HIPAA for SaaS Companies: You Might Need It Even If You're Not in Healthcare
TL;DR
- • HIPAA applies to Business Associates — not just healthcare providers and insurers
- • If your SaaS creates, receives, transmits, or maintains PHI on behalf of a covered entity, you're a Business Associate
- • Business Associates can face penalties up to $1.9M per violation category per year
- • Penalties can apply even without a breach — non-compliance itself is the violation
- • A Business Associate Agreement (BAA) is legally required before you can handle PHI — and signing one without proper controls is a major liability
Most SaaS founders assume HIPAA is someone else's problem — a healthcare issue for hospitals, insurance companies, and medical device makers. That assumption is increasingly dangerous. The reality is that HIPAA's Business Associate rules extend compliance obligations to a surprisingly wide range of technology companies that have never treated a patient or processed a single insurance claim.
What Is HIPAA and Who Does It Actually Cover?
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting sensitive patient health information (PHI). The Act covers three primary entities:
Covered Entities (CEs)
Healthcare providers (hospitals, physician practices, pharmacies), health plans (insurers, HMOs, employer health plans), and healthcare clearinghouses. These are the "traditional" HIPAA entities most people think of.
Business Associates (BAs) — The Surprise Category
A Business Associate is any person or entity that performs functions or activities involving the use or disclosure of PHI on behalf of a covered entity. This is where most technology companies get caught off guard.
Business associates include: EHR vendors, billing service providers, cloud storage providers, analytics platforms, communication tools, scheduling software, data hosting companies, and any SaaS that processes health information on behalf of a covered entity.
Subcontractors of Business Associates
If a Business Associate uses a subcontractor to carry out work involving PHI, that subcontractor is also a Business Associate under HIPAA. This chains compliance obligations through the technology supply chain.
What Counts as PHI?
Protected Health Information (PHI) is any individually identifiable health information that relates to past, present, or future physical or mental health, the provision of healthcare, or the payment for healthcare. The "individually identifiable" element is key — PHI must be linkable to a specific person.
HIPAA defines 18 identifiers that, when combined with health information, create PHI:
Note: ePHI (electronic Protected Health Information) refers specifically to PHI that is created, stored, transmitted, or received in electronic form — which is essentially all PHI your SaaS product touches.
Common SaaS Scenarios That Trigger HIPAA
These are real scenarios where non-healthcare SaaS companies discover they're Business Associates:
HR / benefits platform
Your HR SaaS handles employee health insurance enrollment, FMLA documentation, or disability claims on behalf of employers who are also health plan sponsors. You're a Business Associate.
Scheduling / appointment software
You provide scheduling software to hospitals, physician practices, or therapy providers. Patient appointment data combined with the healthcare context is PHI. You're a Business Associate.
Communication / telehealth platform
Your video, messaging, or communication tool is used by healthcare providers for patient consultations. Any patient messages, video sessions, or related data is PHI. You're a Business Associate.
Analytics / data warehouse
You provide data analytics, business intelligence, or data warehousing services to healthcare organizations. If patient-level data flows through your platform, you're a Business Associate.
Cloud storage / file management
You provide file storage, document management, or cloud backup services to healthcare providers. If they store patient records, test results, or clinical notes in your system, you're a Business Associate.
Billing / payment processing
You process payments for healthcare services or handle medical billing. You handle PHI including diagnoses, treatment codes, and patient identifiers. Definitely a Business Associate.
AI / ML platform in healthcare
Your AI platform processes de-identified clinical data that gets re-linked to patients during analysis. Even "de-identified" data can become PHI if re-identification is possible.
Business Associate Agreements (BAAs)
A Business Associate Agreement is a legally required contract between a covered entity and its business associates that establishes the permitted uses and disclosures of PHI and the BA's obligations to protect it. You cannot legally handle PHI without a signed BAA.
A critical mistake we see constantly: SaaS companies sign BAAs with healthcare customers before having the security controls in place to honor those obligations. Signing a BAA is a legal commitment that your systems comply with HIPAA's Security Rule. Signing without proper controls — and then experiencing a breach — dramatically increases your liability exposure.
What a BAA Must Include
- ✓Permitted uses and disclosures of PHI by the Business Associate
- ✓Prohibition on using or disclosing PHI in ways not permitted by the BAA or required by law
- ✓Obligation to implement appropriate administrative, physical, and technical safeguards
- ✓Obligation to report to the covered entity any use or disclosure not permitted by the BAA, including breaches
- ✓Obligation to ensure any subcontractors agree to the same restrictions (flow-down)
- ✓Obligation to make PHI available to the covered entity and HHS for audit purposes
- ✓At termination, return or destroy all PHI (or justify why return/destruction is infeasible)
HIPAA Security Rule: Technical Safeguards
The HIPAA Security Rule specifies administrative, physical, and technical safeguards for ePHI. Here are the required technical safeguards your SaaS platform must implement:
Access Control (Required)
Unique user identification, emergency access procedures, automatic logoff, and encryption/decryption. Every user accessing ePHI must have a unique ID. Shared accounts are a HIPAA violation.
Audit Controls (Required)
Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. HIPAA requires audit logs — but specifies no minimum retention period. Industry standard is 6 years.
Integrity Controls (Required)
Mechanisms to authenticate ePHI — confirm that ePHI has not been altered or destroyed in an unauthorized manner. This means checksums, hash verification, or digital signatures on sensitive data.
Transmission Security (Required)
Guard against unauthorized access to ePHI transmitted over electronic communications networks. In practice: TLS 1.2+ for all data in transit, no ePHI via unencrypted email or unencrypted API calls.
Encryption at Rest (Addressable)
"Addressable" means you must implement it unless you can document a reasonable alternative that achieves the same result. In practice, any modern SaaS should use AES-256 encryption for ePHI at rest. "Addressable" does not mean optional.
Breach Notification Requirements
Under the HIPAA Breach Notification Rule, Business Associates must notify their covered entity client without unreasonable delay and within 60 calendar days of discovering a breach. The covered entity then has its own notification obligations to affected individuals and HHS.
Breaches affecting 500 or more individuals in a state must be reported to HHS and the media within 60 days. Breaches affecting fewer than 500 individuals must be logged and reported to HHS annually.
Critically: the definition of "breach" under HIPAA includes any impermissible acquisition, access, use, or disclosure of unsecured PHI — not just hacker attacks. Sending an email with patient data to the wrong recipient is a HIPAA breach.
Penalty Structure
| Violation Category | Per Violation | Annual Cap |
|---|---|---|
| Did not know (and couldn't have known) | $141–$71,162 | $35,581 – $1,906,483 |
| Reasonable cause (not willful neglect) | $1,424–$71,162 | $35,581 – $1,906,483 |
| Willful neglect — corrected within 30 days | $14,232–$71,162 | $356,733 – $1,906,483 |
| Willful neglect — not corrected | $71,162+ | $1,906,483+ |
Penalty amounts as adjusted for inflation (2024 figures). Criminal penalties (up to $250K and 10 years imprisonment) apply for intentional PHI violations for personal gain.
HIPAA Compliance Checklist for SaaS Companies
Ready to Simplify Your Compliance?
LowerPlane automates up to 80% of your compliance work across multiple frameworks.
Book a Demo