Summary
HIPAA requires you to document your compliance efforts. Required documentation includes: - Undertrained employees — HIPAA requires documented, role-specific training, not just a one-time onboarding video No. HIPAA requires ongoing compliance, including annual risk analyses, regular employee training, periodic policy reviews, and continuous monitoring of your security controls. Treat it as a program, not a project.
HIPAA Requirements List for SaaS: A Complete Compliance Checklist
If you’re building or operating a SaaS product that touches protected health information (PHI), HIPAA compliance isn’t optional — it’s a legal requirement. But navigating the regulation can feel overwhelming. This guide breaks down the core HIPAA requirements list for SaaS companies into actionable categories, so you know exactly what you need to implement, document, and maintain.
Who Does HIPAA Apply to in the SaaS World?
HIPAA applies to two main categories of organizations:
- Covered Entities (CEs): Healthcare providers, health plans, and healthcare clearinghouses
- Business Associates (BAs): Vendors, including SaaS companies, that create, receive, maintain, or transmit PHI on behalf of a covered entity
Most SaaS companies fall into the Business Associate category. If your platform stores, processes, or transmits PHI — think EHR integrations, telehealth tools, medical billing software, or even analytics platforms used by hospitals — you are likely a Business Associate and must comply with HIPAA.
The Core HIPAA Rules SaaS Companies Must Follow
HIPAA is made up of several rules, each with distinct requirements. Here’s what applies to SaaS:
1. The Privacy Rule
The HIPAA Privacy Rule establishes standards for protecting PHI. For SaaS companies, this primarily means:
- Using and disclosing PHI only as permitted by your Business Associate Agreement (BAA)
- Not using PHI for marketing or commercial purposes without explicit authorization
- Honoring individual rights to access, amend, and receive an accounting of disclosures of their PHI
- Implementing a minimum necessary standard — only access or share the PHI needed to do the job
2. The Security Rule
The Security Rule is the most technically demanding requirement for SaaS platforms. It covers electronic PHI (ePHI) and is divided into three safeguard categories:
Administrative Safeguards
- Designate a HIPAA Security Officer
- Conduct a formal risk analysis and document it
- Implement a risk management plan to address identified vulnerabilities
- Establish workforce training programs on PHI handling
- Create and enforce access management policies
- Develop and test a contingency plan (backup, disaster recovery, and emergency access procedures)
Physical Safeguards
- Control physical access to servers and workstations that store ePHI
- Implement workstation use policies (screen locks, clean desk policies)
- Maintain device and media controls for hardware containing ePHI
- Document procedures for disposing of hardware securely
Technical Safeguards
- Implement access controls (unique user IDs, automatic logoff, encryption)
- Use audit controls to log access to ePHI
- Ensure integrity controls to prevent unauthorized alteration of ePHI
- Encrypt ePHI in transit and at rest (strongly recommended, effectively required)
- Implement transmission security protocols (TLS 1.2 or higher)
3. The Breach Notification Rule
If a breach of unsecured PHI occurs, SaaS companies must:
- Notify the covered entity without unreasonable delay and within 60 days of discovery
- Document the breach thoroughly, including scope, affected individuals, and remediation steps
- Maintain breach logs even for incidents that don’t meet the notification threshold
4. The Omnibus Rule
The 2013 Omnibus Rule extended direct HIPAA liability to Business Associates. This means:
- SaaS companies can be directly fined by the HHS Office for Civil Rights (OCR)
- You must ensure your own subcontractors (sub-BAs) who touch PHI also sign BAAs
- Penalties apply even if your covered entity customer failed to enforce compliance
Business Associate Agreement (BAA) Requirements
A BAA is a legally required contract between a covered entity and any Business Associate who handles PHI. For SaaS companies, the BAA must:
- Describe the permitted uses and disclosures of PHI
- Require the BA to implement appropriate safeguards
- Require reporting of breaches and security incidents
- Ensure the BA will make PHI available for individual rights requests
- Require the return or destruction of PHI upon contract termination
- Mandate that sub-BAs also sign BAAs
Pro tip: Never let a healthcare customer use your platform without a signed BAA in place. Operating without one exposes both parties to significant liability.
Technical Infrastructure Requirements for SaaS Platforms
Beyond the regulatory text, here’s what HIPAA compliance looks like in practice for your SaaS architecture:
Encryption Standards
- Encrypt ePHI at rest using AES-256 or equivalent
- Encrypt ePHI in transit using TLS 1.2 or higher
- Manage encryption keys securely, separate from encrypted data
Access Management
- Implement role-based access control (RBAC)
- Enforce multi-factor authentication (MFA) for all users with PHI access
- Automatically log off inactive sessions
- Maintain detailed user access logs
Audit Logging
- Log all access to ePHI, including read, write, modify, and delete actions
- Store logs securely and retain them for a minimum of 6 years
- Review logs regularly for anomalous activity
Data Backup and Recovery
- Maintain regular, encrypted backups of ePHI
- Test recovery procedures periodically
- Document your recovery time objectives (RTO) and recovery point objectives (RPO)
Vulnerability Management
- Conduct regular penetration testing and vulnerability scans
- Patch known vulnerabilities in a timely manner
- Use intrusion detection and prevention systems
Documentation Requirements
HIPAA requires you to document your compliance efforts. Required documentation includes:
- Risk Analysis and Risk Management Plan
- Policies and Procedures for all administrative, physical, and technical safeguards
- Employee Training Records
- Business Associate Agreements
- Incident and Breach Logs
- Sanction Policy for workforce violations
- Contingency and Disaster Recovery Plans
All HIPAA documentation must be retained for a minimum of 6 years from the date of creation or last effective date.
Common HIPAA Compliance Gaps in SaaS Companies
Even well-intentioned SaaS teams frequently miss these areas:
- No formal risk analysis — a documented risk assessment is required, not just assumed
- Missing BAAs with subcontractors — if you use AWS, Google Cloud, or third-party analytics tools that touch ePHI, you need BAAs with them too
- Inadequate audit logging — many SaaS platforms log errors but not PHI access events
- Undertrained employees — HIPAA requires documented, role-specific training, not just a one-time onboarding video
- No breach response plan — you need a written procedure before an incident happens, not after
HIPAA Compliance Checklist Summary
Use this quick-reference checklist to assess your current standing:
- [ ] Signed BAAs with all covered entity customers
- [ ] Signed BAAs with all sub-BAs (subcontractors touching PHI)
- [ ] Designated HIPAA Security Officer
- [ ] Completed and documented Risk Analysis
- [ ] Written Risk Management Plan
- [ ] Administrative, physical, and technical safeguard policies in place
- [ ] Employee HIPAA training program with records
- [ ] ePHI encrypted at rest and in transit
- [ ] Access controls and MFA implemented
- [ ] Audit logging enabled and retained for 6 years
- [ ] Breach notification procedure documented
- [ ] Contingency and disaster recovery plan tested
- [ ] All documentation retained for 6 years
Frequently Asked Questions
Does my SaaS company need to be HIPAA compliant if we don’t store PHI directly?
Possibly. If your platform transmits, processes, or even temporarily caches PHI — even in memory — you likely qualify as a Business Associate. The key test is whether you create, receive, maintain, or transmit PHI on behalf of a covered entity. When in doubt, consult a healthcare attorney.
What is the penalty for HIPAA non-compliance for SaaS companies?
Penalties range from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. Willful neglect that isn’t corrected can result in criminal charges. Since the Omnibus Rule, Business Associates face the same penalty tiers as covered entities.
Do I need a third-party HIPAA audit?
HIPAA does not legally require a third-party audit, but it strongly implies one through its risk analysis requirements. Many covered entities will require you to provide a SOC 2 Type II report or evidence of a third-party security assessment before signing a BAA. Proactive audits also help you identify gaps before regulators do.
How long does it take to become HIPAA compliant as a SaaS company?
For a small SaaS team starting from scratch, expect 3 to 6 months to implement all required safeguards and documentation. Larger organizations with complex infrastructure may take longer. Using pre-built policy templates and compliance frameworks can significantly accelerate this timeline.
Is HIPAA compliance a one-time project?
No. HIPAA requires ongoing compliance, including annual risk analyses, regular employee training, periodic policy reviews, and continuous monitoring of your security controls. Treat it as a program, not a project.
Get HIPAA-Compliant Faster with Ready-to-Use Templates
Building HIPAA documentation from scratch is time-consuming, error-prone, and expensive when done with outside counsel. Our professionally written HIPAA compliance template bundle gives SaaS companies everything they need to get compliant quickly:
- ✅ Risk Analysis and Risk Management Plan templates
- ✅ Administrative, Physical, and Technical Safeguard policies
- ✅ Business Associate Agreement template
- ✅ Breach Notification Procedure
- ✅ Employee Training Acknowledgment forms
- ✅ Incident Response Plan
- ✅ Contingency and Disaster Recovery Plan
Stop reinventing the wheel. Our templates are written by compliance experts, formatted for immediate use, and regularly updated to reflect the latest OCR guidance.
👉 [Browse our HIPAA compliance template packages and get compliant today.]
Best for teams building a HIPAA documentation and readiness baseline.
HIPAA Security + Privacy Rule documentation with audit-readiness artifacts
View template →