Are You a Business Associate?
If you create, receive, maintain or transmit protected health information on behalf of a covered entity, you are a business associate. That is broader than most software teams assume — it includes hosting PHI, processing it, analysing it, and having incidental access while providing support.
The practical test is simpler than the legal one: if a healthcare customer has sent you a BAA to sign, they have already concluded you are one.
| Your product | Business associate? |
|---|---|
| Stores or processes patient data for a provider | Yes |
| Analytics over data that includes PHI | Yes |
| Support tooling with access to customer records | Yes, even if access is incidental |
| Infrastructure hosting a covered entity's systems | Yes — the conduit exception is narrow |
| A product healthcare staff use that never touches PHI | Generally no |
Subcontractors of business associates are captured too. If you use a subprocessor that touches PHI, you owe them a BAA in turn.
You Are Directly Liable
This is the part that surprises software companies, and it changes how seriously the obligation should be taken.
Since the HITECH Act and the Omnibus Rule, business associates are directly liable for Security Rule compliance and for certain Privacy Rule provisions. OCR can investigate and penalise you directly. Your obligation does not run only through your customer's contract — it runs to the regulator.
Which means the BAA is not the compliance work. The BAA is a contract in which you represent that you have done the compliance work. Signing one you cannot substantiate creates two exposures instead of one — see HIPAA penalties and enforcement.
What Actually Applies to You
Business associates get most of the Security Rule and a narrower slice of the Privacy Rule.
| Obligation | Applies to a BA? | What it means in practice |
|---|---|---|
| Security Rule — all safeguards | Fully | Administrative, physical and technical |
| Risk analysis | Required | The document OCR asks for first |
| Breach notification | Yes | Notify the covered entity, on a defined timeline |
| BAAs with subcontractors | Yes | Flows down the chain |
| Workforce training | Yes | Delivered and evidenced |
| Privacy Rule | Partly | Use and disclosure limits; most patient-facing duties stay with the covered entity |
| Notice of Privacy Practices | No | The covered entity's obligation |
See the 18 safeguard standards for the detail, and what a BAA must contain.
HIPAA and SOC 2 Together
Most SaaS companies asked for a BAA are also being asked for a SOC 2 report, usually by different people at the same customer. They are different instruments — one a legal obligation, one a voluntary attestation — but the underlying control work overlaps heavily.
| Control area | HIPAA | SOC 2 | Shared? |
|---|---|---|---|
| Access control and MFA | Technical safeguard | CC6 | Yes |
| Encryption in transit and at rest | Addressable | CC6 | Yes |
| Audit logging | Technical safeguard | CC7 | Yes |
| Incident response | Administrative | CC7 | Yes |
| Vendor management | BAAs | CC9 | Largely |
| Workforce training | Administrative | CC1 | Yes |
| Risk analysis | Required, specific form | CC3, different shape | Partly |
| Independent audit | None exists | CPA firm required | No |
Running them together is materially cheaper than sequentially. One control implementation, one evidence programme, two outcomes. See SOC 2 compliance — readiness there starts at $7,000.
Our Engagement
1. PHI mapping and scoping. Which systems touch PHI, including the ones nobody catalogued.
2. Security Rule risk analysis. Documented properly, in the form an investigator expects.
3. Safeguard remediation. Administrative, physical and technical, prioritised by risk.
4. BAA programme. Reviewing what your customers send you, and issuing them to your own subprocessors.
5. Breach procedures. Written so they could actually be followed on the day.
6. Workforce training. Delivered and evidenced.
7. Evidence package. What you show a customer's security team when they ask how you handle PHI.
Cost and Timeline
| Tier | Employees | HIPAA engagement | With SOC 2 together | Max duration |
|---|---|---|---|---|
| Startup | 5–50 | from $3,000 | + from $7,000 | 60 days |
| Mid-Market | 51–200 | around $7,500 | + around $16,000 | 60 days |
| Large Enterprise | 201–500 | up to $12,000 | + up to $25,000 | 60 days |
Combined engagements come in below the sum of the two, because the control work is shared. No certification body fee applies to the HIPAA side — there is no HIPAA certificate.
Get a Scoped Quote
Tell us what PHI your product touches and whether SOC 2 is also on the table. Scoped estimate within 24 hours.
Our form could not load. Email your PHI scope and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formHIPAA for SaaS FAQs
Is my SaaS company a HIPAA business associate?
If you create, receive, maintain or transmit protected health information on behalf of a covered entity, yes. That includes hosting it, processing it, analysing it, or having incidental access while providing support. If a healthcare customer has sent you a BAA to sign, they have already concluded you are one.
Are business associates directly liable under HIPAA?
Yes. Since the HITECH Act and the Omnibus Rule, business associates are directly liable for Security Rule compliance and for certain Privacy Rule provisions. OCR can investigate and penalise a business associate directly — the obligation is not purely contractual through the covered entity.
What does a SaaS company have to do for HIPAA?
Conduct and document a Security Rule risk analysis, implement the administrative, physical and technical safeguards, execute BAAs with customers and with any subcontractor touching PHI, maintain breach notification procedures, train your workforce, and keep the documentation current. There is no certification at the end of it.
Do I need HIPAA if I already have SOC 2?
Yes, they are different things. SOC 2 is a voluntary attestation about your controls; HIPAA is a legal obligation if you handle PHI. The good news is substantial overlap — access control, encryption, logging, incident response and vendor management serve both — so running them together is considerably cheaper than sequentially.
Can I sign a BAA before I am actually HIPAA compliant?
You can physically sign it, and companies do. What you are signing is a contractual representation about safeguards you may not have implemented, which converts a compliance gap into a contractual breach as well. If a BAA is on your desk and the risk analysis does not exist, that ordering is the problem to fix.
Does using AWS or Google Cloud make me HIPAA compliant?
No. Major cloud providers will sign a BAA and offer HIPAA-eligible services, which covers their layer of the shared responsibility model. Everything above it — access control, audit logging, workforce training, your own risk analysis and your own BAAs — remains yours. A signed cloud BAA is a prerequisite, not compliance.
Related Reading
Start with the HIPAA risk assessment, understand what a BAA must contain, see the 18 safeguard standards, or read about HITRUST if a health system is asking for something verifiable.
Official reference: HHS, Business Associates.
Sign the BAA from a defensible position
Risk analysis, safeguards and evidence — often alongside SOC 2 in one programme.