Back to blog
    Frameworks

    HIPAA for SaaS companies: a 2026 overview

    BAA scope, technical safeguards, and the auditor expectations that have shifted in the past year.

    Andreas Van Nimmen Feb 27, 2026 6 min readLast verified Feb 27, 2026

    HIPAA compliance for SaaS companies is one of the most misunderstood corners of the compliance landscape. There is no "HIPAA certification". No body issues a stamp that says you're compliant. What there is, instead, is a set of obligations that attach to any Business Associate that handles Protected Health Information (PHI) on behalf of a Covered Entity, enforced through HHS audits, breach reporting, and contractual liability flowed down via Business Associate Agreements (BAAs).

    The first question for any SaaS company is whether you actually touch PHI. If your customers are healthcare providers, payers, or health-adjacent businesses, and your platform stores, processes, or transmits identifiable health information on their behalf, you're a Business Associate. If your platform never sees PHI, even if your customers are healthcare companies, you may not need a BAA at all. Scoping this honestly upfront saves enormous downstream effort.

    Once you've confirmed BA status, the technical safeguards required under the Security Rule are the table stakes: encryption in transit and at rest, access controls with least privilege, audit logging of PHI access, automatic logoff, integrity controls, and a formal risk analysis updated annually. In 2026, auditor expectations have shifted noticeably on two fronts: vendor management (your subprocessors that touch PHI need their own BAAs and risk reviews) and breach detection (passive logging isn't enough; you need active monitoring with documented response timelines).

    Administrative safeguards trip up more SaaS companies than the technical ones. You need a designated Security Officer and Privacy Officer (can be the same person at small companies), workforce training with completion tracking, sanction policies for violations, and a formal contingency plan covering data backup, disaster recovery, and emergency mode operations. These need to be real documents that people have actually read, not boilerplate downloaded from a template site.

    Finally, the BAA itself. The form you sign with your healthcare customers will flow specific obligations through to you: breach notification timelines (typically 24–72 hours rather than the statutory 60 days), audit rights, indemnification scope, and subcontractor restrictions. Read every BAA carefully. They vary widely, and accepting an aggressive one can create operational obligations you're not equipped to meet.

    Frequently asked questions

    Is there a HIPAA certification for SaaS companies?
    No. There is no "HIPAA certification" and no body that issues a compliance stamp. HIPAA obligations attach to a Business Associate that handles PHI on behalf of a Covered Entity, enforced through HHS audits, breach reporting, and BAA liability.
    When does a SaaS company need a Business Associate Agreement?
    You need a BAA when your platform stores, processes, or transmits identifiable health information on behalf of a healthcare provider, payer, or health-adjacent customer. If your platform never sees PHI, you may not need a BAA at all.
    What counts as PHI under HIPAA?
    PHI is identifiable health information that your platform stores, processes, or transmits on behalf of a Covered Entity. The first question is whether your platform actually touches PHI; scoping this honestly upfront saves enormous downstream effort.
    What is the difference between technical and administrative safeguards?
    Technical safeguards are the security controls: encryption in transit and at rest, access controls with least privilege, audit logging of PHI access, automatic logoff, and integrity controls. Administrative safeguards are the people and process requirements: a designated Security Officer and Privacy Officer, workforce training with completion tracking, sanction policies, and a formal contingency plan covering backup, disaster recovery, and emergency mode operations.
    What should I watch for in a Business Associate Agreement?
    BAAs vary widely. Look for breach notification timelines (often 24–72 hours rather than the statutory 60 days), audit rights, indemnification scope, and subcontractor restrictions. Accepting an aggressive BAA can create operational obligations you're not equipped to meet.

    Ready to find your auditor?

    Browse independent firms or post a bid request and let qualified auditors come to you.