Does my startup need to be HIPAA compliant?
You need to comply with HIPAA if you are a covered entity (a health plan, healthcare clearinghouse, or a healthcare provider that transmits health information electronically) or a business associate (a vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity). If your product handles PHI for a covered entity, you are a business associate and HIPAA applies to you.
Covered entity vs business associate
Covered entities are health plans, clearinghouses, and providers that bill electronically. A business associate is any vendor that handles PHI on a covered entity’s behalf, which is where most health-tech SaaS companies land.
When a SaaS is a business associate
If your product stores, processes, or transmits PHI for a customer that is a covered entity (or another business associate), you are a business associate. You will need a signed BAA and the safeguards HIPAA requires.
What compliance involves
The HIPAA Security Rule’s administrative, physical, and technical safeguards, a documented risk analysis, workforce training, a breach-notification process, and BAAs both up (with your customers) and down (with your subprocessors).
FAQ
If we never look at the data, are we still covered?
Yes. If you store or transmit PHI on a covered entity’s behalf, you are a business associate even if you never access the data yourself.
Is HIPAA a certification?
No. There is no official HIPAA certificate. You demonstrate compliance through your safeguards, documentation, risk analysis, and BAAs, not a pass/fail exam.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free