SaaS

HIPAA for SaaS companies

Plenty of SaaS companies that never set out to build for healthcare get pulled into HIPAA the first time a healthcare customer needs a Business Associate Agreement. If your product can store or transmit protected health information (PHI), HIPAA applies to you as a business associate.

Start free HIPAA overview

Why it matters for SaaS

A single healthcare customer can turn HIPAA into a deal requirement. Serving a covered entity that puts PHI into your product makes you a business associate, which means signing a Business Associate Agreement (BAA) and evidencing the safeguards HIPAA requires.

What to focus on

You are likely a business associate

A general-purpose SaaS handling PHI on behalf of a covered entity is a business associate under HIPAA. That means a signed BAA with each such customer, plus the safeguards and breach-notification obligations HIPAA places on associates.

The Security Rule safeguards

The HIPAA Security Rule organizes requirements into administrative, physical, and technical safeguards: risk analysis, access controls, audit controls, encryption where appropriate, and workforce training. These map to controls a mature SaaS team already runs.

Limit where PHI can go

The less of your platform that touches PHI, the smaller your HIPAA surface. Segregating and minimizing PHI, and being deliberate about which features and subprocessors handle it, keeps the obligation contained rather than sprawling across the product.

Do it once, not twice

Keel is built on one crosswalked control library, so a control you implement for HIPAA counts toward every other framework it satisfies. Add a second framework later and it mostly reuses this work. See the crosswalk explorer for the exact overlap.

Start free Check your readiness

Common questions

We are not a healthcare company, so why does HIPAA apply?

Because HIPAA follows the data, not the industry label. If a covered entity puts PHI into your SaaS, you are acting as a business associate and take on HIPAA obligations, including a BAA and the Security Rule safeguards.

Does HIPAA replace SOC 2 for a SaaS company?

No. HIPAA is a legal obligation tied to PHI; SOC 2 is the assurance report most buyers request. They share many controls (access, encryption, monitoring, incident response), so on Keel you collect the evidence once and it serves both.

Do I put PHI into Keel?

No. Keel is your compliance-management workspace - controls, policies, risk analysis, and evidence that your safeguards operate - not a system of record for protected health information. Keep PHI out of Keel; because Keel does not store or process your PHI, it is not your business associate and no BAA with Keel is required.

Framework names are referenced factually for guidance. Keel is not affiliated with or endorsed by the bodies that publish them. See our legal and trademarks page.