HIPAA Compliance for SaaS Companies: A Practical Guide for SMBs (2025)
SaaS companies that store, process, or transmit protected health information (PHI) on behalf of covered entities must comply with HIPAA as Business Associates. This requires a signed BAA, technical safeguards, risk assessments, and documented policies. Non-compliance penalties range from $100 to $50,000 per violation.
Is my SaaS company a Business Associate under HIPAA?
Yes, if your SaaS product creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity (hospital, clinic, insurer, or healthcare clearinghouse), you are a Business Associate under 45 CFR §160.103. This applies even if you only process PHI incidentally, such as through a support ticket system or an analytics pipeline that includes patient identifiers.
Does using AWS or Google Cloud make my SaaS product HIPAA compliant?
No. Signing a BAA with AWS, Google Cloud, or Azure makes those providers HIPAA-eligible infrastructure vendors, but compliance depends on how you configure and use their services. You must enable encryption, configure access controls, implement audit logging, and restrict PHI to services covered under the provider's BAA. Misconfigured cloud environments remain a leading cause of healthcare data breaches.
What happens if a SaaS company does not have a signed BAA with its healthcare clients?
Operating without a BAA is an independent HIPAA violation under 45 CFR §164.504(e). OCR can issue penalties even if no breach occurred. A missing BAA also gives your healthcare client grounds to terminate your contract immediately and seek damages. Many enterprise healthcare procurement processes require a fully executed BAA before any data transfer begins.
How often does a SaaS company need to conduct a HIPAA risk assessment?
HHS requires risk assessments to be conducted on an ongoing basis (45 CFR §164.308(a)(1)). In practice, OCR expects a full formal risk assessment at least annually and whenever there is a significant change to your environment, such as a new product feature, a change in cloud infrastructure, or a merger. A risk assessment performed more than 12 months ago is typically considered stale in an OCR audit.
What is the difference between a HIPAA audit and a SOC 2 audit for SaaS companies?
SOC 2 is a formal third-party audit resulting in a report issued under AICPA standards. HIPAA has no equivalent government-issued certification. HIPAA compliance is self-attested and evidence-based. Many SaaS companies pursue SOC 2 Type II with the HIPAA criteria mapped in as additional controls. This provides customers with an independent auditor's report and reduces the burden of individual customer security questionnaires.
Can a small SaaS startup with fewer than 25 employees achieve HIPAA compliance?
Yes. HIPAA does not set a minimum company size. Small companies must meet the same substantive requirements as large enterprises, though the scale of implementation is proportionate. A 10-person SaaS startup can designate one employee as both Security Officer and Privacy Officer, use a compliance platform like Accountable HQ or Compliancy Group, and complete a risk assessment using a qualified consultant. The key is documentation and evidence, not headcount.
What should a SaaS company do first when starting a HIPAA compliance program?
Conduct a formal risk analysis as your first step. This is the foundational requirement under 45 CFR §164.308(a)(1)(ii)(A) and gives you a prioritized list of gaps to remediate. Simultaneously, audit your existing vendor relationships to identify subcontractors who handle PHI without a signed BAA. These two actions address the most common OCR findings and give your compliance program a defensible starting point.