+91 98804 42758

HIPAA Compliance for SaaS Companies

A healthcare customer sent you a BAA and now HIPAA is your problem too. Here is what genuinely applies to a business associate — and what overlaps with the SOC 2 you are probably also being asked for.

Updated August 2026 10 min read Compliance

Are You a Business Associate?

If you create, receive, maintain or transmit protected health information on behalf of a covered entity, you are a business associate. That is broader than most software teams assume — it includes hosting PHI, processing it, analysing it, and having incidental access while providing support.

The practical test is simpler than the legal one: if a healthcare customer has sent you a BAA to sign, they have already concluded you are one.

Your productBusiness associate?
Stores or processes patient data for a providerYes
Analytics over data that includes PHIYes
Support tooling with access to customer recordsYes, even if access is incidental
Infrastructure hosting a covered entity's systemsYes — the conduit exception is narrow
A product healthcare staff use that never touches PHIGenerally no

Subcontractors of business associates are captured too. If you use a subprocessor that touches PHI, you owe them a BAA in turn.

You Are Directly Liable

This is the part that surprises software companies, and it changes how seriously the obligation should be taken.

Since the HITECH Act and the Omnibus Rule, business associates are directly liable for Security Rule compliance and for certain Privacy Rule provisions. OCR can investigate and penalise you directly. Your obligation does not run only through your customer's contract — it runs to the regulator.

Which means the BAA is not the compliance work. The BAA is a contract in which you represent that you have done the compliance work. Signing one you cannot substantiate creates two exposures instead of one — see HIPAA penalties and enforcement.

What Actually Applies to You

Business associates get most of the Security Rule and a narrower slice of the Privacy Rule.

ObligationApplies to a BA?What it means in practice
Security Rule — all safeguardsFullyAdministrative, physical and technical
Risk analysisRequiredThe document OCR asks for first
Breach notificationYesNotify the covered entity, on a defined timeline
BAAs with subcontractorsYesFlows down the chain
Workforce trainingYesDelivered and evidenced
Privacy RulePartlyUse and disclosure limits; most patient-facing duties stay with the covered entity
Notice of Privacy PracticesNoThe covered entity's obligation

See the 18 safeguard standards for the detail, and what a BAA must contain.

HIPAA and SOC 2 Together

Most SaaS companies asked for a BAA are also being asked for a SOC 2 report, usually by different people at the same customer. They are different instruments — one a legal obligation, one a voluntary attestation — but the underlying control work overlaps heavily.

Control areaHIPAASOC 2Shared?
Access control and MFATechnical safeguardCC6Yes
Encryption in transit and at restAddressableCC6Yes
Audit loggingTechnical safeguardCC7Yes
Incident responseAdministrativeCC7Yes
Vendor managementBAAsCC9Largely
Workforce trainingAdministrativeCC1Yes
Risk analysisRequired, specific formCC3, different shapePartly
Independent auditNone existsCPA firm requiredNo

Running them together is materially cheaper than sequentially. One control implementation, one evidence programme, two outcomes. See SOC 2 compliance — readiness there starts at $7,000.

Our Engagement

1. PHI mapping and scoping. Which systems touch PHI, including the ones nobody catalogued.

2. Security Rule risk analysis. Documented properly, in the form an investigator expects.

3. Safeguard remediation. Administrative, physical and technical, prioritised by risk.

4. BAA programme. Reviewing what your customers send you, and issuing them to your own subprocessors.

5. Breach procedures. Written so they could actually be followed on the day.

6. Workforce training. Delivered and evidenced.

7. Evidence package. What you show a customer's security team when they ask how you handle PHI.

Cost and Timeline

TierEmployeesHIPAA engagementWith SOC 2 togetherMax duration
Startup5–50from $3,000+ from $7,00060 days
Mid-Market51–200around $7,500+ around $16,00060 days
Large Enterprise201–500up to $12,000+ up to $25,00060 days

Combined engagements come in below the sum of the two, because the control work is shared. No certification body fee applies to the HIPAA side — there is no HIPAA certificate.

Get a Scoped Quote

Tell us what PHI your product touches and whether SOC 2 is also on the table. Scoped estimate within 24 hours.

HIPAA for SaaS FAQs

Is my SaaS company a HIPAA business associate?

If you create, receive, maintain or transmit protected health information on behalf of a covered entity, yes. That includes hosting it, processing it, analysing it, or having incidental access while providing support. If a healthcare customer has sent you a BAA to sign, they have already concluded you are one.

Are business associates directly liable under HIPAA?

Yes. Since the HITECH Act and the Omnibus Rule, business associates are directly liable for Security Rule compliance and for certain Privacy Rule provisions. OCR can investigate and penalise a business associate directly — the obligation is not purely contractual through the covered entity.

What does a SaaS company have to do for HIPAA?

Conduct and document a Security Rule risk analysis, implement the administrative, physical and technical safeguards, execute BAAs with customers and with any subcontractor touching PHI, maintain breach notification procedures, train your workforce, and keep the documentation current. There is no certification at the end of it.

Do I need HIPAA if I already have SOC 2?

Yes, they are different things. SOC 2 is a voluntary attestation about your controls; HIPAA is a legal obligation if you handle PHI. The good news is substantial overlap — access control, encryption, logging, incident response and vendor management serve both — so running them together is considerably cheaper than sequentially.

Can I sign a BAA before I am actually HIPAA compliant?

You can physically sign it, and companies do. What you are signing is a contractual representation about safeguards you may not have implemented, which converts a compliance gap into a contractual breach as well. If a BAA is on your desk and the risk analysis does not exist, that ordering is the problem to fix.

Does using AWS or Google Cloud make me HIPAA compliant?

No. Major cloud providers will sign a BAA and offer HIPAA-eligible services, which covers their layer of the shared responsibility model. Everything above it — access control, audit logging, workforce training, your own risk analysis and your own BAAs — remains yours. A signed cloud BAA is a prerequisite, not compliance.

Related Reading

Start with the HIPAA risk assessment, understand what a BAA must contain, see the 18 safeguard standards, or read about HITRUST if a health system is asking for something verifiable.

Official reference: HHS, Business Associates.

Sign the BAA from a defensible position

Risk analysis, safeguards and evidence — often alongside SOC 2 in one programme.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.