HIPAA Compliance by Vertical
HIPAA Compliance for Healthcare SaaS Companies
HIPAA compliance for healthcare SaaS — you are a business associate the moment you process PHI; here is the practical 90-day path to BAA-ready.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- PHI in scope: Anything your customers send through your API or upload to your platform, Logs and metrics that may contain PHI snippets, Support tickets and screenshots from customer staff, AI/ML training data derived from customer usage.
- Start with these controls: PHI inventory across all storage, logs, and analytics; Modern BAA template (the 12-clause 2026 version); Subcontractor list with BAA per subcontractor.
- The most common mistake: Production logs with raw PHI; no log scrubbing
- A signed BAA is required with every vendor that touches PHI, and no tool is HIPAA compliant on its own.
PHI handled in this environment
- Anything your customers send through your API or upload to your platform
- Logs and metrics that may contain PHI snippets
- Support tickets and screenshots from customer staff
- AI/ML training data derived from customer usage
- Backups, replicas, and analytics warehouses
Common compliance pain points
- PHI you did not know you had: Logs, support attachments, AI training data — most healthcare SaaS companies have PHI in places their architecture diagram does not show. The first compliance task is finding it.
- BAA-readiness vs HIPAA-compliance vs SOC 2: Customers ask "are you HIPAA-compliant?" but what they need is a current BAA, documented controls, and (frequently) SOC 2 Type II. Treat these as a three-leg stool, not a single signature.
- AI training and inference flows: If your platform uses AI on customer data, prompts and outputs flow to LLM providers. Each requires a BAA-covered path or a BYOK architecture where the customer controls the flow.
- Subcontractor sprawl: Modern SaaS uses dozens of vendors. Sentry, DataDog, LogRocket, Stripe, Twilio, Postmark — every one that touches PHI is a subcontractor. Each requires a BAA, listed in your customer disclosures.
Priority controls
- PHI inventory across all storage, logs, and analytics
- Modern BAA template (the 12-clause 2026 version)
- Subcontractor list with BAA per subcontractor
- AI flow documentation (BYOK preferred for customer trust)
- SOC 2 Type II to satisfy enterprise procurement
- Customer-facing trust center documenting controls
Common mistakes
- Production logs with raw PHI; no log scrubbing
- Sentry/DataDog/Postmark in production without BAA
- AI training on customer PHI without explicit authorization
- No SOC 2 Type II despite enterprise customer demands
- Single BAA template signed by sales reps without legal review
Enforcement context
Healthcare SaaS companies have rapidly become the #1 source of business-associate breach reports. The 2026 Security Rule extends mandatory technical controls directly to business associates — meaning startup-grade "we will get to it" is no longer a viable strategy. Several settlements over $1M in 2024–2025 involved SaaS startups whose customers (covered entities) bore reputational damage from the SaaS's controls.
Frequently asked questions
What PHI do healthcare SaaS organizations handle?
Anything your customers send through your API or upload to your platform; Logs and metrics that may contain PHI snippets; Support tickets and screenshots from customer staff; AI/ML training data derived from customer usage; Backups, replicas, and analytics warehouses. Any of these, combined with an identifier, is protected health information and brings the full Security Rule into scope.
What are the priority HIPAA controls for healthcare SaaS?
PHI inventory across all storage, logs, and analytics; Modern BAA template (the 12-clause 2026 version); Subcontractor list with BAA per subcontractor; AI flow documentation (BYOK preferred for customer trust); SOC 2 Type II to satisfy enterprise procurement; Customer-facing trust center documenting controls.
What are the most common HIPAA mistakes in healthcare SaaS?
Production logs with raw PHI; no log scrubbing; Sentry/DataDog/Postmark in production without BAA; AI training on customer PHI without explicit authorization; No SOC 2 Type II despite enterprise customer demands; Single BAA template signed by sales reps without legal review.
What does HIPAA enforcement look like for healthcare SaaS?
Healthcare SaaS companies have rapidly become the #1 source of business-associate breach reports. The 2026 Security Rule extends mandatory technical controls directly to business associates — meaning startup-grade "we will get to it" is no longer a viable strategy. Several settlements over $1M in 2024–2025 involved SaaS startups whose customers (covered entities) bore reputational damage from the SaaS's controls.