Sep 17, 2026

Resource

eClinicalWorks vs Athenahealth vs CareCloud: Security

Choosing an EMR is one of the biggest decisions a small medical practice makes, and most of the comparison articles out there focus on billing features, scheduling tools, and monthly cost. Security and HIPAA compliance usually get a single bullet point that says "HIPAA compliant" and calls it a day.


That's not good enough anymore. Here's a more honest look at three of the most common EMR platforms used by South Florida practices, eClinicalWorks, Athenahealth, and CareCloud, with a focus on what actually matters for keeping your patients' data safe.


eClinicalWorks is one of the most widely deployed EHR systems among small and mid-sized practices, and it will execute a standard Business Associate Agreement with your practice, which is the baseline requirement for HIPAA compliance.


What's worth knowing before you sign: in 2017, eClinicalWorks paid $155 million to settle a False Claims Act lawsuit brought by the Department of Justice. The allegations, according to the DOJ's own press release, were that the company had misrepresented the capabilities of its software to obtain federal certification, including hardcoding certain test results rather than actually meeting data portability standards, which in turn caused healthcare providers using the software to falsely collect federal EHR incentive payments. It's an important data point, not because it means the software is insecure today, but because it's a reminder that a vendor's own compliance claims aren't something to take at face value. Ask for independent verification: current SOC 2 Type II or HITRUST reports, not just a marketing page that says "secure."


Athenahealth is a cloud-based platform that publishes more specific security detail than most competitors. According to its own documentation, it uses AES-256 encryption for data at rest, TLS/SSL encryption for data in transit, role-based access controls, multi-factor authentication support, and detailed audit logging of logins, chart access, and data exports. The company maintains HITRUST Certification for applicable services and aligns its controls with the NIST Cybersecurity Framework, which are both meaningful, third-party-verified signals rather than self-reported claims.


Compliance responsibility is still shared, though. Athenahealth provides the technical controls, but your practice is still responsible for configuring role-based access correctly, enforcing MFA for your staff, and training your team, none of which happens automatically just because you chose a well-documented platform.


CareCloud is a cloud-based EHR and practice management platform used by more than 45,000 providers. It's also the vendor behind one of 2026's largest healthcare data breaches: in March 2026, an attacker gained unauthorized access to one of CareCloud's six AWS-hosted EHR environments for approximately eight hours, ultimately exposing the records of 3,756,469 individuals, including Social Security numbers and financial account information (we covered the full incident in a separate post).


That doesn't automatically disqualify CareCloud as a platform. Every major EMR vendor is a target, and a breach disclosure that's handled transparently, with law enforcement involvement, credit monitoring for affected patients, and public SEC filing, is arguably better than a vendor that has never disclosed an incident because it has weaker detection in place. But if your practice uses or is considering CareCloud, it's reasonable to ask pointed questions: what changed in their access control and authentication processes since March 2026, and how would your practice be notified if it happened again?


How to actually evaluate any EMR vendor. Whichever platform you're using or considering, here's what to ask before you take a vendor's "HIPAA compliant" claim at face value: request a current BAA and read it, looking specifically at breach notification timelines and what the vendor is and isn't responsible for; ask for a SOC 2 Type II or HITRUST report, not just a compliance statement on their website, since these are independently audited and mean something; confirm MFA is available and can be enforced practice-wide, not just optional for individual users; ask how role-based access works and whether your practice will need to configure it or whether it comes pre-set to reasonable defaults; and ask what their breach notification process looks like, specifically how quickly they'd tell you if something happened, since your own HIPAA obligations start on a clock you don't control once a vendor is compromised.


The bottom line for South Florida practices: there's no EMR on the market that's immune to attack. eClinicalWorks, Athenahealth, and CareCloud are all used successfully by thousands of practices, including plenty across Palm Beach, Broward, and Miami-Dade counties. The difference between a practice that weathers a vendor incident smoothly and one that ends up in a HIPAA enforcement action usually comes down to whether the practice did its own due diligence upfront, current BAA, MFA enabled, staff access properly scoped, rather than assuming the vendor had it fully covered.

Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence