HIPAA Compliant Scheduling Free: Setup Guide
HIPAA-compliant scheduling requires a Business Associate Agreement. Learn why free tools fail, compare Cal.com options, and secure healthcare scheduling.
- HIPAA-compliant scheduling requires a Business Associate Agreement; free tools like Calendly don't offer one.
- The five non-negotiable controls are encryption, access management, audit logging, session timeout, and BAA signature.
- Cal.com self-hosted is free (you pay $70-180/month for infrastructure) and gives you full control over ePHI.
- Managed hosting with Doxy.me ($25/month) or Opsily's Cal.com option eliminate server maintenance.
- Set up HIPAA scheduling in seven steps: BAA negotiation, deployment choice, encryption config, access control, audit logs, documentation, and staff training.
Yes, HIPAA-compliant scheduling exists and can be free or nearly free, but the word "free" is a trap. Free tools like Calendly don't include Business Associate Agreements, which are legally required for healthcare providers. True compliance starts with a BAA, then adds specific security controls. The good news: Cal.com (open-source, 48.7K GitHub stars) offers both self-hosted and managed options that support HIPAA.
What HIPAA Compliance Actually Requires
HIPAA requires covered entities and business associates to protect electronic protected health information (ePHI). A Business Associate Agreement is the legal foundation: it's a contract between you and any vendor that touches patient data, defining who's responsible for what. Without a BAA, no amount of encryption or access controls makes you compliant.
Too many healthcare providers believe security tools equal compliance. They do not. A BAA does. Your scheduling software is just one piece of the puzzle. The vendor must sign the BAA, agreeing to specific protections: data encryption, access controls, breach notification procedures, and audit logs. You also agree to hold your end: staff training, incident response plans, secure data deletion.
HIPAA applies to covered entities (hospitals, clinics, health plans, healthcare clearinghouses) and business associates (anyone handling ePHI on their behalf, including scheduling vendors). If your patients' names, medical record numbers, or appointment details are in the software, it's ePHI. If you're covered and using a vendor without a BAA, you're in violation, period.
The Office for Civil Rights (OCR) enforces HIPAA. Violations cost: $100-$50,000 per incident, plus reputation damage, plus potential class-action liability. A HIPAA breach notification can destroy a solo practice's reputation and patient trust. The BAA is your first line of defense.
Why Free Scheduling Tools Fail (and Why Calendly Is the Cautionary Tale)
Calendly is the 800-pound gorilla in scheduling. It's also a cautionary tale for HIPAA compliance. Calendly does not offer Business Associate Agreements at any price tier. For a healthcare provider, this makes Calendly non-compliant, full stop. If you need alternatives that do support HIPAA, explore Cal.com hosting options and HIPAA-ready scheduling tools.
Google Calendar, Doodle, and other consumer freebies have the same problem. They're built for scheduling coffee meetings, not protecting patient data. Even if they claimed to offer a BAA, there's no medical-grade security underneath. These tools typically:
- Store data in shared, multi-tenant databases where encryption keys are held by the provider, not the customer. You don't control the key; they do.
- Do not provide audit logs showing who accessed what and when.
- Do not offer role-based access control. Anyone with the link sees everything.
- Do not contractually obligate the vendor to notify you of a breach within 60 days (HIPAA requirement).
- Use consumer infrastructure built for scale, not security. SOC 2, ISO 27001, or HIPAA readiness was never the goal.
Calendly explicitly states in its terms that it is not HIPAA-compliant and will not negotiate BAAs. This isn't a limitation you can pay your way out of; it's by design. Their business model is built on simplicity and cost, not regulated industries.
The Five Non-Negotiable Security Controls
Any HIPAA-compliant scheduling system must have these five features. These are the minimum; you may need more depending on your risk analysis.
-
Encryption in Transit and at Rest. Data moving to and from the software must be encrypted (TLS 1.2 or higher). Data sitting in the database must also be encrypted. The vendor must hold the encryption keys, not you, or you assume the entire encryption burden. Cal.com self-hosted puts this responsibility on you; managed Cal.com or a hosted provider handles it.
-
Role-Based Access Control. Not every staff member needs to see every patient slot. Admins, schedulers, and clinicians should have separate permission levels. Access should be restricted by role: an admin can configure settings; a receptionist can book appointments but not see billing; a clinician can only see their own schedule. Calendly and Google Calendar offer zero role-based control.
-
Audit Logs. You must keep a record of every access to ePHI: who logged in, when, what they did, and from where. HIPAA requires you to retain these logs for six years. Calendly provides no audit logs. Cal.com (self-hosted and managed) provides audit logs. This is non-negotiable for compliance validation.
-
Session Timeout and Multi-Factor Authentication. After 15-30 minutes of inactivity, sessions should automatically expire. Any access to ePHI should require multi-factor authentication (MFA) if the user logs in from an unknown location or after a reset. Calendly offers neither.
-
Business Associate Agreement. Signed by both parties, defining liability, data handling, breach procedures, and survival clauses (what happens if the vendor goes out of business). No BAA, no compliance.
Free & Low-Cost Options with HIPAA Readiness
Here's the hard truth: truly free tools don't include BAAs. However, some tools offer free tiers for individuals or small practices with paid BAA-enabled plans, and a few are legitimately free if you self-host.
| Tool | Self-Hosted Cost | Managed Cost | BAA Included | Complexity |
|---|---|---|---|---|
| Cal.com | Free (infrastructure only) | From $99/month (managed) | Yes, with paid tier | Low (managed), Medium (self-hosted) |
| Doxy.me | N/A | From $25/month | Yes, at all tiers | Very Low |
| Setmore | N/A | Free with limitations; paid tiers $15+/month | No on free tier; yes on paid | Low |
| Jotform Appointments | N/A | Free with limitations; BAA at $30+/month | No on free; yes on paid | Low |
| Acuity Scheduling | N/A | Starting $15/month | No on free; yes on premium tiers | Low |
| EasyAppointments | Free (self-hosted) | N/A | Yes (you sign as the BAA owner) | High |
Translation: If you want free AND BAA, self-hosted Cal.com or EasyAppointments is your only play. You cover infrastructure costs (could be $20-100/month for a small practice). If you want a managed option with BAA at low cost, Doxy.me is the cheapest at $25/month. Understand that the word "free" often means either free tier without BAA (limiting use to individual practitioners) or free self-hosted software (requiring you to manage servers and security).
Cal.com: Self-Hosting for HIPAA Compliance
Cal.com is open-source (48.7K GitHub stars, actively maintained, last commit September 2026). It's built for scheduling but is agnostic about compliance; you implement the security controls yourself. Visit Opsily's guide to self-hosted Cal.com for detailed deployment steps to get started.
Self-hosting means you control the infrastructure, the database, the encryption keys, and the network. You are the business associate. You don't sign a BAA with Cal.com because you own the whole system. This eliminates one vendor risk: you don't have to trust their security; you're responsible for it.
For a small to mid-size practice, self-hosted Cal.com typically runs on a virtual private server (VPS) starting at $20-30/month. You can add managed database backups, load balancing, and monitoring for $50-150/month more. Total: a healthcare-grade scheduling system for $70-180/month, with encryption keys you control. This is significantly cheaper than managed HIPAA-compliant platforms that often start at $300/month or more.
Cal.com's features support HIPAA implementation: role-based permissions (create admin, scheduler, and clinician accounts with granular permissions), audit logs (all activity is logged and can be exported for compliance audits), API and webhooks (integrate with your EHR or practice management system if needed), self-hosted infrastructure (you control data residency, encryption, and access), and GDPR-compliant design (supports data deletion, data portability, and retention policies).
The tradeoff: you need technical capacity (or a contractor) to deploy, monitor, and maintain the server. Patches, updates, backups, and security hardening become your job. For a solo practice without an IT person, this is a burden. For a 20+ person group with an IT director, it's manageable. This is where managed hosting becomes attractive.
How to Set Up HIPAA-Compliant Scheduling (Step-by-Step)
This guide assumes you've chosen a tool (Cal.com self-hosted, Doxy.me, or another BAA-ready platform) and you're now configuring it for production.
Step 1: Execute a Business Associate Agreement (if applicable). Contact your vendor and request a BAA. Have a lawyer review it. The BAA should cover data encryption, breach notification (within 60 days), data deletion, subcontractors, and liability limitations. Ensure survival clauses exist: if the vendor shuts down, they must delete all your ePHI or return it within 30 days. Once signed, keep a copy in your compliance folder. This is proof to OCR if you're ever audited.
Step 2: Choose Your Deployment Model. Self-hosted (Cal.com on a VPS, EasyAppointments on your server) means you're the business associate and do not sign a BAA with anyone, but you manage the server. Managed hosting (Doxy.me, managed Cal.com, SimplePractice) means the vendor is the business associate and should provide a BAA. Decide based on your technical capacity and risk tolerance. A medical director at a 50-person clinic? Managed is worth the cost. A solo psychiatrist with one part-time admin? Self-hosted Cal.com might be more cost-effective, but only if you have IT support.
Step 3: Configure Encryption. If self-hosted, ensure your VPS has full-disk encryption (Linux dm-crypt or Windows BitLocker). Use TLS 1.2+ for all network traffic (your hosting provider handles this). If managed, the vendor handles encryption; verify their encryption policy in the BAA.
Step 4: Set Up Access Control and Authentication. Create separate accounts for each staff role: admin (configure settings), scheduler (book and reschedule), clinician (view only), and patient (book their own appointments). Assign the minimum permissions each role needs. Enable multi-factor authentication (MFA) for all staff accounts. Disable password sharing; each person gets their own login.
Step 5: Enable Audit Logging and Retention. Ensure audit logs are enabled and cannot be disabled by a user. Logs should record who, what, when, and from where. Archive logs to a separate storage location (cloud backup or external drive) and retain for six years. Test log export monthly to ensure backup procedures work.
Step 6: Document Your Policies. Write down your incident response plan (what happens if a patient's appointment is exposed), your data retention policy (delete records after X years), and your staff training plan (every new hire gets HIPAA training). OCR expects documentation. It proves you're taking compliance seriously. Review policies annually and update them if your system changes.
Step 7: Train Your Staff. Every staff member with access to ePHI needs HIPAA training. Cover what ePHI is, who can access it, when they should delete data, and what to do if they suspect a breach. Document the training (date, attendee, topics). Retrain annually.
When to Self-Host vs Managed Hosting
The decision comes down to four factors: practice size, technical capacity, budget, and risk tolerance.
Self-Host Cal.com (or EasyAppointments) if:
- Your practice has fewer than 50 staff members.
- You have an IT person on staff or a trusted contractor who can maintain the server.
- You prefer lower monthly costs ($70-180/month vs $300+/month for managed).
- You're comfortable being the business associate and owning the security stack.
- You can commit to patches, backups, and monitoring.
Use Managed Hosting if:
- Your practice has 50+ staff members.
- You have no IT capacity in-house.
- You prefer simplicity and support.
- You want a vendor to be the business associate and share liability.
- You're willing to pay for peace of mind ($300-1000+/month depending on the platform).
Hybrid Option: Run Cal.com self-hosted for core scheduling but use a managed HIPAA-compliant platform (like Doxy.me or Opsily's managed Cal.com) for video visits or complex integrations you don't want to maintain yourself. Opsily offers managed Cal.com hosting specifically for this use case: you get the self-hosted Cal.com software without the DevOps overhead, hosted in EU data centers, where Opsily handles the server administration and you focus on HIPAA policy, staffing, and training.
Frequently Asked Questions
Which scheduling apps are HIPAA compliant?
Any scheduling app with a signed Business Associate Agreement can be HIPAA-compliant if you implement the five security controls. Cal.com (self-hosted or managed), Doxy.me, EasyAppointments, and others can work. Calendly, Google Calendar, and Doodle cannot because they don't offer BAAs. Compliance is a shared responsibility; the software is only one part.
Is Google scheduling HIPAA compliant?
No. Google does not offer BAAs for Google Calendar or Google Meet Appointments. Google's terms of service explicitly exclude healthcare use cases under HIPAA. If you store appointment data in Google Calendar, you're in violation if you're a covered entity or business associate.
Does HIPAA apply to scheduling appointments?
Yes, if the appointment data includes any electronic protected health information (ePHI). Patient names, medical record numbers, diagnosis hints, appointment reasons, or any identifiable health data must be protected. Even a calendar entry "Patient 123 - follow-up" could be ePHI. If you're unsure, assume it is and apply HIPAA rules.
Can Calendly be HIPAA compliant?
Not currently. Calendly does not offer Business Associate Agreements and explicitly states it does not support HIPAA compliance. You cannot use Calendly for scheduling healthcare appointments without violating HIPAA.
Is there a better option than Calendly?
For healthcare, yes. Doxy.me, SimplePractice, and Cal.com (managed or self-hosted) are HIPAA-ready. For non-healthcare scheduling, Calendly is efficient and widely used. The question is not "better"; it's "compliant for my use case." If you're a healthcare provider, Calendly isn't an option.
Can you make Google HIPAA compliant?
No. Google does not support HIPAA BAAs for Google Calendar or Workspace. Even if you add encryption layers on top, Google's data processing terms do not satisfy HIPAA requirements. You cannot force compliance onto a platform that doesn't support it.
The Bottom Line
HIPAA-compliant scheduling is achievable and affordable. The catch is that "free" almost always excludes the Business Associate Agreement, which is the legal foundation of compliance. Cal.com self-hosted is genuinely free (you pay only for infrastructure, $70-180/month) and gives you full control. Managed options like Doxy.me or Opsily's managed Cal.com hosting cost more but eliminate DevOps overhead.
Start here: understand whether your practice is a covered entity or business associate under HIPAA (most healthcare practices are). If yes, you must have a BAA with any vendor you use. Once you have a tool (Cal.com, Doxy.me, etc.) and a signed BAA, implement the five security controls: encryption, access control, audit logs, session timeout, and staff training. Document everything.
Ready to skip the infrastructure maintenance? Explore Opsily's managed Cal.com hosting to avoid building and maintaining your own servers.