest and in transit (Addressable) | § 164.312(a)(2)(iv); § 164.312(e)(2)(ii) | Host: disks, backups, TLS; EHR: its document encryption |
Audit controls and activity review | § 164.312(b); § 164.308(a)(1)(ii)(D) | EHR chart-access log, plus server and database logs |
Keep Security Rule documentation six years | § 164.316(b)(2)(i) | The practice and the host, each for its own; not a medical-record rule |
"Addressable" is not optional. Under § 164.306(d)(3), you implement it if reasonable and appropriate. If not, you document why and use an equivalent alternative measure if reasonable and appropriate. See HIPAA backup and disaster recovery for the contingency plan.
As of October 8, 2026, the January 2025 proposed Security Rule update is not final; the latest Unified Agenda targets July 2027. Until then, judge HIPAA compliant EHR hosting against today's rule; see the proposed HIPAA Security Rule update.
What must you run to self-host OpenEMR or OpenMRS?

Self-hosting means you, or a host you hire, run every layer under the EHR: server, database, TLS, backups, logs and patches.
OpenEMR. The project's wiki says OpenEMR 8 has ONC Ambulatory EHR Certification, dated January 30, 2026. Certified use depends on settings you apply, such as SHA512 password hashing, "Audit Logging SELECT Query" turned on and a FIPS-compliant TLS cipher. The latest release is 8.4.1, but the project called 8.2.0 the certified production release on July 21, 2026. So check ONC's Certified Health IT Product List (CHPL) for your exact release.
The data layer is covered in HIPAA compliant database hosting.
OpenMRS. Its Requirements page lists 8 GB of RAM for 1 to 10 users and 16 GB beyond that. Its docs require HTTPS and no default passwords. The project does not advertise HIPAA or ONC certification. In containers? See whether Docker is HIPAA compliant for the host settings.
ONC's HTI-5 proposal (December 29, 2025) would drop the privacy and security criteria in § 170.315(d); an alternative keeps the audit criteria. It is not final. A self-hosted EHR becomes HIPAA compliant EHR hosting only when someone owns every layer above.
How to choose HIPAA compliant EHR hosting: a 10-point checklist

To choose HIPAA compliant EHR hosting, check BAA scope, EHR ownership, exit terms and restores.
A BAA that names its scope. Ask which servers and services it covers (§ 164.308(b)), and list every vendor outside it.
A named owner for the EHR software. Who installs, patches and upgrades it? A support partner that touches patient data needs its own BAA.
Data export and exit. EHRs certified to § 170.315(b)(10) must export all the electronic health information the product can store. Check retention after termination: DrChrono, 30 days; Tebra, 60 days. HHS says a business associate may not block access over a payment dispute. Your EHR is part of your designated record set.
Backups and restore tests. Back up every database and the document store together; OpenMRS-based Bahmni's docs note that uploaded documents live outside the database. Test a full restore and time it.
Audit logs at both layers. Section 164.312(b) requires audit controls but sets no retention period. Check that the EHR logs chart views, not just edits.
Unique logins and MFA. The current rule does not name MFA, but MFA is a strong way to meet the authentication standard (§ 164.312(d)). See HIPAA MFA requirements.
Sizing for your workload. Size by users, database load and document storage, not record count alone. Ask how resizing works.
Interfaces. Labs, HL7 and FHIR feeds, clearinghouses and e-prescribing each have their own vendor. Controlled-substance e-prescribing needs an application with a third-party audit or a DEA-approved certification (21 CFR § 1311.300(a) and (e)).
Isolation, encryption and location. Ask for single-tenant servers, encryption, TLS and a region you choose. Some states add rules, such as Texas SB 1188 and Florida 408.051.
A downtime plan. The emergency mode plan is Required (§ 164.308(a)(7)(ii)(C)). Ask what architecture any uptime figure covers.
Run every route through this list before choosing HIPAA compliant EHR hosting.
Six mistakes practices make with EHR hosting

Avoid these six errors in HIPAA compliant EHR hosting.
Assuming the EHR vendor's BAA covers everything. It covers that vendor's own services, not a website, forms, email or SMS run by anyone else.
Treating certification as proof. OCR "does not endorse, certify, or recommend specific technology or products" (HHS cloud guidance). See why HIPAA certified hosting does not exist.
Running a self-hosted EHR outside a BAA. Amazon Lightsail, for example, is not on AWS's HIPAA Eligible Services Reference (last updated September 3, 2026).
Switching off audit logging for speed. OpenEMR says deployments not needing certification may leave two logging settings off "for better performance" (OpenEMR wiki). Weigh that against § 164.312(b).
Leaving defaults in place. Remove default passwords, installer scripts and open ports beyond 443.
Never testing a restore or planning the exit. Put both in your HIPAA risk analysis.
Where we fit, and when you may not need us

We sell this, so weigh it as a disclosure. HIPAA Compliant Hosting runs the managed-server route for HIPAA compliant EHR hosting: single-tenant AWS servers in your own AWS account and VPC. You choose the AWS region. On a Docker plan, we patch the operating system and Docker engine; your containers, including any database container, stay yours. Data is encrypted at rest with dedicated keys and in transit with TLS. Plans keep 7 days of snapshots with tested restores. A SIEM keeps server logs with a 90-day live window and a six-year tamper-proof archive. We sign the BAA within 24 hours of signup, before patient data moves; it covers only what we run.
Our managed plans for other platforms start at $229 a month. Docker plans, which run your own containers, start at $259 a month, in six sizes from Starter to Network. Starter has 4 GB of memory, half what OpenMRS lists for 1 to 10 users; Solo, with 8 GB, is $399 a month. Each plan includes 4 hours of migration and configuration in the first month, then $175 an hour, quoted first. OpenEMR's official Docker image can run on a Docker plan. We do not install, license, upgrade, support or certify EHR software; you or your EHR partner do. See what we run and what you run, and how HIPAA Docker hosting splits the work.
You may not need us. If your EHR is a vendor cloud product, you need no separate HIPAA compliant EHR hosting. With cloud engineers, AWS, Microsoft Azure or Google Cloud gives full control. To have someone run the EHR itself, use your EHR vendor or a support partner. Root access needs an Enterprise engagement. Each plan is one server in one AWS availability zone; hospitals needing failover can ask us to quote a multi-zone design. Need your host's SOC 2 report? HIPAA Compliant Hosting does not hold SOC 2 or HITRUST certification. Compare HIPAA compliant hosting providers, or take a quick HIPAA readiness assessment first.
Running your own EHR? Talk through your EHR server with an engineer; we usually reply within one business day. Bring your EHR name, user count, storage size, interfaces and recovery goals. Or see our current plans and the safeguards on our ePHI hosting on single-tenant AWS page. Whichever route you pick, HIPAA compliant EHR hosting needs every BAA signed.
Frequently asked questions
What is HIPAA compliant EHR hosting?
HIPAA compliant EHR hosting means running an electronic health record on servers covered by a signed BAA. The servers need access controls, audit logs and backups. Encryption and restore testing are Addressable, not optional. The host covers its layer; you own EHR users, settings and your risk analysis.
Do we need separate hosting if our EHR is cloud-based?
Usually not for the EHR itself, since the cloud EHR vendor hosts the record and signs your BAA. You need separate HIPAA compliant EHR hosting only when you run the EHR software yourself, such as OpenEMR. Your website and forms may still need hosting under a BAA.
Who should host our medical records system?
A cloud EHR vendor fits if you want no servers; AWS, Microsoft Azure or Google Cloud fits if you have cloud engineers. For HIPAA compliant EHR hosting without them, pair a managed single-tenant host with an EHR support partner. We sell hosting.
Is ONC certification the same as HIPAA compliance?
No. ONC certification tests what an EHR release can do. HIPAA looks at how your whole deployment protects patient data, so a certified EHR on a poorly run server can still fail. Check your release on ONC's CHPL.
Does the hosting BAA cover e-prescribing, labs, clearinghouses, email and SMS?
No. A host's BAA covers only the servers and services it runs. Your EHR vendor, e-prescribing gateway, clearinghouse, lab interface vendor, and email and SMS providers need their own BAAs. A lab receiving treatment orders is a provider, not your business associate (45 CFR § 160.103).
How much server does an EHR need?
Size by users and workload, not record count alone. OpenMRS lists 8 GB of RAM as its minimum for 1 to 10 users. Scanned documents drive storage growth, and audit logging adds load.
How long must we keep EHR records?
HIPAA sets no retention period for medical records; HHS says state laws generally govern. Security Rule documentation, such as your risk analysis, must be kept six years (45 CFR § 164.316(b)(2)(i)). The clock runs from creation or from when it was last in effect, whichever is later.
Can we get all our data out if we switch EHRs?
EHRs certified to 45 CFR § 170.315(b)(10) must export all the electronic health information the product can store, for one patient or all patients. The information blocking fees exception does not cover a fee for that export when you switch systems (§ 171.302(b)(3)).
Recap: HIPAA compliant EHR hosting
HIPAA compliant EHR hosting starts with who runs the software. A cloud EHR vendor signs your BAA and runs the stack. Self-hosting OpenEMR or OpenMRS makes every layer yours. A managed host runs the servers while you run the EHR. Whatever the route, collect every BAA, test restores and plan your exit.
General information, not legal advice. Vendor terms, project facts and rule status were checked on October 8, 2026; confirm with each vendor and check CHPL. Base safeguards on a documented risk analysis and consult counsel. We sell HIPAA compliant hosting. Reviewed October 2026.
Sources
HIPAA rules: 45 CFR § 160.103, § 164.306, § 164.308, § 164.310, § 164.312, § 164.314 and § 164.316.
Other rules: 45 CFR § 170.315 and § 171.302; 21 CFR § 1311.300.
HHS: cloud guidance; FAQs on record retention, blocking access and software vendors.
ONC: EMR vs EHR, HTI rules. Federal Register: Security Rule proposal, HTI-5 proposal. Unified Agenda: RIN 0945-AA22.
Cloud: AWS HIPAA, AWS eligible services, Azure HIPAA, Google Cloud HIPAA.
EHR vendors: DrChrono terms, Tebra terms, athenahealth, Elation, Practice Fusion, Epic and eClinicalWorks Cloud.
OpenEMR: certification, security, blog, releases, Docker image.
OpenMRS: requirements, security. Bahmni: backups.