← Writing

The compliance claim we deliberately didn't make

We set out to put 'HIPAA compliant' on an EHR's marketing site. The research said HIPAA doesn't even apply — and the honest answer turned into better positioning than the badge would have been.

On this page

The question that kicked this off was simple and commercially reasonable: what do we need to do to claim HIPAA compliance?

ChiroSimple is an EHR — practitioners store patient records, treatment notes, and billing in it. Every competitor page in the space has a HIPAA badge somewhere. Prospects ask about it. The obvious move was to figure out the checklist, do the work, and put the badge up.

So I did the research expecting a to-do list. What came back instead was: HIPAA doesn’t apply to this product at all.

Why the obvious claim was wrong

ChiroSimple’s practitioners are animal chiropractors. Their patients are horses and dogs.

HIPAA protects PHI — protected health information — and PHI is defined around identifiable health information about people, held by covered entities: health plans, clearinghouses, and human-healthcare providers. Animal medical records aren’t PHI. Animal chiropractors aren’t covered entities. There is no legal sense in which this product can be “HIPAA compliant,” because the law’s scope doesn’t reach it.

Which means a HIPAA badge on the site wouldn’t have been a stretch — it would have been a claim about a law that doesn’t govern the product, aimed at customers it doesn’t bind. Some competitors do it anyway, because prospects pattern-match “medical records software” to “HIPAA” and the badge soothes them. That’s exactly what makes it tempting, and exactly what makes it hollow.

(To be clear about the other direction: if you’re building for human healthcare, HIPAA absolutely does bind you, and the diligence is real work — I’ve written about what to actually look for when hiring for it. The lesson here isn’t “compliance is optional.” It’s the opposite.)

The question behind the question

The useful move was to stop asking “how do we claim HIPAA?” and ask what the customer’s actual regulatory exposure is. If a practitioner ever faces a records dispute, who knocks on their door?

The answer: state boards. Animal chiropractic sits under a patchwork of state veterinary and chiropractic board rules, and the obligation that consistently shows up is record-keeping — maintain patient records, retain them for a specified number of years, and be able to produce them when the board asks. The retention period and specifics vary by state.

That’s the compliance reality our customers live in. Not a federal privacy statute — a state records-retention rule with an audit at the end of it.

Selling the truth instead

Once the real obligation was clear, the product story rewrote itself. ChiroSimple already had the relevant feature set: finalized visit notes that send automatically to owners and referring vets, with delivery logs recording what was sent, to whom, and when.

The honest positioning wrote itself from there: one switch satisfies your state’s records-retention rule — with a delivery log that proves it if a board ever asks.

Compare the two pitches:

  • “HIPAA compliant” — legally meaningless for this audience, indistinguishable from every competitor, and indefensible under scrutiny.
  • “Your records are kept, retained, and provable to your state board” — addresses the risk the customer actually carries, is concretely true, and points at a feature competitors would have to build.

The second one is better marketing because it’s true. It also opened an editorial angle the badge never could: a records-requirements-by-state resource is genuinely useful content for this audience, and nobody writes it because everyone is busy photocopying each other’s HIPAA pages.

The general lesson

This pattern isn’t about veterinary software. It’s about the gap between the compliance claim a market expects and the rules that actually bind your customers.

The expected claim is usually inherited — from an adjacent industry, from competitors, from a prospect’s half-remembered checklist. Investigating the real obligation takes a day or two of unglamorous reading. Three outcomes are possible, and all of them beat badge-collecting:

  1. The expected rule applies. Now you know, and the work you do toward it is real instead of cosmetic.
  2. The expected rule doesn’t apply, but a different one does. This case. The different rule is your positioning gift — you get to be the vendor that understands the customer’s actual life.
  3. Nothing applies. Then say what you actually do — encryption, access controls, backups, export — as facts rather than borrowed acronyms.

The badge would have taken an afternoon to add and would have been worth roughly nothing — until the day a sophisticated buyer, or a lawyer, asked us to substantiate it. The truthful claim took a research detour and produced positioning that no competitor can copy without first building the feature and reading the same state rules.

“What do we need to claim compliance?” was the wrong question. The right one — what rule actually binds our customers, and can we make satisfying it effortless? — turned compliance from a marketing checkbox into a product advantage.

← All writing Book a call →
Book a call → WhatsApp