saas
Glossary ↗HIPAA
HIPAA - the U.S. Health Insurance Portability and Accountability Act of 1996 - is the federal law governing how protected health information (PHI) is handled in the United States. For SaaS builders it becomes relevant the moment your product touches identifiable health data on behalf of a healthcare provider, insurer, or their vendors. If you do, you're likely a business associate and must sign a Business Associate Agreement (BAA) with your customer, contractually committing to safeguard PHI. Compliance spans administrative, physical, and technical safeguards: access controls, encryption, audit logging, breach notification, and workforce training, among others. Practically, HIPAA shapes architecture and vendor choices early - you need infrastructure providers that will themselves sign BAAs (major clouds do), you must restrict and log who can see PHI, and you have to design breach response before you need it. Getting this wrong carries real regulatory and financial penalties. If you're selling into healthcare, treat HIPAA readiness - including BAAs down your whole sub-processor chain - as a prerequisite, not a later add-on.
Related terms