Disclosure: We may earn commissions from partner links on this site. This does not affect our independent editorial reviews. All opinions are our own. Full disclosure.
HIPAA Compliant Remote Access for Healthcare, Finance & Legal
Yes, Splashtop signs a HIPAA BAA. Splashtop Enterprise delivers HIPAA-compliant remote access with a signed Business Associate Agreement (BAA), SOC 2 Type II certification, end-to-end AES-256 encryption, and comprehensive audit controls — all while maintaining the 4K/60fps performance that clinical imaging, financial modeling, and document review demand.
Compliance Requirements by Sector
Healthcare
Primary Framework: HIPAA Security Rule (45 CFR Parts 160, 162, 164)
- BAA required with all vendors handling ePHI
- Access controls: unique user IDs, emergency access, automatic logoff
- Audit controls: hardware, software, and procedural mechanisms to record and examine access
- Integrity controls: ePHI must not be improperly altered or destroyed
- Transmission security: encryption of all ePHI in transit
Financial Services
Primary Framework: GLBA, SEC, FINRA, SOX
- Customer information safeguards (GLBA Safeguards Rule)
- Session recording and retention for FINRA/SEC compliance
- Multi-factor authentication for all remote access
- Audit trails for user access to sensitive systems
- Data residency and sovereignty controls
Legal
Primary Framework: ABA Model Rules, State Bar Regulations
- Client confidentiality (attorney-client privilege)
- Secure transmission of privileged documents
- Access controls for document management systems
- Audit trails for discovery responses
- Mobile and remote work compliance
Splashtop Compliance & Security Architecture
Splashtop meets the technical safeguards required by HIPAA, GLBA, and other regulatory frameworks through a defense-in-depth architecture. Our Splashtop Enterprise review provides detailed coverage of the full security model.
Splashtop vs. Remote Access Tools for Compliance
| Feature | Splashtop Enterprise | TeamViewer | AnyDesk | Chrome Remote Desktop | Action |
|---|---|---|---|---|---|
| Business Associate Agreement (BAA) | Available | Available | Available | Not available | |
| Encryption Standard | TLS 1.2 + AES-256 / DTLS + SRTP | AES-256 / RSA-4096 | TLS 1.2 + AES-256 | WebRTC/DTLS | |
| Access Controls | Role-based, group-based, IP allowlist, time-based | Role-based, device groups | Role-based, device profiles | Google account only | |
| Audit Controls | Full session audit logs, watermarked recording | Session logging | Session logging | No | |
| Integrity Controls | End-to-end encryption for all data in transit | End-to-end encryption | End-to-end encryption | In-transit only | |
| Transmission Security | TLS 1.2 + DTLS/SRTP | TLS + proprietary | TLS + DeskRT | WebRTC | |
| Device Authentication | Device binding + MFA | Device assignment + MFA | Device auth + MFA | Google account + 2FA | |
| Session Recording | Built-in with watermarking | Yes (add-on) | Limited (add-on) | No | |
| MFA | TOTP, Duo, push notifications | Yes | Yes | Google 2FA only | |
| SSO Integration | SAML: Entra ID, Okta, OneLogin, ADFS | SAML SSO | SAML SSO | Google SSO only | |
| On-Premise Option | Yes — self-hosted gateway | No | On-prem relay | No | |
| Certifications | SOC 2 Type II, GDPR, ISO 27001 | SOC 2, ISO 27001, HIPAA | SOC 2, ISO 27001 | None |
Key Compliance Features
- Business Associate Agreement (BAA): Splashtop executes BAAs covering all HIPAA-covered entities and business associates. Required before any ePHI transits the platform.
- End-to-End Encryption: TLS 1.2 + AES-256 for signaling; DTLS/SRTP for media streams. No Splashtop infrastructure can decrypt session content.
- On-Premise Deployment: Self-hosted gateway option eliminates data transit to Splashtop cloud — sessions stay entirely within your network boundary. Critical for healthcare and financial organizations with data sovereignty requirements.
- Session Recording: Built-in, watermarked session recording with playback. Every remote session is captured with visual watermarking for audit and compliance review.
- Access Controls: Role-based, group-based, IP allowlisted, and time-windowed access policies. Integrates with Entra ID, Okta, OneLogin, and ADFS via SAML SSO.
- Certifications: SOC 2 Type II (audited annually), GDPR compliant, ISO 27001 certified, HIPAA-BAA ready.
Deployment for Compliance
- Execute BAA with Splashtop before any production deployment involving ePHI.
- Deploy Splashtop On-Premise gateway behind your firewall if data sovereignty or zero-cloud-exposure is required.
- Configure access policies — enforce MFA, set IP allowlists, enable session recording with watermarking, and configure automatic logoff timeouts.
- Integrate SSO via SAML with your identity provider — enforce conditional access policies (device compliance, location, risk score).
- Enable audit logging and forward logs to your SIEM for centralized compliance monitoring.
- Train users and administrators on HIPAA-compliant remote access workflows.
For a structured compliance evaluation framework across remote access vendors, see our comparison matrix.
Frequently Asked Questions
Does Splashtop sign a HIPAA BAA?
Yes. Splashtop executes Business Associate Agreements (BAAs) with covered entities and business associates. The BAA covers all HIPAA-required technical safeguards for remote access involving ePHI.
Is Splashtop remote access HIPAA compliant?
Yes. Splashtop Enterprise meets HIPAA technical safeguards including access controls (role-based, MFA, IP allowlist), audit controls (session recording with watermarking), integrity controls (end-to-end encryption), and transmission security (TLS 1.2 + AES-256).
What remote access software is HIPAA compliant?
Splashtop Enterprise, TeamViewer, and AnyDesk all offer HIPAA compliance with BAA availability. Splashtop differentiates with an on-premise gateway option for data sovereignty and included session recording.
Can Splashtop be used for healthcare remote access?
Yes. Splashtop Enterprise is widely used in healthcare for telehealth, clinical imaging review, EHR access, and IT support. It supports HIPAA-compliant BAA, 4K/60fps streaming for medical imaging, and on-premise deployment for data sovereignty.
Is Splashtop suitable for financial services compliance?
Yes. Splashtop Enterprise meets GLBA, SOX, and FINRA requirements with SOC 2 Type II certification, session recording, MFA, and access controls. The on-premise gateway option supports data residency requirements.
Is Splashtop HIPAA compliant?
Yes. Splashtop Enterprise is HIPAA compliant when deployed with a signed BAA. It meets all HIPAA Security Rule technical safeguards: access controls (role-based, MFA, IP allowlist), audit controls (session recording with watermarking), integrity controls (end-to-end encryption), and transmission security (TLS 1.2 + AES-256).
Does Splashtop support SOC 2?
Yes. Splashtop maintains SOC 2 Type 2 compliance, audited annually by an independent CPA firm. SOC 2 reports cover security, availability, and confidentiality trust services criteria for the Splashtop cloud platform and remote access infrastructure.
Splashtop Architecture & Performance Analysis
Splashtop's proprietary architecture delivers enterprise-grade remote access through a combination of protocol innovation, flexible deployment models, integrated endpoint management, and defense-in-depth security — all at a fraction of the cost of legacy VPN or VDI approaches.
Proprietary Streaming Protocol
- Adaptive bitrate with H.264/H.265/VP9 multi-codec support
- 4:4:4 color mode for lossless design and engineering workflows
- <50ms LAN latency; <100ms cross-region WAN
- Hardware encoding/decoding on supported GPUs
- USB peripheral redirection — stylus, drawing tablets, game controllers
- Seamless multi-monitor spanning across up to 4 displays
Defense-in-Depth Security
- TLS 1.2 + AES-256 signaling; DTLS/SRTP encrypted media
- SAML/SSO with Entra ID, Okta, OneLogin, ADFS
- MFA (TOTP, Duo, push) and device authentication
- IP allowlisting, time-based access, group-based permissions
- Watermarked session recording with full audit trail
- SOC 2 Type II, GDPR, HIPAA-BAA, ISO 27001 certified
Dual Deployment Flexibility
- Splashtop Cloud — fully managed global relay infrastructure
- Splashtop On-Premise — self-hosted gateway behind your firewall
- Zero traffic to Splashtop cloud in on-prem mode
- HA clustering for enterprise-scale resilience
- Air-gapped and data-sovereignty ready
- Minutes to provision cloud; hours for on-prem gateway
Integrated Endpoint Management
- Hardware and software inventory across all managed devices
- Patch management — Windows Update and third-party
- Wake-on-LAN — scheduled and on-demand
- Remote command execution — PowerShell, CMD, Bash
- System info, event logs, services, and processes
- Eliminates need for separate RMM tool for small-to-mid IT teams
Pricing for Regulated Organizations
Splashtop Enterprise (the tier required for on-premise deployment and BAA) is custom-priced based on user count, deployment model, and support tier. Organizations in regulated industries typically choose the Enterprise tier for its on-premise gateway, advanced access policies, session recording, and dedicated support. Contact Splashtop or an authorized partner for current pricing.