Is Joomla HIPAA Compliant? Joomla 6, Multi-factor Authentication, and the Settings to Switch On (2026)
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/is-joomla-hipaa-compliant
Last updated: September 30, 2026
Joomla is not HIPAA compliant on its own, and no CMS is. HIPAA regulates the organizations that handle patient data, not the software they run. A Joomla HIPAA compliant site needs a host that signs a Business Associate Agreement (BAA), the right settings, and your own policies. Joomla core ships several controls you need: multi-factor authentication, a User Actions Log, and a 15-minute session default. Most of them ship off or unenforced. No Joomla vendor signs a BAA, so your host is the one that signs. We sell HIPAA compliant hosting, so weigh our advice accordingly.
TL;DR: Quick answer
A Joomla HIPAA compliant site needs a host that signs a BAA under 45 CFR § 164.308(b). As of September 30, 2026, no Joomla-branded service offers one.
Joomla Launch, the free hosting at launch.joomla.org, is run by CloudAccess.net. Its page mentioned no HIPAA terms or BAA on September 30, 2026.
Core MFA supports TOTP, WebAuthn, YubiKey, and email codes. "Enforce Multi-factor Authentication" (
forceMFAUserGroups) covers no user group by default, and "IP Logging" (ip_logging) is off.Per the Joomla 6.1 source, "Force HTTPS" (
force_ssl) is None and HSTS (hsts) is off. "Send Password" (sendpassword) is Yes, and "Session Lifetime" (lifetime) is 15 minutes.Joomla 6.1.4 and 5.4.9, security releases from September 29, 2026, are current. Joomla 5.x goes security-only on October 13, 2026. 2026 brought six High advisories and four MFA bypasses.
Is Joomla HIPAA compliant? The three-layer answer

A Joomla HIPAA compliant system has three layers, and each needs an owner. The first is the contract. Under 45 CFR § 164.308(b), any vendor that stores protected health information (PHI) for you must sign a BAA first. Our HIPAA business associate agreement guide covers what it must say. The second layer is the server: physical safeguards, disk encryption, firewalls, backups, and patching. The third layer is your Joomla site and your team. It covers the technical safeguards in 45 CFR § 164.312, which Joomla meets only in part. It also covers the HIPAA risk analysis under 45 CFR § 164.308(a)(1), policies, and training.
Joomla! is a free PHP content management system (CMS), licensed GPL-2.0-or-later. Its maintainer is Open Source Matters, Inc. (OSM), a nonprofit that holds the project's trademarks. The Joomla Framework is a separate set of PHP packages; HIPAA questions concern the CMS. OSM sells no hosting under a BAA. So the Joomla HIPAA compliant question comes down to your host and your settings.
What Joomla gives you for the HIPAA technical safeguards

Here is how Joomla core maps to 45 CFR § 164.312, per the 6.1 and 5.4 source. The last column is what a Joomla HIPAA compliant site still adds.
Safeguard (45 CFR § 164.312) | What Joomla core provides | What you still add |
|---|---|---|
Access control, (a) | User groups, access levels, and item permissions; 15-minute sessions stored in the database | An IP limit on the administrator area |
Audit controls, (b) | User Actions Log for 21 core components, with CSV export; IP and API logging off; no record of page views | IP logging, web server logs, and an off-server copy, since any Super User can purge the log |
Integrity, (c) | Content versions (off by default), check-in locks, form tokens, and TUF-signed core updates | File integrity monitoring and tested backups |
Person or entity authentication, (d) | bcrypt hashing; 12-character minimum passwords; MFA with 10 tries, then a 1-hour block | MFA enforced for every group that sees PHI, and password complexity rules |
Transmission security, (e) | A Force HTTPS option, set to None; HSTS in the HTTP Headers plugin, off; optional SMTP over TLS | HTTPS for the entire site, HSTS, a TLS mail relay, and TLS to the database |
Two gaps matter most. First, Joomla core encrypts nothing at rest. Articles, user records, sessions, and action logs sit in plain text in the database. Disk and database encryption at rest and in transit is the host's job. Second, the User Actions Log records back-end changes, logins, and logouts, not who viewed a page. Audit logging for a Joomla HIPAA compliant site means core logs plus web server logs, shipped off the server.
Where Joomla sites usually get hosted, and which hosts sign a BAA

No official Joomla cloud signs a BAA. We read each host's own pages on September 22 and 23, 2026, and again on September 30.
Joomla Launch: no BAA. The old joomla.com address now redirects to launch.joomla.org. CloudAccess.net runs it "on behalf of Open Source Matters, Inc.," the page says. It is free, with paid plans from $5 per month, and never mentions HIPAA.
CloudAccess.net managed hosting: no BAA. One plan at $9.58 per month, with no HIPAA or BAA language.
SiteGround: no BAA found. Its only HIPAA page covers Google's BAA for Google Workspace email, not SiteGround hosting.
Rochen and Hosting.com: not confirmed. Neither page could be read, so we make no claim about either.
DigitalOcean: BAA on request. "New customers may request a BAA by contacting Sales," its HIPAA page says. Droplets, Droplet Backups, Volumes, and Spaces are covered.
AWS: BAA in AWS Artifact. You accept AWS's standard BAA in AWS Artifact. You install and harden Joomla on EC2 yourself.
On DigitalOcean or AWS, the cloud signs for its hardware. You own the operating system, PHP, Joomla, TLS, logs, and backups. Cloud providers call this split the shared responsibility model. DigitalOcean's 1-Click Joomla images make HTTPS an opt-in step and do not enforce MFA. One of them, OpenLiteSpeed Joomla, lists Joomla 6.1.1 in its docs, so update to 6.1.4 or later before use. More hosts are compared in HIPAA compliant app hosting. A Joomla HIPAA compliant build on either cloud works, but the hardening is yours.
Which Joomla settings are off by default?
These defaults come from the Joomla 6.1.4 and 5.4.9 source, read September 30, 2026. A Joomla HIPAA compliant site changes most of them.
Setting, as labelled in the admin | Config key | Default | Change for PHI |
|---|---|---|---|
Force HTTPS | force_ssl | None | Entire Site |
HTTP Strict Transport Security (HSTS) | hsts | Off | On |
Enforce Multi-factor Authentication | forceMFAUserGroups | No groups | Every group that sees PHI |
Onboard new users | mfaredirectonlogin | No | Yes |
Multi-factor Authentication after silent login | mfaonsilent | No | Yes |
IP Logging | ip_logging | No | Yes |
Enable Versions | save_history | No | Yes, if edits need a history |
Send Password | sendpassword | Yes | No |
Error Reporting | error_reporting | System Default | None |
Debug System | debug | No | Keep No |
Track Session Metadata | session_metadata | Yes | Keep, on an encrypted database |
Connection Encryption | dbencryption | Default (server controlled) | TLS to the database |
Minimum Numbers, Symbols, Upper Case | minimum_integers, minimum_symbols, minimum_uppercase | 0 | At least 1 each |
Send Password is the default most teams miss. It emails new users their password at registration, putting a patient portal login in an inbox you do not control. And every MFA method ships switched on, yet no one is forced to use one. A Joomla HIPAA compliant setup closes both gaps first.
Which Joomla versions are safe to run?

As of September 30, 2026, Joomla 6.1.4 and 5.4.9 are current. Both are security releases from September 29, 2026. Joomla's roadmap sets the dates that matter:
Joomla 6.2.0 reached its first release candidate on September 29, 2026.
Joomla 6.2.0 and 5.4.10 are due October 13, 2026. That day, Joomla 5.x gets security fixes only, until October 12, 2027.
Joomla 6.x gets bug fixes to October 17, 2028 and security fixes to October 16, 2029.
Joomla 4 support ended October 14, 2025. Most 2026 advisories list 4.x as affected, and none has a 4.x fix.
Joomla 6.1 needs PHP 8.3 or later, and 5.4 needs PHP 8.1. The Joomla Security Strike Team (JSST) shipped six security rounds in 2026. For a Joomla HIPAA compliant site, these matter most:
Advisory and fix release date | JSST severity | What it was |
|---|---|---|
20260305, March 31, 2026 | High | Arbitrary file deletion in the core updater (CVE-2026-23898) |
20260306, March 31, 2026 | High | Improper access check in web service endpoints (CVE-2026-23899) |
20260509, May 26, 2026 | High | Local file inclusion (CVE-2026-40383) |
20260513, May 26, 2026 | High | Privilege escalation through the com_users batch task (CVE-2026-48898) |
20260905, September 29, 2026 | High | Arbitrary directory deletion through the cache purge action (CVE-2026-90915) |
20260909, September 29, 2026 | High | Server-side request forgery (SSRF) in several core extensions (CVE-2026-92222) |
20260511, 20260512, 20260807, 20260914 | Moderate | Four MFA bypasses, the latest through Remember Me cookies (CVE-2026-48896, CVE-2026-48897, CVE-2026-73337, CVE-2026-92227) |
The JSST uses its own scale of Critical, High, Moderate, and Low, not CVSS. On that scale, High means site data is compromised. The four MFA bypasses mean MFA protects you only on a patched site. A Joomla HIPAA compliant site runs the newest 6.x release, or 5.4.x until October 12, 2027, and patches within days.
The 9 settings that make a Joomla site HIPAA-ready

We check these first in every Joomla HIPAA compliant review.
Update, and keep updating. Run 6.1.4 or later, or 5.4.9 while you plan the move to 6. In the Joomla Update options, confirm "Automated Update" (
autoupdate) is Yes. Fresh 6.1 installs ship with it on.Force HTTPS for the entire site. Once HTTPS works at the server, set Force HTTPS to Entire Site. Then turn on HSTS in the System - HTTP Headers plugin.
Enforce MFA. Add Super Users, Administrators, and every group that can see submissions to Enforce Multi-factor Authentication. Set "Onboard new users" (
mfaredirectonlogin) to Yes. Set "Multi-factor Authentication after silent login" (mfaonsilent) to Yes, so Remember Me logins also ask for MFA.Keep sessions short and errors quiet. Keep Session Lifetime at 15 minutes or less, and "Shared Sessions" (
shared_session) at No. Set "Error Reporting" (error_reporting) to None, with "Debug System" (debug) at No.Log more, and keep the log. Set IP Logging and "Log API Requests" (
loggable_api) to Yes. Core creates no log-deletion task. If you add "Task - Delete Action Logs", its "Days to delete action logs after" (logDeletePeriod) defaults to 7. Set your policy's number, and ship a copy to a log store under a BAA.Tighten passwords and registration. Set "Minimum Numbers" (
minimum_integers), "Minimum Symbols" (minimum_symbols), and "Minimum Upper Case" (minimum_uppercase) to at least 1. Set Send Password to No.Protect secrets and move logs. configuration.php holds the database password and site secret in plain text, so lock its file permissions. Point "Path to Log Folder" (
log_path) and "Path to Temp Folder" (tmp_path) outside the web root, never at /tmp.Treat form extensions as PHI stores. In RSForm! Pro, set "Save data to database", "Save IP to database", and "Delete Submissions Older Than" per form. In Convert Forms, keep submissions off the front end.
Move backups out of the web root. Point Akeeba Backup's output folder above the site root. Encrypt the archives, and store them only under a BAA.
Item 3 is covered in HIPAA MFA requirements, and our glossary defines multi-factor authentication (MFA). Item 4 is the automatic logoff rule in 45 CFR § 164.312(a)(2)(iii), explained in HIPAA automatic logoff. With all nine in place, the Joomla HIPAA compliant work inside your site is mostly done.
Where Joomla sites leak PHI

A Joomla HIPAA compliant review finds most leaks in forms, backups, and logs.
Form extensions. RSForm! Pro stores submissions in its own tables, and its emails still go out when storage is off. Convert Forms can publish submissions on a front-end page.
The core contact form. It stores nothing, but it emails each message. The default Mailer is PHP mail(), with no TLS option.
Backups in the web root. Akeeba's warning Q203 says the default output folder is "in a well known, browser accessible location."
Logs and debug output. The default log folder, administrator/logs, is inside the public tree. Debug System prints queries and session data when on.
Plain-text tables. Session metadata, action logs, and user profiles sit unencrypted in the database and every backup. The Privacy component emails data exports as attachments.
The /api web services. Eleven 2026 advisories fixed missing access checks in the API. If you do not use it, block /api/ at the server.
Form settings and debug switches are your layer. The log store, backups, and server rules are the host layer of a Joomla HIPAA compliant site, and you can hand that layer off. The mail relay that sends form emails needs a BAA too. Intake form rules are in HIPAA compliant forms. Backups copy every leak above, so see HIPAA backup and disaster recovery.
Who signs the BAA for a Joomla site, and what does it cost?

A Joomla HIPAA compliant budget starts with the host that signs the BAA. Figures are as published on September 30, 2026.
Route | Published price | Who signs the BAA | What you still own |
|---|---|---|---|
Joomla Launch or CloudAccess.net | Free, or $5 to $9.58 per month | No one | Not a PHI route |
DigitalOcean Droplet or AWS EC2 | Droplets from $4 per month, or AWS usage, plus your time | The cloud provider | Server, PHP, and Joomla patching, TLS, logs, backups, and encryption |
HIPAA compliant Joomla hosting from us | Six plan sizes, priced on our Joomla hosting page; migration included | Us, within 24 hours | Your Joomla settings, extensions, user groups, and content, plus BAAs for any outside services |
We sell the last row, so weigh it as a disclosure. On AWS, PHI belongs only in HIPAA-eligible services. Our AWS HIPAA eligible services guide shows how to check EC2, S3, and the rest of your stack against AWS's current list. A Joomla HIPAA compliant DIY build also means applying every JSST release yourself.
If you would rather not harden the server yourself
Our HIPAA compliant Joomla hosting runs Joomla on AWS servers we manage. We run the network, operating system, PHP, database, TLS, disk encryption, server logs, backups, and monitoring. You run your Joomla settings, extensions, user groups, and content. That split keeps the Joomla HIPAA compliant duties clear. The BAA is signed within 24 hours, before any patient data moves. It covers the servers and services listed above. Any outside service that receives patient data, such as a mail relay or an extension's cloud service, needs its own BAA too. Plans come in six sizes, from Starter to Network, with migration included, and our Joomla hosting page lists current prices. We sell this, so weigh it as a disclosure.
Here is the honest inverse. A brochure site with a phone number and no forms holds no PHI and needs none of this. If your team runs on AWS under AWS's BAA, with an engineer who patches and ships logs, you do not need us. Weighing a move? Read is WordPress HIPAA compliant first. Drupal is the other common choice, but its core ships no MFA. The Drupal HIPAA compliant guide names the module that adds it and the hosts that sign a BAA. Our HIPAA compliant hosting plans are public. You can request a quote or tell us what your Joomla site collects.
Frequently asked questions
Is Joomla HIPAA compliant?
Not by itself, and no CMS is. A Joomla HIPAA compliant site needs a host that signs a BAA, core settings changed from their defaults, and a risk analysis. Joomla comes from a nonprofit, Open Source Matters, Inc., and no Joomla vendor signs a BAA.
Does Joomla have multi-factor authentication?
Yes. Joomla core supports authenticator app codes, WebAuthn security keys, YubiKey, email codes, and backup codes. As of September 30, 2026, no user group is forced to use it by default. A Joomla HIPAA compliant site adds groups under Enforce Multi-factor Authentication.
Is a Joomla contact form HIPAA compliant?
Not on its own. The core contact form emails each message, so PHI passes through your mail server. RSForm! Pro and similar extensions also store submissions in the database. A Joomla HIPAA compliant form needs a host and mail relay under a BAA.
Does Joomla encrypt data at rest?
No. Joomla core hashes passwords with bcrypt but does not encrypt content, user records, sessions, or logs. On a Joomla HIPAA compliant site, disk and database encryption comes from the host.
Is Joomla 4 still supported?
No. Joomla 4 support ended October 14, 2025. Most 2026 advisories list 4.x as affected, and none ships a 4.x fix. Move to the newest Joomla 6.x release, or to 5.4.x, which gets security fixes until October 12, 2027.
Recap: Joomla HIPAA compliant
A Joomla HIPAA compliant site is Joomla on a host that signs a BAA, with core settings changed. No Joomla vendor signs a BAA; DigitalOcean and AWS do. Enforce MFA, force HTTPS, turn on HSTS and IP logging, and switch off Send Password. Keep backups and logs out of the web root. Joomla 5.x goes security-only on October 13, 2026.
This article is general information, not legal advice. The details reflect joomla.org, the Joomla source, and vendor pages as last read on September 30, 2026. Joomla 5.x support status changes October 13, 2026. Confirm current terms with each vendor, consult qualified counsel, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting. Reviewed September 2026.
Sources
Joomla! developer network: Roadmap, Security Centre, and Security Strike Team.
Joomla.org: The project, Joomla 6.0 and 5.4 release, Joomla 5.3.4 release, and Joomla 6.1.4 and 5.4.9 release.
Joomla manual: Technical requirements.
Joomla source: Releases, Global Configuration, Users options, and User Actions Log options.
Hosts: Joomla Launch, CloudAccess.net pricing, and SiteGround Google Workspace HIPAA.
Extensions: RSForm! Pro form properties, Convert Forms front-end submissions, and Akeeba Q203.
DigitalOcean: HIPAA at DigitalOcean, Droplet pricing, and OpenLiteSpeed Joomla 1-Click.
AWS: HIPAA compliance.
45 CFR § 164.308 and § 164.312: ecfr.gov.