Skip to content

United States · Applies by law

HIPAA compliance

Health Insurance Portability and Accountability Act

SaaS handling protected health information for US covered entities, which makes you a Business Associate with direct liability.

The context

What it actually asks of you

HIPAA reaches SaaS companies through the Business Associate relationship. The moment a covered entity, a hospital, clinic, insurer or their vendor, sends you protected health information, you acquire direct statutory liability under the Security Rule and the breach notification requirements.

The rule most teams underestimate is §164.308(a)(1)(ii)(A): a documented, accurate and thorough risk analysis covering every system that touches PHI. It is not optional, it is not satisfied by a penetration test, and it is the first document requested after any incident or complaint.

The good news is that HIPAA's Security Rule maps cleanly onto controls a competent SaaS company should already run. If you have ISO 27001 or SOC 2 work under way, most of the technical safeguards are already in scope and the incremental effort is smaller than teams expect.

The common mistake

What teams get wrong.

Signing a BAA does not make you compliant; it makes you liable. The Security Rule requires a documented risk analysis, and that analysis is the first thing requested after any incident.

Our scope

What we do for HIPAA.

  1. 01Security Rule administrative, physical and technical safeguards
  2. 02Documented risk analysis and risk management plan (§164.308)
  3. 03Business Associate Agreement review and sub-processor flow-down
  4. 04Audit controls, encryption and access management for PHI
  5. 05Breach notification procedures and the 60-day clock
  6. 06Workforce training with retained records

innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.

Questions

HIPAA FAQ

You are already liable, so the priority is closing the gap quickly and quietly. Start with the risk analysis, encryption of PHI at rest and in transit, audit controls and access management. We routinely take teams from signed-but-unready to defensible inside eight weeks.

No. There is no government-recognised HIPAA certification, and any vendor selling one is selling their own opinion. What you can have is an independent assessment against the Security Rule, which is what buyers actually accept.

PHI is broader than names. It includes any of the eighteen identifiers linked to health information, including device identifiers, IP addresses in some contexts, and dates. De-identification is a defined standard with two specific methods; assuming you have met it is a common and expensive mistake.

Find out whether HIPAA binds you.

Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.