Scrutineer · By framework
HIPAA compliance for SaaS companies that sign BAAs
Hospitals and health plans that buy your software will send a BAA and a security review before they send a purchase order. Signing the BAA makes your SaaS a business associate, and your cloud provider's BAA covers far less of that than most founders assume.
Scrutineer maps your controls to the HIPAA Security Rule, tracks a BAA for every tool that can see ePHI, and keeps the evidence your customers ask for. Compliance software, not a certification.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HIPAA for SaaS
Hosting on a HIPAA-eligible cloud does not make your SaaS compliant
The large cloud providers sign a business associate addendum, and AWS lets you accept it in AWS Artifact for the whole account. Read what it covers: AWS says customers should only process, store and transmit PHI in the HIPAA-eligible services named in the addendum, under its shared responsibility model. Everything above that line is yours: how you configure encryption and keys, who in your company can reach production data, what gets logged, whether backups restore, and whether a developer spun up a service that is not on the eligible list. HHS guidance on cloud computing makes the same point from the other direction. A provider that stores ePHI is a business associate even when the data is encrypted and it holds no key. So encryption does not take your SaaS out of scope either. If your product stores a customer's ePHI, you are a business associate and the Security Rule applies to you in full.
Your BAA chain is only as strong as the vendor you forgot
Under 45 CFR 164.308(b)(2) and 164.314(a)(2)(iii), a business associate must have its own business associate agreement with every subcontractor that creates, receives, maintains or transmits ePHI on its behalf. In a SaaS stack that list is longer than the hosting bill suggests. PHI leaks into application logs, error tracking payloads, support tickets, team chat, transactional email, session replay and, more and more, prompts sent to an AI model API. Many of those vendors sign a BAA only on an enterprise tier, or only for specific products or endpoints, and some never sign one. The conduit exception will not rescue you: HHS limits it to transmission-only services with no storage beyond what transmission needs. The practical fix is an inventory of every tool that can see ePHI, with a BAA on file or a control that keeps PHI out of it.
What a hospital security review actually asks a SaaS vendor
Health systems and health plans send the same short list in different wrappers. They want a signed BAA, your most recent risk analysis under 164.308(a)(1)(ii)(A), your subcontractor list, your incident response plan, and proof you can meet the breach notice clock. HIPAA gives a business associate up to 60 days after discovery to notify the covered entity under 164.410, and most hospital BAAs shorten that to days. Larger buyers add a SOC 2 Type 2 report or HITRUST. What nobody can hand them is a HIPAA certification, because HHS does not issue or recognize one. Scrutineer keeps the evidence for each of those answers against a mapped control, so the questionnaire, the BAA and the report say the same thing.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your controls to every HIPAA Security Rule standard and implementation specification, so a SaaS team sees exactly which safeguards it owns above the cloud provider's line
- Keeps an inventory of every subcontractor that can see ePHI (hosting, logging, error tracking, support desk, email, AI APIs) with the BAA status next to each
- Records each addressable implementation specification with the decision you made and why, which is the documentation OCR asks for
- Collects evidence continuously from your cloud, identity and ticketing tools, so encryption, access reviews and backup restores stay proven, not promised
- Runs the 164.308(a)(1) risk analysis against the systems that actually hold ePHI, including the ones outside your main production account
- Keeps the incident and breach assessment record that starts the 60-day notice clock, and the shorter clock your customer BAAs set
- Answers hospital and health plan security questionnaires from the same mapped controls, so the answer matches the evidence
- Adds SOC 2 on the same library when your healthcare buyers start asking for a report, with no second program to maintain
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Where ePHI goes in a SaaS stack
Which tools in your stack need a BAA, and what stays on you
Most HIPAA for SaaS guides stop at "sign a BAA with your cloud provider". A business associate owes a BAA from every subcontractor that creates, receives, maintains or transmits ePHI for it (45 CFR 164.308(b)(2), 164.314(a)(2)(iii)). This is where that list usually runs in a SaaS company, and what no vendor BAA takes off your plate.
| Stack component | Is the vendor your subcontractor? | What its BAA typically covers | What stays on you |
|---|---|---|---|
| Cloud hosting, compute and storage | Yes, even if the ePHI is encrypted and the provider has no key | Only the services on the provider's HIPAA-eligible list, once you accept the BAA for the account | Configuration, keys, access, logging, backups, and keeping ePHI out of services not on the list |
| Application logs and observability | Yes, if logs or traces carry ePHI | Where offered, often limited to certain products or plan tiers | Scrubbing PHI before it ships, or buying the covered tier and turning the right settings on |
| Error tracking and crash reporting | Yes, if request payloads or stack traces include ePHI | Where offered, usually on business or enterprise plans only | Data scrubbing rules and retention limits on captured events |
| Customer support desk and help center | Yes, if tickets or attachments carry ePHI | Varies by vendor and plan | Rules for what agents may paste, attachment handling, access for contractors |
| Team chat and internal wiki | Yes, if staff paste ePHI into messages or pages | Usually the enterprise plan only, if at all | A written rule, workforce training and, ideally, data loss prevention |
| AI model APIs used in your product | Yes, if prompts or files contain ePHI | Where offered, usually limited to named endpoints with zero data retention | Routing ePHI only to covered endpoints and keeping prompt logging off |
| Transactional email and SMS | Yes, if the provider stores message content | Varies; the conduit exception does not cover a service that stores messages | Minimum necessary in the message body, and a link to the app instead of PHI |
| Session replay and product analytics | Yes, if it records screens that show ePHI | Rarely offered | Masking or excluding every screen that renders patient data |
| Internet and network carriers | No. The conduit exception covers transmission-only services | Not applicable | Encryption in transit under 164.312(e) |
Good questions
Questions about HIPAA for SaaS
Keep reading
Guides that go deeper on this framework
Best HIPAA risk assessment software
Which tools actually produce the 164.308(a)(1) risk analysis a hospital asks for.
Read the guideHIPAA compliance checklist
The Security Rule safeguards in the order a business associate should build them.
Read the guideBest HIPAA and PCI compliance software
For SaaS products that hold patient data and card data at once.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification