HIPAA & privacy
Does my startup need to be HIPAA compliant?
Short answer
You need to comply with HIPAA if you are a covered entity (a health plan, healthcare clearinghouse, or a healthcare provider that transmits health information electronically) or a business associate (a vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity). If your product handles PHI for a covered entity, you are a business associate and HIPAA applies to you.
Covered entity vs business associate
Covered entities are health plans, clearinghouses, and providers that bill electronically. A business associate is any vendor that handles PHI on a covered entity’s behalf, which is where most health-tech SaaS companies land.
When a SaaS is a business associate
If your product stores, processes, or transmits PHI for a customer that is a covered entity (or another business associate), you are a business associate. You will need a signed BAA and the safeguards HIPAA requires.
What compliance involves
The HIPAA Security Rule’s administrative, physical, and technical safeguards, a documented risk analysis, workforce training, a breach-notification process, and BAAs both up (with your customers) and down (with your subprocessors).
FAQ
-
If we never look at the data, are we still covered?
- Yes. If you store or transmit PHI on a covered entity’s behalf, you are a business associate even if you never access the data yourself.
-
Is HIPAA a certification?
- No. There is no official HIPAA certificate. You demonstrate compliance through your safeguards, documentation, risk analysis, and BAAs, not a pass/fail exam.
Next step
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.