Selling SaaS to Hospitals: Clear the Compliance Gate
By Ben Su — Co-founder & Head of Legal Service Delivery at LegalLayer, and a lawyer. Last updated August 12, 2026.
To pass a hospital's security review, prove three things to its privacy office: you'll sign a Business Associate Agreement and meet HIPAA, you run a documented health-data privacy program, and your security is backed by independent evidence like a SOC 2 Type II report or HITRUST certification. Vendors who can't show these stall in review — and that's what kills the deal.
You can have the best product in the room and still lose a hospital deal without ever talking price. Between the demo and the signature sits a gate most founders underestimate: the hospital's privacy office and third-party risk team. They decide whether your SaaS is safe to connect to patient data — and if you can't answer their questions fast and with evidence, procurement never gets to sign. This is the crash course on clearing that gate.
This is general information, not legal advice. It's written for founders who need to get through a hospital security review, not to replace your security auditor or counsel.
Who is the hospital privacy office, and why can it block your deal?
The hospital privacy and security office is the team that vets every vendor touching protected health information before the hospital will do business with you — and its sign-off is a hard gate on the deal. It usually operates as "third-party risk management" (TPRM), sometimes pulling in the Chief Information Security Officer, the Privacy Officer, and procurement.
Their job is to make sure a vendor won't become the hospital's next breach headline. Under HIPAA, the hospital (a "covered entity") stays responsible for PHI even after it hands data to a vendor, so they push their obligations onto you and demand proof you can carry them. Healthcare organizations formally tier vendors by risk — critical, high, medium, low — based on data sensitivity and system access, and the depth of your review scales with that tier (Accountable).
The practical consequence: no matter how much the clinical champion loves your product, the deal does not close until the privacy office clears you. Founders who treat security review as a formality at the end lose months — or the deal.
What does a hospital assess before onboarding a SaaS vendor?
A hospital assesses a SaaS vendor across a consistent set of security and privacy domains, usually delivered as a written questionnaire plus requests for evidence. Knowing the categories in advance is how you prepare answers instead of scrambling. Hospitals commonly evaluate:
HIPAA and the BAA — whether you'll sign their Business Associate Agreement with required clauses, audit rights, breach-notification timelines, and subcontractor terms.
Data encryption — encryption in transit and at rest; questionnaires commonly ask for AES-256 at rest and TLS 1.2 or higher (TLS 1.3 preferred) in transit (Censinet).
Access controls — multi-factor authentication, least-privilege/role-based access, and periodic (often quarterly) access reviews.
Breach and incident response — a tested incident-response plan, named contacts, and fast notification (hospitals frequently want 24–72 hours, stricter than HIPAA's outer limit).
Independent certifications — a SOC 2 Type II report, and for many large systems, HITRUST certification.
Subcontractor management — proof you flow equivalent obligations down to your own subprocessors via BAAs.
Data location and lifecycle — where PHI is hosted, multi-tenant isolation, retention limits, and secure deletion.
Business continuity — disaster recovery, backups, and recovery-time objectives.
The through-line: the privacy office is looking for evidence, not assurances. Every category above has a document or report behind it that they will ask you to produce.
How do you answer "how are you HIPAA compliant?"
Answer "how are you HIPAA compliant?" by showing you understand your role as a business associate and can back it with the BAA plus HIPAA's three rules. A vague "yes, we're HIPAA compliant" is a red flag to a privacy office; a specific answer moves the review forward.
A strong answer covers:
Your status and the BAA. "We're a business associate — we handle PHI on your behalf, and we'll sign your Business Associate Agreement before any PHI flows." A business associate is a vendor that creates, receives, maintains, or transmits PHI for a covered entity (HHS), and the BAA is mandatory before data moves.
The Security Rule. You maintain administrative, physical, and technical safeguards for ePHI — a documented risk analysis, access controls, encryption, audit logging, and workforce training.
The Privacy Rule's minimum-necessary standard. You use and disclose only the PHI needed for the service, and you don't repurpose PHI without authorization.
Breach notification. You can meet HIPAA's Breach Notification Rule — individuals and the covered entity notified without unreasonable delay and no later than 60 days after discovery (HHS) — and you can hit the tighter contractual window the hospital's BAA specifies.
One current edge worth knowing: since a January 2021 amendment to the HITECH Act, HHS must consider whether an organization had "recognized security practices" (such as the NIST Cybersecurity Framework or the HHS 405(d) Health Industry Cybersecurity Practices) in place for the prior 12 months when it decides HIPAA enforcement — which can reduce fines and shorten audits (Holland & Knight). Adopting a recognized framework is both a selling point to the privacy office and a way to lower your own legal exposure.
What health-data privacy do you need to show?
Beyond "we're HIPAA compliant," a hospital privacy office wants to see that you actually control the flow of PHI. Show a documented privacy program, not just a policy page. Come prepared with:
A data map / data-flow diagram — what PHI you collect, where it lives, who can access it, and every subprocessor it touches. Privacy offices ask this first; not having it signals you don't know where patient data goes.
Minimum-necessary practices — evidence that you limit collection and access to what the service requires, with data minimization, tokenization, or redaction where possible.
Subcontractor BAAs — signed BAAs with every vendor of yours that touches PHI (hosting, email, analytics), proving obligations flow downstream.
Retention, return, and deletion — clear retention limits and a secure process to return or destroy PHI at contract end, which the BAA will require.
Data location — where PHI is stored and processed, and how you isolate it in a multi-tenant environment.
Being able to hand over a data-flow diagram and your list of subprocessor BAAs on request is one of the fastest trust signals you can send a privacy office.
What internal security measures do hospitals expect?
Hospitals expect internal security measures backed by an independent audit — most commonly a SOC 2 Type II report, and for larger systems, HITRUST certification. Self-attestation rarely clears a serious review; third-party evidence does. The measures they look for:
Independent certification: a SOC 2 Type II report (security controls tested over time) as the practical baseline, and HITRUST CSF certification — the healthcare-specific, higher-bar framework — for many large health systems (Censinet). ISO 27001 is sometimes accepted alongside these.
Encryption: AES-256 at rest, TLS 1.2+ in transit, with real key management.
Access control: MFA everywhere, least privilege, and periodic access reviews.
Risk analysis: a current, documented HIPAA Security Rule risk analysis — a specific thing regulators and hospitals both ask for by name.
Incident response: a written, tested plan with named 24/7 contacts and a defined notification timeline.
Business continuity: disaster recovery and backups with defined recovery-time and recovery-point objectives.
Vulnerability management: regular scanning and periodic penetration testing, with remediation evidence.
Workforce training: documented security-awareness and HIPAA training.
The pattern is the same as everything else in the review: name the control, then show the artifact that proves it.
SOC 2 vs. HITRUST: which do hospitals want?
SOC 2 Type II and HITRUST are the two certifications hospitals ask for most, and they serve different purposes. Most health SaaS vendors start with SOC 2 Type II and add HITRUST when they move upmarket into large health systems. The comparison:
| SOC 2 vs. HITRUST for health SaaS | SOC 2 Type II | HITRUST CSF |
|---|---|---|
| What it is | An audit report on your security controls, tested over a period (usually 6–12 months), against the Trust Services Criteria | A certifiable healthcare security framework that maps to HIPAA, NIST, ISO, and more |
| Industry focus | Cross-industry, security-general | Healthcare-specific, built around PHI |
| Output | An auditor's report you share under NDA | A formal certification with a validated assessment |
| Effort / cost | Lower; common startup baseline | Higher; more rigorous and expensive |
| When hospitals want it | Commonly requested as the baseline | Often expected or required by large health systems |
Neither is legally mandated by HIPAA — but in practice they are how you prove your security to a privacy office quickly. A vendor with current SOC 2 Type II and, where needed, HITRUST clears third-party risk review far faster than one asking the hospital to take its word.
The compliance packet to have ready before the review
The single best way to avoid getting blocked is to assemble a "compliance packet" before the hospital asks — so you respond to the security questionnaire in days, not months. Have these ready to share (most under NDA):
Your SOC 2 Type II report (and HITRUST certification, if you have it).
A completed security questionnaire you can reuse and tailor.
Your HIPAA Security Rule risk analysis (current).
A data-flow diagram and list of subprocessors with signed BAAs.
Your incident-response plan and breach-notification process.
Policies: access control, encryption, data retention/disposal, business continuity, workforce training.
A BAA position — your acceptable terms and where you can flex — so the contract doesn't become the bottleneck.
The vendors who close hospitals are rarely the ones with perfect security — they're the ones who can prove their security on demand.
Why founders get blocked (and how to avoid it)
Health SaaS founders get blocked at the hospital security review for predictable, avoidable reasons — almost always a gap between what they've built and what they can evidence. The common failure modes:
Treating security review as a formality. It's a gate, not a rubber stamp. Start it early, in parallel with the commercial conversation.
No independent evidence. "We take security seriously" without a SOC 2 report or HITRUST certification stalls immediately.
No data map. If you can't say where PHI flows and which subprocessors touch it, the privacy office assumes the worst.
A slow or hostile BAA negotiation. Hospitals send demanding BAAs. If you can't turn one around quickly and knowledgeably — breach windows, audit rights, indemnity, subcontractor terms — the deal sits in legal limbo.
If you don't know the material in this crash course, you will feel it as deals that "go quiet" after the demo. The privacy office isn't rejecting your product — it's rejecting the absence of evidence. Fix that, and the same review that blocked you becomes the thing that makes the hospital trust you.
Frequently asked questions
What does a hospital check before buying SaaS?
A hospital's privacy and security office (third-party risk management) checks whether you will sign a Business Associate Agreement, how you protect PHI (encryption, access controls, breach response), your independent security evidence such as a SOC 2 Type II report or HITRUST certification, how you manage subcontractors, and where data is stored. Vendors who cannot produce this evidence stall in review, which is what blocks the deal.
Do I need SOC 2 or HITRUST to sell to hospitals?
Neither is legally required by HIPAA, but hospitals commonly ask for a SOC 2 Type II report, and many larger health systems expect or require HITRUST certification for vendors that handle PHI. SOC 2 Type II is usually the practical baseline; HITRUST is the healthcare-specific, higher-bar certification that shortens security reviews with large systems.
How fast do hospitals expect breach notification?
HIPAA's Breach Notification Rule sets an outer limit of 60 days, but hospitals frequently negotiate much shorter contractual windows in the BAA, often requiring notice of a suspected breach within 24 to 72 hours. Read the hospital's BAA carefully, because the contractual clock is usually stricter than the statute.
What is a Business Associate Agreement with a hospital?
A Business Associate Agreement (BAA) is the HIPAA-required contract a hospital signs with a vendor that handles protected health information on its behalf. It sets permitted uses of PHI, security obligations, breach-notification timelines, audit rights, and return-or-destroy terms. No hospital will let PHI reach your SaaS without a signed BAA in place.
Why do health SaaS deals get stuck in security review?
Deals stall because the vendor cannot quickly produce the evidence the privacy office needs: a completed security questionnaire, a SOC 2 or HITRUST report, a documented risk analysis, an incident-response plan, and acceptable BAA terms. When answers are missing or the BAA negotiation drags, the review does not clear, and procurement will not sign.
About the author: Ben Su is Co-founder and Head of Legal Service Delivery at LegalLayer, and a lawyer. He works with health-technology and growth-stage companies on the enterprise contracts — BAAs, MSAs, and DPAs — that turn a hospital's privacy requirements into a signed deal.
This article is general information, not legal advice, and it doesn't replace a security auditor or qualified counsel. The security certifications above (SOC 2, HITRUST) come from your auditor — but the BAA and data-protection terms a hospital puts in front of you are exactly the kind of high-stakes contract LegalLayer drafts, negotiates, and turns around fast, so legal review stops being the reason your hospital deal stalls.