HIPAA Compliance Checklist for SaaS and Digital Health Products
This HIPAA compliance checklist for software development is written specifically for multi-tenant SaaS and digital health products that serve hospitals, clinics and payers. General development checklists cover encryption, logging and access control. SaaS companies face additional questions: how tenants are isolated, which subprocessors touch PHI, how customer BAAs are structured, how HIPAA overlaps with SOC 2 and who is responsible for what. For general development controls, start with our HIPAA software development checklist. Need a SaaS readiness review? Contact our team.
Tenant Isolation Checklist
Tenant isolation is the defining HIPAA challenge for SaaS products. When one platform stores patient data for many healthcare customers, a single authorization bug can expose one customer's patients to another customer's users. Health system security teams ask detailed questions about isolation, and weak answers stall sales. Isolation must be designed at every layer: data storage, application logic, encryption keys, search indexes, caches, logs, analytics and internal support tooling used by your staff.
Choose an Isolation Model
Decide between separate databases, separate schemas or shared tables with tenant identifiers. Stronger isolation costs more to operate, so document why your chosen model fits your risk analysis and customer requirements.
Enforce Tenant Scope in Every Query
Apply tenant filters centrally, through database row-level security or a shared data access layer, rather than relying on each developer to add conditions manually. Test cross-tenant access explicitly in automated suites.
Separate Encryption Keys per Tenant
Consider tenant-specific encryption keys for sensitive data. Per-tenant keys limit exposure if one key is compromised and simplify data deletion when a customer leaves the platform. Store keys in managed vaults with logged access.
Isolate Search, Caches and Files
Search indexes, caches, object storage and generated reports often bypass database isolation. Include tenant identifiers everywhere, and test that cached or indexed content never appears for users in another tenant.
Restrict Internal Support Access
Support staff tools must respect tenant boundaries too. Require customer approval or ticket justification for accessing tenant data, log every support session and remove access automatically when tickets close. Audit these sessions monthly.
Subprocessor and Vendor Management Checklist
SaaS products rely on many vendors: cloud hosting, email delivery, error monitoring, analytics, customer support platforms and AI services. Any vendor that creates, receives, maintains or transmits PHI on your behalf is a subcontractor business associate and needs a BAA. Customers increasingly ask for complete subprocessor lists during procurement. Keeping vendors under control prevents accidental PHI leakage into tools that were never designed or contracted to handle it. Use the checklist below to stay in control.
Inventory Every Subprocessor
List every vendor that could receive PHI, including monitoring, logging, email, SMS, support and analytics tools. Record data types shared, purpose, location and whether a BAA is signed. Update it quarterly.
Sign Subcontractor BAAs
Vendors handling PHI must sign BAAs that flow down your obligations. If a vendor refuses, stop sending PHI to it and redesign data flows, because no workaround makes unsigned sharing compliant.
Prevent PHI Leakage Into Tools
Error trackers, session replay tools and analytics scripts frequently capture PHI accidentally. Configure scrubbing, disable session recording on clinical screens and review what each tool actually collects in production. Test scrubbing rules.
Publish a Subprocessor List
Maintain a current subprocessor list for customers, with advance notice of changes. Many health system contracts require notification before adding subprocessors that will handle their patients' information. Keep change history visible.
Review Vendors Regularly
Reassess vendors annually, reviewing security reports, BAA terms and incidents. Remove vendors no longer needed, and confirm they return or destroy PHI according to your agreements. Document each review and its outcome.
Customer BAAs and SOC 2 Overlap
Selling to healthcare organizations means negotiating BAAs with customers and answering detailed security questionnaires. Many enterprise buyers also expect a SOC 2 report, even though SOC 2 is not a HIPAA requirement. Building one control framework that supports both reduces duplicated effort and speeds sales cycles. Our HIPAA compliance guide explains the legal basics, while this checklist focuses on commercial and operational readiness for SaaS teams. Our HIPAA compliant app development guide covers product-level controls.
Prepare a Standard Customer BAA
Create your own standard BAA, reviewed by legal counsel, covering required elements, breach notification timelines and subcontractor terms. Offering your template first often speeds negotiations with smaller healthcare customers. Keep versions controlled.
Track Negotiated Terms
Large health systems often insist on their own BAA. Track negotiated obligations, such as shorter breach notification windows or data location limits, so operations teams actually meet each customer's commitments.
Map HIPAA to SOC 2 Controls
HIPAA safeguards and SOC 2 criteria overlap heavily in access control, logging, change management and incident response. Map controls once, collect evidence once and use it for both audits. This saves effort.
Build a Security Questionnaire Library
Maintain approved answers to common questionnaires, including architecture diagrams, encryption details and incident response summaries. A reusable library shortens sales cycles and keeps answers consistent across different customers. Review answers every quarter.
Plan Breach Notification Workflows
BAAs require notifying customers of breaches of unsecured PHI. Define detection, investigation, legal review and customer notification steps, including contact lists for every customer and contractual notification deadlines. Rehearse them annually.
Shared Responsibility Documentation Checklist
Healthcare customers need to know which controls your platform provides and which remain their responsibility. Without clear documentation, customers may assume you handle user provisioning, access reviews or device security, while you assume they do. Gaps between those assumptions create compliance failures. A shared responsibility matrix, similar to those published by cloud providers, makes boundaries explicit. It also supports customer audits and your own HIPAA technical safeguards documentation. Use the items below as a starting point.
Publish a Responsibility Matrix
List controls such as access management, audit logging, encryption, backups and incident response, stating whether each is provided by you, the customer or both. Update it with every major release.
Document Customer Configuration Duties
Explain settings customers must configure, such as single sign-on, role assignments, session timeouts and data retention. Customers cannot meet obligations they do not know exist within your product. Include setup guides.
Provide Audit Log Access
Customers need audit logs for their own compliance reviews. Offer searchable logs or exports scoped to each tenant, with documented fields and retention periods customers can rely on. Keep formats stable.
Explain Data Location and Retention
State where data is stored, how long it is retained and how customers request deletion or export. Many contracts require specific regions, retention limits or documented destruction at termination. Keep this current.
Support Integration Responsibilities
Integrations with EHRs and other systems introduce shared duties. Document who manages credentials, interface monitoring and error handling, especially for connections built through healthcare API development or partner integrations. Put this in writing.
Frequently Asked Questions
What should a HIPAA compliance checklist for SaaS include?
A SaaS HIPAA checklist should cover tenant isolation, subprocessor management with BAAs, customer BAA templates and negotiated terms, SOC 2 control mapping, breach notification workflows and shared responsibility documentation. It should sit alongside core technical controls such as encryption, audit logging, access control and secure development practices.
Do SaaS companies need a BAA with customers?
Yes, if the SaaS product creates, receives, maintains or transmits PHI on behalf of covered entities or other business associates. The SaaS company becomes a business associate and must sign BAAs with those customers. It must also sign BAAs with its own subprocessors handling PHI.
Is SOC 2 required for HIPAA compliance?
No. SOC 2 is a voluntary audit framework, not a HIPAA requirement. However, many healthcare enterprise buyers request SOC 2 reports during procurement. Because controls overlap heavily, mapping HIPAA safeguards to SOC 2 criteria lets organizations collect evidence once and support both compliance and sales needs efficiently.
How should multi-tenant SaaS isolate patient data?
Choose an isolation model, such as separate databases, schemas or tenant-scoped tables, based on risk. Enforce tenant filters centrally, consider per-tenant encryption keys, isolate caches, search indexes and files, restrict support access, and test cross-tenant access automatically in every release to prevent data exposure.
What is a shared responsibility matrix in HIPAA SaaS?
A shared responsibility matrix documents which security and compliance controls the SaaS provider handles, which the customer handles and which are shared. It clarifies duties like user provisioning, access reviews, session settings and audit log review, preventing gaps caused by mismatched assumptions between providers and customers.
Can SaaS products use analytics and monitoring tools with PHI?
Only if those tools sign BAAs and are configured appropriately, or if PHI is removed before data reaches them. Error trackers, session replay and analytics scripts often capture PHI accidentally. Configure scrubbing, disable recording on clinical screens and review collected data regularly to prevent unauthorized disclosure.
Need a SaaS HIPAA Readiness Review?
Our integration engineers are ready to help. Free consultation, no obligation.