Skip to main content

Is ExpressionEngine HIPAA Compliant? EE 7, Packet Tide, and the Settings That Matter (2026)

By Joseph Abear ·
Banner asking whether ExpressionEngine meets HIPAA: EE 7 ships TOTP MFA, CSRF protection, and login lockout, but lacks field encryption and an entry edit log, and Packet Tide signs no BAA, so the host must

Last updated: October 6, 2026

ExpressionEngine is not HIPAA compliant on its own, and no CMS is. HIPAA regulates the organizations that handle patient data, not the software they install. An ExpressionEngine HIPAA compliant site needs a host that signs a Business Associate Agreement (BAA). Packet Tide, which owns EE, sells software, not hosting, so it signs no BAA. EE 7 has two-factor login and CSRF protection built in, but no field encryption and no log of who edited which entry. And EE 6 reaches end of life on December 31, 2026. We sell HIPAA compliant hosting, so weigh our advice accordingly.

TL;DR: Quick answer

  • ExpressionEngine is open-source PHP software under the Apache License 2.0, owned by Packet Tide. As of October 6, 2026, version 7.5.27, released September 21, 2026, is the newest release and carries security fixes.

  • Packet Tide signs no BAA, so your host is the business associate under 45 CFR § 164.308(b). As of October 6, 2026, Liquid Web's EE plans list no BAA, while its HIPAA line and Nexcess offer one.

  • Against 45 CFR § 164.312, EE 7 ships TOTP multi-factor login, default CSRF protection, bcrypt hashing, and login lockout. It has no field encryption, no entry edit log, and no private uploads.

  • Per the EE 7 docs, re-checked October 6, 2026, cookie_secure is off by default. EE has no force-HTTPS setting, and its Backup Utility writes a plaintext SQL file.

  • Core allows one control panel user. An ExpressionEngine HIPAA compliant site with staff needs Pro, $249 as of October 6, 2026, for unique logins under 45 CFR § 164.312(a)(2)(i).

Is ExpressionEngine HIPAA compliant? The three-layer answer

Three layers of a HIPAA ready ExpressionEngine site: the BAA that Packet Tide does not sign, the server safeguards your host runs, and the technical safeguards EE 7 meets only in part

An ExpressionEngine HIPAA compliant system has three layers, and each needs an owner. The first is the contract. Under 45 CFR § 164.308(b), any vendor that stores protected health information (PHI) for you must sign a BAA first. See our HIPAA business associate agreement guide. The second layer is the server: physical safeguards, disk encryption, firewalls, backups, and patches. The third layer is your EE site and team. It covers the 45 CFR § 164.312 technical safeguards, which EE meets only in part. It also covers the risk analysis under 45 CFR § 164.308(a)(1), policies, training, and vendor BAAs. Our HIPAA risk analysis guide shows what the analysis must cover.

Packet Tide, LLC owns and develops ExpressionEngine, which most users call EE. EllisLab built it in 2002, and Packet Tide has run it since October 2019. The core uses the Apache License 2.0, not MIT, and Pro is a separate paid license. EE runs on a bundled legacy CodeIgniter core, so our CodeIgniter HIPAA compliant guide covers the framework underneath. So the ExpressionEngine HIPAA compliant answer turns on your host.

What ExpressionEngine 7 gives you for the HIPAA technical safeguards

Five HIPAA technical safeguards mapped to ExpressionEngine 7: roles, six logs, revisions, TOTP MFA, and cookie settings it provides, and the Pro license, Logit or Informer, host backups, and HTTPS you still add

Here is how EE 7 maps to 45 CFR § 164.312. The last column is what an ExpressionEngine HIPAA compliant site adds.

Safeguard (45 CFR § 164.312)

What ExpressionEngine 7 provides

What you still add

Access control, (a)

Member roles, per-channel and per-template access, and Role Groups. Core allows one control panel user.

ExpressionEngine Pro for separate staff logins, and private file storage outside EE

Audit controls, (b)

Six logs, including CP Access, plus entry versioning. No log of who edited an entry.

Logit ($45) or Informer ($15), plus server logs shipped off the server

Integrity, (c)

Entry revisions, CSRF checks on all requests, XSS filtering of uploads, and Strip image metadata

Encrypted, tested backups at the host

Person or entity authentication, (d)

TOTP MFA, optional or required per role, bcrypt hashing, and lockout after more than four failed logins

A Strong password policy and MFA required on every role with control panel access

Transmission security, (e)

Cookie Secure (off by default), Cookie HttpOnly (on), SameSite Lax, and the HTTP Header add-on

An HTTPS redirect and HSTS at the web server, and SMTP over TLS

Three gaps decide the ExpressionEngine HIPAA compliant question. First, EE has no field, column, or database encryption for entries, members, or form data. Disk and database encryption at rest and in transit is the host's job. Second, no built-in log records which user viewed or edited which entry. Audit logging here means an add-on plus server logs kept under a BAA. Logit and Informer were last updated about two years ago, so test them on 7.5.x. Third, a shared Core login breaks unique user identification, so a clinic with staff editors needs Pro.

Does Packet Tide, Liquid Web, or Nexcess sign a BAA?

Who signs a business associate agreement for an ExpressionEngine site: Packet Tide does not, Liquid Web's EE plans list none, its HIPAA line and the Nexcess compliance tier offer one, and other hosts must be asked directly

Of the hosts below, only the Liquid Web and Nexcess HIPAA lines say they sign one, per each company's pages on October 6, 2026. An ExpressionEngine HIPAA compliant build settles this first.

Packet Tide: no. Packet Tide sells EE licenses, not hosting. Its site had no HIPAA or BAA text on October 6, 2026. It never stores your PHI, so it is not your business associate.

Liquid Web: not on its EE plans. Liquid Web calls itself the only official ExpressionEngine hosting partner. Its EE plans run from $64 to $1,128 per month. The plan table lists PCI compliance but no BAA. Its HIPAA hosting is a separate dedicated-server line with a signed BAA, estimated at $600 to $1,000+ per month.

Nexcess: yes, on its compliance tier. Nexcess and Liquid Web are one company. Nexcess lists BAA coverage for HIPAA workloads on its compliance tier. An April 22, 2026 press release says Nexcess "executes BAAs with qualifying healthcare clients." Neither page names EE, so confirm support before you sign.

Other hosts. Cloudways sells EE hosting through a Composer install, but its Trust Center lists HIPAA only for partner clouds and makes no BAA statement. On October 6, 2026, Arcustech's site blocked our checks and Hosting.com's site had no HIPAA or BAA page, so ask them directly. More hosts are compared in HIPAA compliant app hosting.

Which ExpressionEngine settings are off or missing by default?

These defaults come from the EE 7 docs and the 7.5.27 installer, re-checked October 6, 2026. An ExpressionEngine HIPAA compliant setup changes most of them.

Setting

Default

Change for PHI

cookie_secure

n, off

y, so cookies travel only over HTTPS

cp_session_length

3600 seconds, 1 hour

Shorten to match your logoff policy

website_session_length

7200 seconds, 2 hours

Shorten for member and patient logins

expire_session_on_browser_close

n

y

allow_multi_logins

y on a fresh install

n, so each account has one session

password_security_policy

Basic

Strong, with a minimum length

Multi-factor authentication

Optional unless a role requires it

Required on every role with control panel access

Force HTTPS

No such setting

Redirect and HSTS at the web server

Upload directories

Always public URLs

Keep PHI files out of EE uploads

Control panel Backup Utility

Plaintext .sql file in system/user/cache

Do not use for PHI; back up at the host

disable_csrf_protection

n, so CSRF protection is on

Leave it unset

The session keys are the ExpressionEngine HIPAA compliant fix most teams miss. EE has no idle-logout screen, so the only timeout controls are cp_session_length and website_session_length in system/user/config/config.php. Set cookie_secure to y there too, once the whole site runs on HTTPS. Never set disable_csrf_protection, which turns off CSRF checks. Those checks guard against cross-site request forgery (CSRF), where another site tricks a signed-in browser into sending a request its user never intended.

Which ExpressionEngine versions are safe to run?

Timeline of 2026 ExpressionEngine security releases from 7.5.20 to 7.5.27, the newest as of October 6, 2026, with version 8.0 targeted for EEConf on October 7 to 8, 2026, and EE 6 end of life on December 31, 2026

As of October 6, 2026, the newest release is ExpressionEngine 7.5.27, published September 21, 2026, and GitHub lists no 8.x release. In August 2026, Packet Tide said it aimed to release 8.0 around EEConf, October 7 to 8, 2026. Check the changelog for anything newer before you upgrade. For an ExpressionEngine HIPAA compliant site, these dates matter:

  • EE 6 reaches end of life on December 31, 2026. After that it gets no updates of any kind, security fixes included.

  • EE 7 has no published end-of-life date as of October 6, 2026.

  • A current Pro license covers the move to EE 8 at no extra fee, per Packet Tide's September 14, 2026 post.

  • Run PHP 8.2 or 8.3, which the EE 7 docs support.

Through October 6, 2026, five 2026 releases carried security fixes:

Version and date

What the changelog says

7.5.27, September 21, 2026

Important security updates; SQL queries and Search and Replace now require a Super Admin

7.5.26, July 22, 2026

Important security updates, with no details published

7.5.25, June 23, 2026

Important security updates, plus stronger encryption keys

7.5.24, June 8, 2026

Important security updates, plus stricter upload filename checks

7.5.20, February 26, 2026

Important security updates, with no details published

As of October 6, 2026, Packet Tide publishes no CVE ids or severity scores, and GitHub lists no advisories. So your risk analysis should treat every "important security updates" release as required. An ExpressionEngine HIPAA compliant site applies each one within days.

The 8 settings that make an ExpressionEngine site HIPAA-ready

Checklist of eight ExpressionEngine settings for patient data: upgrade, unique logins with MFA, secure cookies and HTTPS, shorter sessions, strong passwords, PHI kept out of entries, change logs, and host backups

We check these first in every ExpressionEngine HIPAA compliant review.

  1. Upgrade. Run 7.5.27 or later. Sites on EE 6 must move before December 31, 2026.

  2. Give every user a login, then require MFA. Buy Pro so each staff member has their own account. Then require MFA on every role with control panel access, Super Admin first.

  3. Secure the cookies and force HTTPS. Set cookie_secure to y and keep cookie_httponly on. Force HTTPS at the web server, with HSTS.

  4. Shorten sessions. Lower cp_session_length and website_session_length, set expire_session_on_browser_close to y, and set allow_multi_logins to n.

  5. Tighten passwords. Set password_security_policy to Strong, raise pw_min_len, turn off dictionary words, and keep password_lockout on.

  6. Keep PHI out of entries, or protect it at the host. Avoid storing PHI in Channel Form or Freeform entries. Where you must, encrypt at the disk layer and purge old entries on a schedule.

  7. Log who changed what. Review the CP Access log, add Logit or Informer for entry changes, and ship logs to a store under a BAA.

  8. Back up at the host, not in EE. Never run the Backup Utility on a PHI database. Use encrypted backups at the server layer instead.

Item 2 is covered in HIPAA MFA requirements. Item 4 is the automatic logoff rule in 45 CFR § 164.312(a)(2)(iii), explained in HIPAA automatic logoff. With these eight done, the ExpressionEngine HIPAA compliant work inside your site is mostly done.

Where ExpressionEngine sites leak PHI

Six places an ExpressionEngine site can leak patient data: Channel Form and Freeform submissions, the Email log, public upload directories, the Backup Utility SQL file, debug output, and the Search log

An ExpressionEngine HIPAA compliant review finds most leaks in forms, logs, files, and backups.

  • Channel Form and Freeform submissions. Channel Form saves every front-end submission as an entry, guests included. Freeform stores submissions and emails them, in plain text unless SMTP uses TLS.

  • The Email log. log_email_console_msgs is on by default and keeps the full text of Email Console messages.

  • Public upload directories. Every upload directory has a public URL, so a patient document can be fetched by anyone with the link.

  • The Backup Utility's SQL file. It lands unencrypted in system/user/cache, which may sit inside the web root.

  • Debug output and the Developer log. Debug output shows SQL queries and submitted form data, and debug set to 2 shows errors to all users.

  • The Search log and add-ons. enable_search_log is on by default and records each search term, even a patient's name. Add-ons that send data out need their own BAA.

The common failure: a clinic's Freeform intake form puts each submission in the database and a staff inbox. An ExpressionEngine HIPAA compliant fix splits the work by layer. Form and log settings are your layer. Disk encryption, the log store, and backups are the host layer, which you can hand off. A mail relay or SMS service outside your host needs its own BAA. Intake form rules are in HIPAA compliant forms. Backups copy every leak above, so see HIPAA backup and disaster recovery.

Who signs the BAA for an ExpressionEngine site, and what does it cost?

Four hosting routes for an ExpressionEngine site compared by price and who signs the BAA: Liquid Web EE plans with no BAA, Liquid Web or Nexcess compliance hosting, DIY on AWS or DigitalOcean, and managed hosting from us

An ExpressionEngine HIPAA compliant budget starts with the host that signs the BAA. Figures are as published on October 6, 2026.

Route

Published price

Who signs the BAA

What you still own

Liquid Web EE plans

$64 to $1,128 per month

No one; no BAA on the plan page

Not a PHI route as listed

Liquid Web HIPAA dedicated, or the Nexcess compliance tier

Liquid Web estimates $600 to $1,000+ per month; Nexcess lists its own tier price

Liquid Web or Nexcess

EE settings, add-ons, updates, and your policies

DIY on AWS or DigitalOcean

Cloud usage

AWS in AWS Artifact, or DigitalOcean through Sales or Support

Server, PHP, MySQL, EE patching, TLS, backups, logs, and encryption

HIPAA compliant ExpressionEngine hosting from us

From $229 per month, 4 hours of migration and configuration included

Us, within 24 hours

Your EE site, add-ons, roles, content, and BAAs with outside services such as a mail relay

We sell the last row, so weigh it as a disclosure. Any ExpressionEngine HIPAA compliant route with more than one editor also needs Pro. On AWS, PHI belongs only in HIPAA-eligible services.

If you would rather not harden the server yourself

Most EE teams would rather build templates than patch PHP. Our HIPAA compliant ExpressionEngine hosting runs EE on single-tenant AWS servers. We run the AWS account, operating system, PHP, MySQL, TLS, disk encryption, logs, backups, and monitoring. You run your add-ons, roles, forms, and content. That split keeps the ExpressionEngine HIPAA compliant duties clear on both sides. The BAA covers the servers and services listed above and is signed within 24 hours, before any patient data moves. An outside service, such as a mail relay, needs its own BAA. Plans start from $229 per month with 4 hours of migration and configuration included. We sell this, so weigh it as a disclosure.

Here is the honest inverse. If your EE site is an association site with no member health data, it needs none of this. If your team already runs on the Nexcess compliance tier with a signed BAA, you do not need us. Thinking of leaving EE before the EE 8 upgrade? See is WordPress HIPAA compliant first. Moving to Drupal instead? Its core ships no MFA, but Acquia and Upsun sign a BAA. The Drupal HIPAA compliant guide names the module that fills the MFA gap. For everyone else, our HIPAA compliant hosting plans are public. You can request a quote or tell us what your EE site collects.

Frequently asked questions

Is ExpressionEngine HIPAA compliant?

Not by itself, and no CMS is. An ExpressionEngine HIPAA compliant site needs a host that signs a BAA, Pro for staff logins, and MFA on every role. It also needs an audit add-on, host encryption, and a risk analysis.

Does ExpressionEngine have two-factor authentication?

Yes. EE 7 has included TOTP multi-factor authentication since version 7.0.0 in August 2022, in the free Core edition too. Users turn it on in their profile, and you can require it for any member role.

Does Packet Tide sign a BAA?

No. Packet Tide sells ExpressionEngine licenses and does not host sites, so it never stores your PHI. Your host is the business associate. As of October 6, 2026, Nexcess offers a BAA on its compliance tier, and Liquid Web's EE plans do not.

Can ExpressionEngine encrypt patient data?

Not in the database. EE 7 has no field or database encryption for entries, members, or form submissions. On an ExpressionEngine HIPAA compliant site, encryption at rest comes from the host's disk and database layer.

Is ExpressionEngine 6 still supported?

Only until December 31, 2026. After that date EE 6 gets no updates, including security fixes. Plan the move to EE 7 or EE 8 now.

Recap: ExpressionEngine HIPAA compliant

An ExpressionEngine HIPAA compliant site is EE on a host that signs a BAA, plus Pro, add-ons, and your policies. Packet Tide and Liquid Web's EE plans offer no BAA; Nexcess does. EE 7 has MFA but lacks field encryption and an entry edit log. Turn on secure cookies, shorten sessions, force HTTPS, and leave EE 6 before December 31, 2026.

This article is general information, not legal advice. The details here reflect expressionengine.com, the EE 7 docs, GitHub, and vendor pages as read on September 22 and 23, 2026, and re-checked October 6, 2026. EE 8.0 had not been released as of October 6, 2026. Confirm current terms with each vendor, consult qualified counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting. Reviewed October 2026.

Sources

Read full definition

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.