Guides · Updated

Is TaxDome HIPAA Compliant? A Straight Answer

TaxDome states plainly in its own Help Center that it is not HIPAA-compliant, even though its data sits on HIPAA-eligible AWS infrastructure under a signed BAA. Here's what that distinction actually means, and where PHI-bearing files should go instead.

No — by TaxDome's own account. TaxDome's Help Center runs a dedicated article titled "Is TaxDome HIPAA-compliant?" and its answer is direct: TaxDome meets industry standards for online security but is not compliant with HIPAA's privacy standards, and healthcare professionals are advised not to enter individually identifiable health information into it. That is TaxDome describing its own product, not a third party's characterization.

This matters beyond healthcare providers themselves. Accounting and bookkeeping firms that serve medical practices, healthcare billing and revenue-cycle clients, or health-benefits administration work are Business Associates under HIPAA the moment they handle a client's protected health information (PHI), and are bound to the same safeguard standard as the covered entity. If your firm runs client work through TaxDome and any of it touches PHI — a medical practice's patient ledgers, a billing dispute, an insurance claim file — TaxDome's own documentation says that data doesn't belong there.

What TaxDome actually says

TaxDome's position, in its own words, has two parts that are easy to conflate and worth separating:

  • The infrastructure is HIPAA-eligible. TaxDome states that all data is stored in HIPAA-compliant, multi-tenant datastores in Amazon Web Services data centers, protected under a signed Business Associate Agreement (BAA) between TaxDome and AWS.
  • The platform itself is not HIPAA-compliant. Despite that infrastructure, TaxDome's own Help Center is explicit that the product does not meet HIPAA's privacy standards, and it recommends against putting individually identifiable health information into it at all.

Those two claims are consistent, not contradictory, and the gap between them is the actual point of this page.

Why "HIPAA-eligible hosting" isn't the same as "HIPAA-compliant platform"

A BAA with AWS covers the physical and infrastructure layer AWS controls — data-center security, hardware, network isolation. It says nothing about what the application built on top of that infrastructure does with the data flowing through it. HIPAA's Security Rule requires the covered entity or Business Associate to implement its own administrative, physical, and technical safeguards on top of that: encryption that meets the standard, access controls tied to individual users, audit logging of every access to ePHI, and a signed BAA between the firm and every vendor that touches the data — not just between the vendor and its cloud provider.

TaxDome running on AWS's HIPAA-eligible infrastructure is a real, useful fact. It is not the same claim as "TaxDome is HIPAA-compliant," and TaxDome's own Help Center draws that line itself rather than leaving it to be inferred. This is the same distinction that shows up across the industry — see what HIPAA actually requires for file sharing for the fuller technical-safeguard breakdown (encryption, access control, unique user identification, audit trails) that determines whether a workflow is compliant, independent of which vendor is involved.

TaxDome's encryption model

TaxDome's published security documentation describes TLS 1.2+ for data in transit and AES-256 for data at rest, with encryption keys rotated regularly. Nothing in its public documentation claims client-side, end-to-end, or zero-knowledge encryption — TaxDome holds the keys as part of its managed SaaS offering (via AWS KMS), meaning TaxDome's own infrastructure can technically decrypt customer files. That is provider-managed encryption, a legitimate and common model, but a different guarantee from zero-knowledge, where the provider is architecturally unable to decrypt regardless of intent, breach, or legal compulsion. TaxDome does not claim otherwise; it simply isn't the model in use.

The certifications TaxDome does and doesn't hold

TaxDome completed a SOC 2 Type I audit examination, reported in April 2024. Its own published pages describe a subsequent SOC 2 Type II certification, audited through the third-party compliance platform Strike Graph and covering security, availability, and confidentiality, with a page date indicating roughly May 2026 — a normal progression, since Type II requires observing controls operate over a period rather than just assessing their design, and typically follows Type I by six to twelve months.

Two certifications commonly assumed are not TaxDome's own. ISO 27001: the ISO 27001 certification referenced in TaxDome's materials belongs to AWS's underlying data centers, not to TaxDome as a company — a common and reasonable inheritance, but worth not conflating with a TaxDome-held certificate. HITRUST: TaxDome publishes a page titled "HITRUST Compliance," but its own wording frames this as TaxDome helping firms meet their HITRUST requirements, not TaxDome itself holding a validated HITRUST assessment (HITRUST's e1/i1/r2 tiers) — confirm directly with TaxDome before treating this as an independent, TaxDome-held credential rather than a services claim. TaxDome doesn't process cards directly; PCI DSS obligations are inherited through its payment partners, Stripe and CPACharge, both independently PCI DSS Level 1.

The January 2025 incident, in context

TaxDome disclosed a security incident on 28 January 2025, reported by Accounting Today: a row-level-security configuration error on a third-party reporting tool briefly let roughly 30 paying firm-side users see high-level aggregate reporting data — revenue figures, client counts by tag — belonging to other firms. TaxDome's own account states no client-identifying detail (Social Security numbers, financial account numbers, documents, or contact information) was exposed, the cause was a configuration error rather than an external attacker, and the exposure window was roughly an hour before the reporting page was pulled. It's a real, dated incident worth knowing about, and it's a modest one: no PHI or client documents were involved, and TaxDome disclosed it promptly. It doesn't change the HIPAA answer above either way — that answer comes from TaxDome's own compliance statement, not from this incident.

Routing PHI-bearing files somewhere else

ShieldFive does not offer a US HIPAA Business Associate Agreement and has no completed external security audit. The comparison below does not recommend it as a replacement channel for protected health information.

CapabilityTaxDomeShieldFive
TaxDome's own HIPAA statementNot HIPAA-compliant; advises against entering PHIN/A — not a HIPAA-covered claim either; see caveats below
Encryption / key custodyProvider-managed AES-256 at rest, TLS 1.2+ in transit; TaxDome/AWS KMS holds the keysClient-side encryption with client-code trust
Post-quantum encryptionNot mentioned in public documentationHybrid default on web and Android, AES-GCM fallback
SOC 2Type I (2024), Type II (~2026, own audit via Strike Graph)None yet — open crypto core + published internal review
ISO 27001AWS infrastructure only, not TaxDome itselfNone
HITRUSTPublishes a page describing help for firms' own HITRUST needs; not confirmed as TaxDome's own validated assessmentNone
Practice management (CRM, pipelines, invoicing, e-sign + KBA)Yes — this is the product's coreNone — encryption-first storage and sharing only
Tax-software integrationDrake, Lacerte, ProConnect, UltraTax (print-to-TaxDome model)None
Indicative price$800/year (Essentials, single-user only) to $1,000–$1,200/user/year (Pro/Business, annual)Free 5 GB; paid from €6/mo (1 TB); Shield+ 2 TB €10/mo

ShieldFive is an encrypted storage and document-request tool with no CRM, e-signature, KBA or tax-software integrations. ShieldFive encrypts files on the device before upload and stores encrypted file data in the EU. Your password never reaches our servers: the browser turns it into a separate login value with Argon2id and sends only that, and the key that opens the vault is derived separately and stays on the device. That service remains part of the trust boundary; this is not an absolute provider-cannot-decrypt guarantee. It does not offer a US HIPAA Business Associate Agreement; do not choose it for a workflow that requires one.

Where TaxDome is genuinely the right tool

None of the above is a case against TaxDome generally. For running an accounting practice — CRM and pipeline automation, unlimited secure document storage, e-signature with per-signer KBA priced at roughly $1 (TaxDome markets this as the lowest in the category) for IRS Form 8879, native integrations with Drake, Lacerte, ProConnect and UltraTax, invoicing and time tracking — TaxDome is a consolidated, mature suite that a narrow storage tool like ShieldFive doesn't attempt to replace. Firms researching "TaxDome alternative" broadly are usually looking for a different practice-management suite (Karbon, Canopy, Financial Cents, Jetpack Workflow, SmartVault), not an encryption-first product; that's a different comparison than this page. For TaxDome next to Canopy, SmartVault, ShareFile, Suralink and Liscio on price, client upload links and reminders, see the accountant file sharing comparison.

Do not treat client-side encryption or a zero-knowledge label as evidence that a service meets your contractual requirements. ShieldFive provides no US HIPAA Business Associate Agreement. Assess the required agreements and controls before routing protected health information through any service.

Frequently asked questions

Is TaxDome HIPAA compliant?

No. TaxDome's own Help Center states it meets industry security standards but is not compliant with HIPAA's privacy standards, and advises against entering individually identifiable health information into the platform.

Is TaxDome's infrastructure HIPAA-compliant even if the platform isn't?

TaxDome states its data is stored in HIPAA-compliant, multi-tenant AWS datastores under a signed BAA between TaxDome and AWS. That covers the infrastructure layer AWS controls; it is not the same as TaxDome itself being HIPAA-compliant at the application level, and TaxDome's own documentation does not claim otherwise.

Is TaxDome zero-knowledge or end-to-end encrypted?

No. TaxDome encrypts data in transit (TLS 1.2+) and at rest (AES-256), but TaxDome (via AWS KMS) holds the encryption keys as part of its managed service, so TaxDome's own infrastructure can technically decrypt customer files. Nothing in its public documentation claims client-side or zero-knowledge encryption.

Is TaxDome SOC 2 certified?

Yes. TaxDome completed a SOC 2 Type I audit examination reported in April 2024, and its own pages describe a subsequent SOC 2 Type II certification around May 2026, audited through Strike Graph. Confirm the current report scope directly with TaxDome before relying on it for a specific compliance requirement.

Is TaxDome ISO 27001 certified?

Not independently. The ISO 27001 certification associated with TaxDome belongs to AWS's underlying data centers, which TaxDome's infrastructure runs on — not to TaxDome as a company. No independently held TaxDome ISO 27001 certificate was found in its public documentation.

What should an accounting firm do if a client engagement involves PHI?

Keep the general practice on TaxDome if it already fits the workflow, and route the specific PHI-bearing files through a channel designed for HIPAA's technical safeguards — client-side encryption, per-file access controls, unique user identification, and audit logging. See what HIPAA actually requires for file sharing for the full safeguard checklist, independent of which vendor you choose.


This page reflects TaxDome's public documentation as of 2026-08-24 and will be updated as the product changes.

Ready to Protect What's Yours?

Encrypted on your device

5 GB free · No card required · Encrypted before upload