Endpoint Index
Research / Industry guide

Endpoint Security for Medical and Dental Practices: The BAA Decides the Shortlist

Updated · data as of · 7 min read

Contents
  1. Executive summary
  2. Which Security Rule duties does an endpoint product touch?
  3. Why does the BAA come before features?
  4. Which BAA-offering products fit a practice?
  5. What does it cost a practice?
  6. What should each kind of practice buy?
  7. Mistakes practices make
  8. Frequently asked questions
  9. Methodology and caveats
  10. Sources

Executive summary

A small medical or dental practice should shortlist only endpoint products whose vendor will sign a Business Associate Agreement (BAA) for the exact edition being bought, and should accept that this rules out some managed services that IT providers commonly resell. Just 4 of 17 products on this site are recorded as offering a BAA, and only 0 of that group bundle round-the-clock managed response (vendor data from 2026-10-02). Huntress and ThreatDown, both sold through IT providers, state that they do not sign BAAs.

The second test is what the product records. Under HIPAA, an impermissible access to patient data is presumed to be a breach unless the practice can show a low probability that the data was compromised (45 CFR 164.402). One of the four factors in that assessment is whether the information was actually acquired or viewed. A product with endpoint detection and response (EDR) keeps the activity record that answers it. A product that only blocks malware does not.

So the buy for most practices is a BAA-backed product with EDR, plus a named person or service that reads its alerts.

Which Security Rule duties does an endpoint product touch?

The Security Rule never names a product. It sets standards a practice meets in proportion to its size, technical capability and the cost of the measure (45 CFR 164.306(b)). Five provisions in 45 CFR 164.308 land directly on the workstations and servers in a practice:

Provision Text of the rule Where the endpoint product fits
164.308(a)(1)(ii)(D) Regularly review records of information system activity, such as audit logs and security incident tracking reports The console's alert history and monthly report are those records, if someone reviews them
164.308(a)(5)(ii)(B) Procedures for guarding against, detecting and reporting malicious software Blocking and central reporting on every device that opens patient records
164.308(a)(5)(ii)(C) Procedures for monitoring log-in attempts and reporting discrepancies EDR logs sign-ins on each device and flags unusual ones
164.308(a)(6)(ii) Identify and respond to suspected or known security incidents, mitigate harmful effects, and document incidents and their outcomes Isolation, containment and the incident timeline
164.308(b)(1) A business associate may handle ePHI for you only with satisfactory assurances that it will safeguard it Whether the endpoint vendor must sign a BAA

The malware and log-in specifications are addressable. Under 164.306(d)(3), that means the practice implements them if reasonable and appropriate, or documents why not and implements an equivalent. It does not mean optional. No dental office has a credible written reason to leave a front-desk PC without malware protection.

Why does the BAA come before features?

An endpoint agent sees file names, paths and sometimes whole files it quarantines. In a practice, those can be patient documents, imaging exports and scanned referral letters. If your risk analysis concludes the vendor's cloud service receives or maintains ePHI, 164.308(b)(1) requires a BAA before you deploy it.

Vendors answer that question differently, and the products below are the ones where the answer is "no" or where the vendor publishes nothing:

ProductHIPAA BAASupports PCI DSSCMMC-relevantFedRAMP
Bitdefender GravityZone Business SecurityUnknownUnknownUnknownunknown
ESET PROTECT CoreUnknownYesUnknownnone
Microsoft Defender for BusinessUnknownYesUnknownunknown
Bitdefender GravityZone Business Security PremiumUnknownUnknownUnknownunknown
Avast Ultimate Business SecurityNoUnknownUnknownnone
CrowdStrike Falcon GoUnknownYesYesauthorized
Webroot Business Endpoint ProtectionUnknownUnknownUnknownnone
ThreatDown EliteNoYesUnknownnone
ThreatDown AdvancedNoYesUnknownnone
Sophos EndpointUnknownYesYesnone
Huntress Managed EDRNoUnknownYesnone
CynetUnknownYesYesnone
WatchGuard Endpoint Security 360UnknownYesUnknownnone
From each vendor's trust or compliance pages. "Unknown" means the vendor does not publish the fact; follow a product link for sources.

Huntress's position is explicit: it states that its products do not access, use or disclose health information, so it does not provide BAAs. ThreatDown (Malwarebytes) says the same about its own products; the source is on the ThreatDown Elite product page. Avast is recorded as not offering one. The other vendors in the table publish no position either way. Microsoft's agreement applies only to services on its HIPAA in-scope list, which names neither Defender for Business nor Defender for Endpoint. Sophos publishes a HIPAA attestation and Cynet maps its reporting to HIPAA, but neither says it signs a BAA. Bitdefender's HIPAA page sends BAA questions to the account manager, and CrowdStrike, ESET, WatchGuard and Webroot say nothing on the point. Ask before you buy, and get the answer in writing. A vendor's view that it never touches ePHI is an input to your risk analysis, not a substitute for it. If your analysis disagrees, the product is off the list regardless of how good it is.

Some BAAs are narrower than the marketing suggests. Acronis, for example, signs BAAs only for Cyber Protect Advanced (or Cyber Protect Cloud) with Acronis Cloud Storage in a US data centre, through an account manager, and not before purchase. The Acronis Cyber Protect page links the source. Whichever vendor you pick, ask for the agreement itself and check which edition it names.

Which BAA-offering products fit a practice?

This table is limited to products recorded as offering a BAA, because for a covered practice the others need a documented risk-analysis exception before they can be considered. The columns are the ones that matter after the BAA: whether the product keeps an activity record (EDR), whether someone watches it around the clock, whether it can undo ransomware encryption, and whether it runs on the Macs many practices use at reception.

ProductEDR24/7 managed responseRansomware rollbackmacOS
Acronis Cyber ProtectNot offeredNot offeredIncludedIncluded
SentinelOne Singularity ControlIncludedNot offeredIncludedIncluded
SentinelOne Singularity CompleteIncludedNot offeredIncludedIncluded
Trend Micro Worry-Free Services AdvancedNot offeredNot offeredIncludedIncluded
From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.

What does it cost a practice?

ProductPer unit per month10 seats / yr25 seats / yr100 seats / yr
SentinelOne Singularity Control$6.67 /endpoint/mo$799.90$1,999.75$7,999.00
Acronis Cyber Protect$7.08 /endpoint/mo$850.00$2,125.00$8,500.00
SentinelOne Singularity Complete$15.00 /endpoint/mo$1,799.90$4,499.75$17,999.00
Annual totals from each vendor's store or calculator at list price. "Quote only" means the vendor publishes no online price at that seat count; "Min N seats" means the vendor's smallest purchase is larger. Not shown because the vendor does not publish a price: Trend Micro Worry-Free Services Advanced.

Count every device that can open patient data: reception PCs, operatory and exam-room machines, imaging workstations, the practice-management server and any laptop a clinician takes home. Microsoft Defender for Business is not in this table because Microsoft's BAA does not name it. If Microsoft confirms coverage in writing, note that it is licensed per user rather than per device, and one licence covers up to five devices per user (Microsoft FAQ), which suits a clinician with a desktop, a laptop and a tablet. Windows and Linux servers are not covered by the user licence; they need Microsoft's Defender for Business servers add-on.

What should each kind of practice buy?

Solo or two-chair practice with no IT staff. If the practice already runs Microsoft 365, Microsoft Defender for Business ($36.00 per user per year) brings EDR, but Microsoft's public list of HIPAA in-scope services does not name Defender for Business or Defender for Endpoint, so confirm with Microsoft in writing that its BAA covers it. It has no 24/7 managed response, so name the person who reads the weekly report and write that into your risk analysis. If nobody can, pay for managed response rather than buying EDR that no one opens.

Group practice of 10 to 40 staff with an outside IT provider. Ask the provider in writing which endpoint product it deploys and whether that vendor signs a BAA with you or with it. If the answer is Huntress or ThreatDown, ask for a BAA-capable alternative or a written risk-analysis conclusion that the service handles no ePHI. Cynet includes a 24/7 team but publishes no BAA position, and its sales orders cannot be cancelled once signed, so get the BAA text before you sign. None of the 4 products recorded as offering a BAA includes 24/7 managed response. SentinelOne Singularity Complete ($179.99 per endpoint per year) and Singularity Control ($79.99 per endpoint per year) include EDR and record a BAA, but neither includes 24/7 managed response, so agree who watches the console.

Practice with imaging servers, Macs or Linux. Check the Mac column above, and each product page's Linux and server support, against your equipment list before you check the price. Several products cover servers only with a separate licence: Microsoft's servers add-on, or Sophos Workload Protection alongside Sophos Endpoint. If an imaging vendor forbids third-party software on its workstation and you leave that machine unprotected, record the reason and the compensating control, such as network isolation, as 164.306(d)(3) requires.

Mistakes practices make

  • Assuming the IT provider's bundle comes with a BAA. Huntress, a managed EDR built for the IT-provider channel, does not.
  • Signing a BAA that covers a different edition. Match the BAA's product name to the invoice line.
  • Buying EDR and never opening it. 164.308(a)(1)(ii)(D) asks for regular review of activity records. An unread console is a record that nobody reviewed.
  • Leaving the imaging PC off the console because it "belongs to the vendor", with nothing written down.

Frequently asked questions

Does HIPAA name antivirus software?

No. It requires procedures for guarding against, detecting and reporting malicious software (45 CFR 164.308(a)(5)(ii)(B)). Centrally managed endpoint protection on every device that opens patient data is how nearly every practice meets it.

Which endpoint vendors refuse to sign a BAA?

Huntress and ThreatDown state that they do not sign BAAs because their services do not handle ePHI. The table in this guide shows every product whose vendor does not offer a BAA or does not publish a position.

Can a practice use Huntress without a BAA?

Only if its own risk analysis concludes that the Huntress service does not create, receive, maintain or transmit ePHI, and it documents that conclusion. That is a decision for the practice and its compliance adviser.

Why does EDR matter after a ransomware attack on a practice?

Because the practice must show a low probability that patient data was compromised, or treat the incident as a breach (45 CFR 164.402). EDR's record of which files and accounts were touched is the evidence for that assessment.

Methodology and caveats

The quoted HIPAA provisions (45 CFR 164.306, 164.308, 164.402) were compared against the Legal Information Institute's CFR text on 30 September 2026. The product set in the capability and cost tables is filtered to products whose BAA field is recorded as available; the regulatory table lists products recorded as not offering a BAA or whose vendor publishes no position. BAA status reflects each vendor's published position on its verification date and can change at renewal.

Nothing here is legal advice. Your risk analysis, and your compliance adviser, decide whether a given vendor needs a BAA.

Sources

  1. Legal Information Institute. 45 CFR 164.308, Administrative safeguards. Checked 30 September 2026.
  2. Legal Information Institute. 45 CFR 164.306, Security standards: general rules. Checked 30 September 2026.
  3. Legal Information Institute. 45 CFR 164.402, Definitions (breach). Checked 30 September 2026.
  4. Huntress. Huntress and HIPAA Compliance.
  5. Microsoft Learn. Defender for Business FAQ.
  6. Endpoint Index product pages, each carrying the vendor's BAA statement and its verification date. Dataset last verified 2026-10-02.

Related research

All research ›

Methodology · Report an error · Vendor not listed? Get listed