Scrutineer.ai

Scrutineer · By framework

HIPAA compliance for SaaS companies that sign BAAs

Hospitals and health plans that buy your software will send a BAA and a security review before they send a purchase order. Signing the BAA makes your SaaS a business associate, and your cloud provider's BAA covers far less of that than most founders assume.

Scrutineer maps your controls to the HIPAA Security Rule, tracks a BAA for every tool that can see ePHI, and keeps the evidence your customers ask for. Compliance software, not a certification.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HIPAA for SaaS

Hosting on a HIPAA-eligible cloud does not make your SaaS compliant

The large cloud providers sign a business associate addendum, and AWS lets you accept it in AWS Artifact for the whole account. Read what it covers: AWS says customers should only process, store and transmit PHI in the HIPAA-eligible services named in the addendum, under its shared responsibility model. Everything above that line is yours: how you configure encryption and keys, who in your company can reach production data, what gets logged, whether backups restore, and whether a developer spun up a service that is not on the eligible list. HHS guidance on cloud computing makes the same point from the other direction. A provider that stores ePHI is a business associate even when the data is encrypted and it holds no key. So encryption does not take your SaaS out of scope either. If your product stores a customer's ePHI, you are a business associate and the Security Rule applies to you in full.

Your BAA chain is only as strong as the vendor you forgot

Under 45 CFR 164.308(b)(2) and 164.314(a)(2)(iii), a business associate must have its own business associate agreement with every subcontractor that creates, receives, maintains or transmits ePHI on its behalf. In a SaaS stack that list is longer than the hosting bill suggests. PHI leaks into application logs, error tracking payloads, support tickets, team chat, transactional email, session replay and, more and more, prompts sent to an AI model API. Many of those vendors sign a BAA only on an enterprise tier, or only for specific products or endpoints, and some never sign one. The conduit exception will not rescue you: HHS limits it to transmission-only services with no storage beyond what transmission needs. The practical fix is an inventory of every tool that can see ePHI, with a BAA on file or a control that keeps PHI out of it.

What a hospital security review actually asks a SaaS vendor

Health systems and health plans send the same short list in different wrappers. They want a signed BAA, your most recent risk analysis under 164.308(a)(1)(ii)(A), your subcontractor list, your incident response plan, and proof you can meet the breach notice clock. HIPAA gives a business associate up to 60 days after discovery to notify the covered entity under 164.410, and most hospital BAAs shorten that to days. Larger buyers add a SOC 2 Type 2 report or HITRUST. What nobody can hand them is a HIPAA certification, because HHS does not issue or recognize one. Scrutineer keeps the evidence for each of those answers against a mapped control, so the questionnaire, the BAA and the report say the same thing.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your controls to every HIPAA Security Rule standard and implementation specification, so a SaaS team sees exactly which safeguards it owns above the cloud provider's line
  • Keeps an inventory of every subcontractor that can see ePHI (hosting, logging, error tracking, support desk, email, AI APIs) with the BAA status next to each
  • Records each addressable implementation specification with the decision you made and why, which is the documentation OCR asks for
  • Collects evidence continuously from your cloud, identity and ticketing tools, so encryption, access reviews and backup restores stay proven, not promised
  • Runs the 164.308(a)(1) risk analysis against the systems that actually hold ePHI, including the ones outside your main production account
  • Keeps the incident and breach assessment record that starts the 60-day notice clock, and the shorter clock your customer BAAs set
  • Answers hospital and health plan security questionnaires from the same mapped controls, so the answer matches the evidence
  • Adds SOC 2 on the same library when your healthcare buyers start asking for a report, with no second program to maintain
HIPAA for SaaS readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Where ePHI goes in a SaaS stack

Which tools in your stack need a BAA, and what stays on you

Most HIPAA for SaaS guides stop at "sign a BAA with your cloud provider". A business associate owes a BAA from every subcontractor that creates, receives, maintains or transmits ePHI for it (45 CFR 164.308(b)(2), 164.314(a)(2)(iii)). This is where that list usually runs in a SaaS company, and what no vendor BAA takes off your plate.

Stack component Is the vendor your subcontractor? What its BAA typically covers What stays on you
Cloud hosting, compute and storage Yes, even if the ePHI is encrypted and the provider has no key Only the services on the provider's HIPAA-eligible list, once you accept the BAA for the account Configuration, keys, access, logging, backups, and keeping ePHI out of services not on the list
Application logs and observability Yes, if logs or traces carry ePHI Where offered, often limited to certain products or plan tiers Scrubbing PHI before it ships, or buying the covered tier and turning the right settings on
Error tracking and crash reporting Yes, if request payloads or stack traces include ePHI Where offered, usually on business or enterprise plans only Data scrubbing rules and retention limits on captured events
Customer support desk and help center Yes, if tickets or attachments carry ePHI Varies by vendor and plan Rules for what agents may paste, attachment handling, access for contractors
Team chat and internal wiki Yes, if staff paste ePHI into messages or pages Usually the enterprise plan only, if at all A written rule, workforce training and, ideally, data loss prevention
AI model APIs used in your product Yes, if prompts or files contain ePHI Where offered, usually limited to named endpoints with zero data retention Routing ePHI only to covered endpoints and keeping prompt logging off
Transactional email and SMS Yes, if the provider stores message content Varies; the conduit exception does not cover a service that stores messages Minimum necessary in the message body, and a link to the app instead of PHI
Session replay and product analytics Yes, if it records screens that show ePHI Rarely offered Masking or excluding every screen that renders patient data
Internet and network carriers No. The conduit exception covers transmission-only services Not applicable Encryption in transit under 164.312(e)

Good questions

Questions about HIPAA for SaaS

Yes, if the software creates, receives, maintains or transmits protected health information for a covered entity or another business associate. That makes the SaaS company a business associate, directly liable under the HIPAA Security Rule and breach notification rule. A SaaS product that never touches PHI, such as scheduling without health details, may fall outside HIPAA.
A SaaS company is a business associate when it handles PHI on behalf of a covered entity or another business associate, for example by storing patient records, claims data or clinical notes in its product. It then has to sign a business associate agreement with each such customer and meet the Security Rule itself, not only through its cloud provider.
A SaaS business associate needs a documented risk analysis, the administrative, physical and technical safeguards of the Security Rule, written policies kept six years, a BAA with each customer and each subcontractor that touches ePHI, workforce training, and a breach process that notifies the customer within 60 days of discovery, or sooner if the BAA says so.
No. AWS signs a business associate addendum through AWS Artifact, but it covers only the HIPAA-eligible services named in it, under a shared responsibility model. Your configuration, encryption keys, access control, logging, backups and every tool outside AWS that sees ePHI remain your responsibility. Hosting on a compliant cloud is necessary, not sufficient.
Yes, with every subcontractor that creates, receives, maintains or transmits ePHI on your behalf, under 45 CFR 164.308(b)(2) and 164.314(a)(2)(iii). In a typical SaaS stack that includes hosting, logging, error tracking, support, email and any AI API that receives PHI. If a vendor will not sign one, keep PHI out of that tool.
No. HHS guidance on cloud computing says a service that stores ePHI is a business associate even if the data is encrypted and the service has no key. Encryption lowers breach risk and can matter for breach notification, but it does not remove the business associate relationship or the need for a BAA.
Under 164.410 a business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI. Most hospital and health plan BAAs shorten that sharply, often to a few business days, so the contract clock is usually the one that binds you.
No. HHS does not certify SaaS products or companies as HIPAA compliant and does not recognize private certifications. What buyers accept instead is evidence: a signed BAA, a current risk analysis, and often a SOC 2 Type 2 report with HIPAA as additional criteria, or a HITRUST assessment. Treat any "HIPAA certified" badge with suspicion.
No. Scrutineer is compliance software: it maps your controls to the Security Rule, tracks subcontractor BAAs, collects evidence and flags gaps. HIPAA compliance stays your organization's responsibility, and a CPA firm or assessor issues any SOC 2 or HITRUST report. HIPAA alone runs on the Essentials plan; adding SOC 2 on the same library is Growth.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification