What is HIPAA compliance and when does a SaaS company need it?

March 6, 20262 min readBeyond SOC 2

When Does a SaaS Company Need HIPAA?

You need HIPAA if your software handles Protected Health Information (PHI). Specifically:

Your CustomerData You HandleHIPAA Required?
Hospital or clinicPatient records, appointment dataYes
Health insurance companyClaims data, member informationYes
Healthcare software vendorPHI passed through your systemYes (business associate)
Wellness app (no PHI)Step counts, general health tipsNo
Non-healthcare companyEmployee data (not PHI)No

What HIPAA Requires

RequirementWhat It Means
Business Associate Agreement (BAA)Legal contract with healthcare customers defining your PHI responsibilities
Administrative safeguardsPolicies, training, risk assessment for PHI handling
Physical safeguardsPhysical access controls for systems with PHI
Technical safeguardsEncryption, access controls, audit logging for PHI
Breach notification60-day notification requirement for PHI breaches

HIPAA vs. SOC 2

AspectSOC 2HIPAA
Applies toAny company (voluntary)Companies handling PHI (mandatory)
CertificationAudit reportSelf-attestation + BAA
Penalty for non-complianceNone (it's voluntary)Fines up to $1.5M per violation
FrameworkTrust Services CriteriaHIPAA Security Rule + Privacy Rule
AuditorCPA firmSelf-attestation (no formal audit required, but recommended)

SOC 2 + HIPAA

Many healthcare SaaS companies pursue both. SOC 2 provides the independent audit report that healthcare buyers want to see, while HIPAA compliance is the legal requirement for handling PHI. About 60% of SOC 2 controls satisfy HIPAA requirements — so doing both is more manageable than doing them separately.

Getting Started

  1. Determine if you actually handle PHI (many SaaS companies don't)
  2. If yes, start with SOC 2 to build your control foundation
  3. Layer HIPAA-specific controls on top (BAA process, PHI data mapping, breach notification)
  4. Have a lawyer draft your BAA template

Ready to Automate Your Compliance?

Join 50+ companies automating their compliance evidence with Screenata.

© 2025 Screenata. All rights reserved.