HIPAA Compliant Remote Access for Healthcare, Finance & Legal

Yes, Splashtop signs a HIPAA BAA. Splashtop Enterprise delivers HIPAA-compliant remote access with a signed Business Associate Agreement (BAA), SOC 2 Type II certification, end-to-end AES-256 encryption, and comprehensive audit controls — all while maintaining the 4K/60fps performance that clinical imaging, financial modeling, and document review demand.

Compliance Requirements by Sector

Healthcare

Primary Framework: HIPAA Security Rule (45 CFR Parts 160, 162, 164)

  • BAA required with all vendors handling ePHI
  • Access controls: unique user IDs, emergency access, automatic logoff
  • Audit controls: hardware, software, and procedural mechanisms to record and examine access
  • Integrity controls: ePHI must not be improperly altered or destroyed
  • Transmission security: encryption of all ePHI in transit

Financial Services

Primary Framework: GLBA, SEC, FINRA, SOX

  • Customer information safeguards (GLBA Safeguards Rule)
  • Session recording and retention for FINRA/SEC compliance
  • Multi-factor authentication for all remote access
  • Audit trails for user access to sensitive systems
  • Data residency and sovereignty controls

Legal

Primary Framework: ABA Model Rules, State Bar Regulations

  • Client confidentiality (attorney-client privilege)
  • Secure transmission of privileged documents
  • Access controls for document management systems
  • Audit trails for discovery responses
  • Mobile and remote work compliance

Splashtop Compliance & Security Architecture

Splashtop meets the technical safeguards required by HIPAA, GLBA, and other regulatory frameworks through a defense-in-depth architecture. Our Splashtop Enterprise review provides detailed coverage of the full security model.

Splashtop vs. Remote Access Tools for Compliance

Splashtop vs. Remote Access Tools for Compliance
Feature Splashtop EnterpriseTeamViewerAnyDeskChrome Remote Desktop Action
Business Associate Agreement (BAA) AvailableAvailableAvailableNot available
Encryption Standard TLS 1.2 + AES-256 / DTLS + SRTPAES-256 / RSA-4096TLS 1.2 + AES-256WebRTC/DTLS
Access Controls Role-based, group-based, IP allowlist, time-basedRole-based, device groupsRole-based, device profilesGoogle account only
Audit Controls Full session audit logs, watermarked recordingSession loggingSession loggingNo
Integrity Controls End-to-end encryption for all data in transitEnd-to-end encryptionEnd-to-end encryptionIn-transit only
Transmission Security TLS 1.2 + DTLS/SRTPTLS + proprietaryTLS + DeskRTWebRTC
Device Authentication Device binding + MFADevice assignment + MFADevice auth + MFAGoogle account + 2FA
Session Recording Built-in with watermarkingYes (add-on)Limited (add-on)No
MFA TOTP, Duo, push notificationsYesYesGoogle 2FA only
SSO Integration SAML: Entra ID, Okta, OneLogin, ADFSSAML SSOSAML SSOGoogle SSO only
On-Premise Option Yes — self-hosted gatewayNoOn-prem relayNo
Certifications SOC 2 Type II, GDPR, ISO 27001SOC 2, ISO 27001, HIPAASOC 2, ISO 27001None

Key Compliance Features

  • Business Associate Agreement (BAA): Splashtop executes BAAs covering all HIPAA-covered entities and business associates. Required before any ePHI transits the platform.
  • End-to-End Encryption: TLS 1.2 + AES-256 for signaling; DTLS/SRTP for media streams. No Splashtop infrastructure can decrypt session content.
  • On-Premise Deployment: Self-hosted gateway option eliminates data transit to Splashtop cloud — sessions stay entirely within your network boundary. Critical for healthcare and financial organizations with data sovereignty requirements.
  • Session Recording: Built-in, watermarked session recording with playback. Every remote session is captured with visual watermarking for audit and compliance review.
  • Access Controls: Role-based, group-based, IP allowlisted, and time-windowed access policies. Integrates with Entra ID, Okta, OneLogin, and ADFS via SAML SSO.
  • Certifications: SOC 2 Type II (audited annually), GDPR compliant, ISO 27001 certified, HIPAA-BAA ready.

Deployment for Compliance

  1. Execute BAA with Splashtop before any production deployment involving ePHI.
  2. Deploy Splashtop On-Premise gateway behind your firewall if data sovereignty or zero-cloud-exposure is required.
  3. Configure access policies — enforce MFA, set IP allowlists, enable session recording with watermarking, and configure automatic logoff timeouts.
  4. Integrate SSO via SAML with your identity provider — enforce conditional access policies (device compliance, location, risk score).
  5. Enable audit logging and forward logs to your SIEM for centralized compliance monitoring.
  6. Train users and administrators on HIPAA-compliant remote access workflows.

For a structured compliance evaluation framework across remote access vendors, see our comparison matrix.

Frequently Asked Questions

Does Splashtop sign a HIPAA BAA?

Yes. Splashtop executes Business Associate Agreements (BAAs) with covered entities and business associates. The BAA covers all HIPAA-required technical safeguards for remote access involving ePHI.

Is Splashtop remote access HIPAA compliant?

Yes. Splashtop Enterprise meets HIPAA technical safeguards including access controls (role-based, MFA, IP allowlist), audit controls (session recording with watermarking), integrity controls (end-to-end encryption), and transmission security (TLS 1.2 + AES-256).

What remote access software is HIPAA compliant?

Splashtop Enterprise, TeamViewer, and AnyDesk all offer HIPAA compliance with BAA availability. Splashtop differentiates with an on-premise gateway option for data sovereignty and included session recording.

Can Splashtop be used for healthcare remote access?

Yes. Splashtop Enterprise is widely used in healthcare for telehealth, clinical imaging review, EHR access, and IT support. It supports HIPAA-compliant BAA, 4K/60fps streaming for medical imaging, and on-premise deployment for data sovereignty.

Is Splashtop suitable for financial services compliance?

Yes. Splashtop Enterprise meets GLBA, SOX, and FINRA requirements with SOC 2 Type II certification, session recording, MFA, and access controls. The on-premise gateway option supports data residency requirements.

Is Splashtop HIPAA compliant?

Yes. Splashtop Enterprise is HIPAA compliant when deployed with a signed BAA. It meets all HIPAA Security Rule technical safeguards: access controls (role-based, MFA, IP allowlist), audit controls (session recording with watermarking), integrity controls (end-to-end encryption), and transmission security (TLS 1.2 + AES-256).

Does Splashtop support SOC 2?

Yes. Splashtop maintains SOC 2 Type 2 compliance, audited annually by an independent CPA firm. SOC 2 reports cover security, availability, and confidentiality trust services criteria for the Splashtop cloud platform and remote access infrastructure.

Splashtop Architecture & Performance Analysis

Splashtop's proprietary architecture delivers enterprise-grade remote access through a combination of protocol innovation, flexible deployment models, integrated endpoint management, and defense-in-depth security — all at a fraction of the cost of legacy VPN or VDI approaches.

Proprietary Streaming Protocol

  • Adaptive bitrate with H.264/H.265/VP9 multi-codec support
  • 4:4:4 color mode for lossless design and engineering workflows
  • <50ms LAN latency; <100ms cross-region WAN
  • Hardware encoding/decoding on supported GPUs
  • USB peripheral redirection — stylus, drawing tablets, game controllers
  • Seamless multi-monitor spanning across up to 4 displays

Defense-in-Depth Security

  • TLS 1.2 + AES-256 signaling; DTLS/SRTP encrypted media
  • SAML/SSO with Entra ID, Okta, OneLogin, ADFS
  • MFA (TOTP, Duo, push) and device authentication
  • IP allowlisting, time-based access, group-based permissions
  • Watermarked session recording with full audit trail
  • SOC 2 Type II, GDPR, HIPAA-BAA, ISO 27001 certified

Dual Deployment Flexibility

  • Splashtop Cloud — fully managed global relay infrastructure
  • Splashtop On-Premise — self-hosted gateway behind your firewall
  • Zero traffic to Splashtop cloud in on-prem mode
  • HA clustering for enterprise-scale resilience
  • Air-gapped and data-sovereignty ready
  • Minutes to provision cloud; hours for on-prem gateway

Integrated Endpoint Management

  • Hardware and software inventory across all managed devices
  • Patch management — Windows Update and third-party
  • Wake-on-LAN — scheduled and on-demand
  • Remote command execution — PowerShell, CMD, Bash
  • System info, event logs, services, and processes
  • Eliminates need for separate RMM tool for small-to-mid IT teams

Pricing for Regulated Organizations

Splashtop Enterprise (the tier required for on-premise deployment and BAA) is custom-priced based on user count, deployment model, and support tier. Organizations in regulated industries typically choose the Enterprise tier for its on-premise gateway, advanced access policies, session recording, and dedicated support. Contact Splashtop or an authorized partner for current pricing.

Ready to Deploy Splashtop Enterprise?

Splashtop Enterprise signs BAAs and meets HIPAA technical safeguards. Start a free trial and complete your compliance deployment.

Start Splashtop Free Trial