Skip to content
ResourcesContact
Sign inTalk to a lawyer
  1. Home/
  2. Resources/
  3. Enterprise SaaS
Enterprise SaaS

HIPAA Compliance for SaaS: The Founder's Guide

Ben SuCo-founder & Head of Legal Service Delivery, LegalLayer · Lawyer·Updated Aug 12, 2026·11 min read

By Ben Su — Co-founder & Head of Legal Service Delivery at LegalLayer, and a lawyer. Last updated August 12, 2026.

HIPAA compliance for SaaS turns on whether you handle protected health information on behalf of a health-care provider, health plan, or clearinghouse. If yes, your SaaS is a "business associate" — sign a Business Associate Agreement before data flows and follow HIPAA's Security, Privacy, and Breach rules. If no, HIPAA may not apply, but FTC and state health-data laws often do.

If you build digital-health software in the US — telehealth, patient intake, scheduling, remote monitoring, an EHR-adjacent tool, or health analytics — HIPAA is the compliance question your first enterprise customer will ask about. This guide explains exactly what puts a SaaS under HIPAA, how to become and stay compliant, what the penalties are, and the newer federal and state rules that reach health apps HIPAA never touched.

This is general information, not legal advice. The specifics below are sourced to the primary regulators — HHS and the FTC — and to the statute, but which rules bind your company depends on your customers, your data, and where your users are.

Which US privacy laws apply to a healthcare SaaS company?

A US healthcare SaaS usually faces two layers of privacy law: HIPAA, if it works with health-care organizations, and a consumer-protection layer that applies to health data regardless of HIPAA. Most founders know the first layer and get blindsided by the second.

  • HIPAA — the Health Insurance Portability and Accountability Act. It governs "covered entities" (providers, health plans, clearinghouses) and their "business associates," and it is the law behind Business Associate Agreements, the Security Rule, and breach notification.

  • The FTC Act and the FTC Health Breach Notification Rule — the Federal Trade Commission polices unfair or deceptive data practices, and its Health Breach Notification Rule applies to health apps and connected devices not covered by HIPAA (FTC).

  • State consumer-health-data laws — led by Washington's My Health My Data Act, these regulate "consumer health data" broadly and, in Washington's case, let consumers sue (Goodwin).

  • State comprehensive privacy laws (CCPA/CPRA and peers) — California and other states regulate personal information generally. Data already regulated as PHI under HIPAA is largely carved out, but the rest of what your app collects is not.

The practical rule: HIPAA is the floor if you serve health-care organizations; the FTC and state health-data laws are the floor if you serve consumers directly. Many SaaS companies straddle both and owe both.

What makes a SaaS a HIPAA "business associate"?

A SaaS becomes subject to HIPAA when it handles protected health information on behalf of a covered entity — at which point it is a "business associate." The trigger is the relationship and the data, not whether the company calls itself a health-tech company.

A covered entity is a health-care provider that transmits health information electronically, a health plan, or a health-care clearinghouse. These are the organizations HIPAA regulates directly.

A business associate is a person or organization, other than a covered entity's workforce, that creates, receives, maintains, or transmits protected health information (PHI) to perform a function or service for a covered entity — or a subcontractor that does the same for another business associate (U.S. Department of Health and Human Services). Cloud hosting, an EHR platform, an analytics tool, a scheduling app, or a patient-portal chatbot that touches PHI all qualify.

Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or business associate, in any form. In electronic form it is called ePHI.

If your SaaS stores, processes, or transmits PHI so a US provider or health plan can do its job, you are almost certainly a business associate — and HIPAA requires a signed Business Associate Agreement before that PHI reaches you.

Example: why Flo and Apple Fitness usually aren't covered by HIPAA

Holding health data does not, by itself, make you a business associate — the trigger is whom you handle it for. A direct-to-consumer app that collects health data straight from its users is the clearest illustration.

  • A period- or fertility-tracking app (like Flo) collects sensitive reproductive-health data, but from consumers directly, not on behalf of a covered entity. That is why Flo's 2021 case was a Federal Trade Commission matter over alleged deceptive data-sharing, enforced under the FTC Act, not HIPAA (FTC).

  • Apple Fitness / Apple Health stores workouts and heart-rate data, but Apple is not a covered entity, and data you log yourself is not PHI under HIPAA.

The distinction matters, but it is not a free pass. As the next section shows, the FTC's Health Breach Notification Rule and state consumer-health-data laws were written precisely to cover the apps HIPAA misses. And the analysis flips the moment a consumer app starts handling data on behalf of a provider or plan — then a Business Associate Agreement becomes mandatory.

How do you become and stay HIPAA compliant?

Becoming HIPAA compliant as a SaaS business associate comes down to a signed BAA plus the three HIPAA rules — Security, Privacy, and Breach Notification — operationalized in your product and your company. Here is the practical checklist.

  1. Sign a Business Associate Agreement before any PHI flows. HIPAA requires a written BAA with every covered entity you serve, and with every subcontractor of yours that touches PHI. The BAA sets permitted uses, safeguard obligations, breach-reporting duties, and return-or-destroy terms. No signed BAA, no lawful PHI.

  2. Implement the Security Rule safeguards. HIPAA's Security Rule requires administrative, physical, and technical safeguards for ePHI — including a risk analysis, access controls, encryption, audit logging, and workforce training. Build these in; they are what a customer's security review checks.

  3. Apply the Privacy Rule's "minimum necessary" standard. Use and disclose only the PHI needed for the task you were engaged to do. Do not repurpose PHI — for model training, analytics, or new features — without a lawful basis and the covered entity's authorization.

  4. Stand up breach notification with the right clock. Under HIPAA's Breach Notification Rule, individuals must be notified without unreasonable delay and no later than 60 days after discovery of a breach; a business associate must notify the covered entity within the same 60-day window; and HHS is notified within 60 days for breaches affecting 500 or more individuals, or annually for smaller ones (HHS).

  5. Document everything. HIPAA compliance is provable, not assumed. Keep your risk analysis, policies, BAAs, and training records — regulators and enterprise buyers both ask to see them.

Getting these right is what lets you answer "yes, we're HIPAA compliant, here's our BAA and our safeguards" in a security review without hesitating — which is often what unblocks the deal.

What laws apply when HIPAA doesn't? (The part founders miss)

When HIPAA does not apply to a health app, two other regimes usually do: the FTC's Health Breach Notification Rule and state consumer-health-data laws. Both were expanded specifically to close the "consumer health app" gap HIPAA leaves open.

The FTC Health Breach Notification Rule requires vendors of personal health records and related health apps that are not covered by HIPAA to notify affected individuals, the FTC, and in some cases the media when unsecured identifiable health information is breached. The FTC's 2024 update made two things explicit: the rule covers health and wellness apps and connected devices, and a "breach" is not limited to hacks — an unauthorized disclosure, such as sharing health data with an advertising platform, counts. Notification to individuals is required within 60 days, and to the FTC simultaneously for breaches affecting 500 or more people (FTC).

Washington's My Health My Data Act (MHMDA) is the most demanding of the new state consumer-health-data laws. It defines "consumer health data" expansively — including data that identifies a consumer's health status, and even health information inferred from non-health data — and it applies to entities doing business in Washington or targeting Washington consumers, with no small-business revenue threshold. It requires a standalone consumer-health-data privacy policy, opt-in consent to collect health data and separate consent to share it, and bans geofencing around health-care facilities. Critically, MHMDA carries a private right of action, meaning consumers can sue directly. Its main obligations took effect March 31, 2024 (June 30, 2024 for small businesses), and it exempts data already regulated by HIPAA (Goodwin). Other states have followed with their own consumer-health-data rules, so a national consumer app should not assume Washington is the only one.

The takeaway: falling outside HIPAA narrows your obligations, it doesn't erase them. A consumer health app still answers to the FTC and, increasingly, to state health-data laws with real teeth.

What are the penalties for HIPAA violations?

HIPAA civil penalties are tiered by how culpable the violation was, and the dollar amounts are adjusted for inflation each year. The table below shows the tiers as adjusted for 2025; treat the figures as a snapshot and confirm the current-year amounts before relying on a specific number.

HIPAA civil penalty tiers (2025) Culpability Minimum per violation Maximum per violation Annual cap per category
Tier 1 Lack of knowledge ~$145 ~$36,506 ~$36,506
Tier 2 Reasonable cause ~$1,461 ~$73,011 ~$146,053
Tier 3 Willful neglect (corrected) ~$14,602 ~$73,011 ~$365,052
Tier 4 Willful neglect (uncorrected 30+ days) ~$73,011 ~$2,190,294 ~$2,190,294

2025 inflation-adjusted amounts as compiled by the HIPAA Journal; verify the current-year figures on HHS's enforcement pages before relying on them.

On top of civil penalties, HIPAA carries criminal penalties for knowing violations: up to $50,000 and one year in prison at the base level, rising to fines up to $250,000 and up to 10 years in prison for offenses committed with intent to sell or use PHI for commercial advantage or malicious harm. State attorneys general can also bring HIPAA enforcement actions, and the FTC and state regulators add their own penalties for the non-HIPAA laws above. For a SaaS company, the practical exposure is rarely just a fine — it's the enterprise customer that walks when your compliance can't survive their security review.

Frequently asked questions

Is my SaaS a HIPAA business associate?

Your SaaS is a HIPAA business associate if it creates, receives, maintains, or transmits protected health information on behalf of a covered entity (a health-care provider, health plan, or clearinghouse) or another business associate. The trigger is handling PHI for a covered entity, not whether your product is marketed as a health tool. If that describes you, HIPAA requires a signed Business Associate Agreement before PHI is shared with you.

Do I need a Business Associate Agreement (BAA)?

Yes, if you handle protected health information on behalf of a HIPAA covered entity or another business associate. HIPAA requires a written Business Associate Agreement to be in place before that protected health information is shared with you, and your subcontractors that touch PHI need BAAs too.

Does HIPAA apply to consumer health apps?

Usually not. HIPAA applies to covered entities and their business associates, not to direct-to-consumer apps that collect health data straight from users. A period tracker or fitness app is generally outside HIPAA. But the FTC's Health Breach Notification Rule and state consumer-health-data laws such as Washington's My Health My Data Act can apply to those apps instead, so "not HIPAA" does not mean "no rules."

What are the penalties for a HIPAA violation?

HIPAA civil penalties are tiered by culpability and adjusted for inflation each year. As of 2025 they range from about $145 per violation at the lowest tier to a maximum around $2.19 million per violation category per year for uncorrected willful neglect. Criminal violations can carry fines up to $250,000 and up to 10 years in prison for the most serious offenses.

What is the FTC Health Breach Notification Rule?

The FTC Health Breach Notification Rule requires vendors of personal health records and health apps that are not covered by HIPAA to notify consumers, the FTC, and sometimes the media when unsecured identifiable health information is breached. The FTC's 2024 update made clear it covers health and wellness apps and that an unauthorized disclosure, such as sharing data with advertisers, counts as a breach.

About the author: Ben Su is Co-founder and Head of Legal Service Delivery at LegalLayer, and a lawyer. He works with growth-stage and health-technology companies on the enterprise contracts — MSAs, BAAs, and DPAs — that turn privacy obligations into signable deals.

This article is general information, not legal advice. Privacy laws change and their application depends on your specific facts — consult a qualified healthcare-privacy attorney for your situation. If it would help to have your Business Associate Agreements and data terms drafted and negotiated quickly and consistently, that's the kind of work LegalLayer does.

Make the next legal step with confidence.

Talk to a lawyer

LegalBooks combines practical startup workflows with lawyer review when the decision calls for it.

Ben SuCo-founder & Head of Legal Service Delivery, LegalLayer · Lawyer·Updated Aug 12, 2026·11 min read

Ben Su is Co-founder and Head of Legal Service Delivery at LegalLayer, and a lawyer.

TermsPrivacyContact

© 2026 LegalBooks