Skip to content

HIPAA for SaaS and tech companies

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

You do not have to be a hospital for HIPAA to apply. Touch PHI on behalf of a covered entity and you are a business associate, on the hook.

When HIPAA applies to you

HIPAA reaches beyond hospitals and insurers (the "covered entities"). If your software creates, receives, maintains, or transmits protected health information (PHI) on behalf of one of those healthcare customers, you are a business associate — and HIPAA applies to you directly. Selling to a single hospital can pull a SaaS into scope.

The Business Associate Agreement

Your healthcare customer will require a BAA — a contract that binds you to protect PHI and defines responsibilities and breach obligations. Signing one is a commitment, not a formality: it makes your HIPAA obligations contractual and enforceable. Your own subprocessors that touch PHI need BAAs too.

What you actually owe

As a business associate you owe the HIPAA Security Rule: administrative, physical, and technical safeguards for electronic PHI — access controls, encryption, audit logging, a risk analysis, training, and an incident/breach process. Much of this overlaps with SOC 2 and ISO 27001, so existing security work counts.

Shrink the surface

The smartest move is to minimise what touches PHI: isolate the systems that handle it, avoid storing PHI you do not need, and keep the rest of your stack out of scope. A small PHI footprint is a small HIPAA footprint. SentinelPanda maps the HIPAA safeguards to your existing controls so you are not building a separate programme.

HIPAA business associate agreements HIPAA Security Rule safeguards Which compliance framework should you do first?

Run your compliance program in one workspace.