PilotLab
HIPAA-Compliant SaaS Development: Technical Requirements
Security

HIPAA-Compliant SaaS Development: Technical Requirements

PilotLab TeamPilotLab Team
September 18, 20267 min read

HIPAA-compliant SaaS development is a requirement, not a feature, for any product that creates, receives, stores or transmits protected health information (PHI) on behalf of healthcare providers, health plans or their partners. There is no official HIPAA certification for software; compliance comes from implementing the required safeguards, documenting them and operating them consistently. This guide explains when HIPAA applies to a SaaS company, how Business Associate Agreements work, and the technical safeguards to build into your architecture: encryption, access controls, audit logging, PHI-safe tooling, backups and incident response. It is written for founders and CTOs and is not legal advice; work with qualified healthcare counsel on your specific obligations. Our cloud security and DevOps team builds infrastructure to these requirements.

When Does HIPAA Apply to a SaaS Company?

HIPAA regulates covered entities (healthcare providers that bill electronically, health plans and healthcare clearinghouses) and their business associates, which are vendors that handle PHI on a covered entity's behalf. If your SaaS stores patient records, appointment details, clinical notes, claims data or any individually identifiable health information for a covered entity, you are almost certainly a business associate and directly liable for complying with the HIPAA Security Rule and parts of the Privacy Rule. Your own vendors that touch that PHI (cloud hosting, email delivery, error tracking, support desk) are in turn subcontractor business associates. Consumer health apps that individuals use on their own, without a covered entity relationship, may fall outside HIPAA but can still be subject to the FTC Health Breach Notification Rule and state privacy laws. Mapping exactly where PHI enters, flows and rests in your system is the first engineering task. Our healthcare software development work always starts with that data flow map.

Business Associate Agreements and HIPAA-Eligible Cloud Services

A Business Associate Agreement (BAA) is a contract that defines how a business associate may use and must protect PHI, and it is required before PHI changes hands. You will sign BAAs with your healthcare customers, and you need BAAs with every vendor that stores or processes PHI for you.

Cloud Provider BAAs

AWS, Microsoft Azure and Google Cloud all offer BAAs, but each covers only a defined list of HIPAA-eligible services. Running PHI through a service outside that list is a compliance gap even if the rest of your stack is covered. Check the current eligible services list before adopting any new managed service, and remember the shared responsibility model: the provider secures the underlying infrastructure, while you remain responsible for configuring services securely.

The Hidden Vendors

Teams often secure the database and forget about logging platforms, error monitoring, analytics, transactional email, SMS, customer support tools and AI APIs. Each one either needs a BAA or must be configured so PHI never reaches it. Keep a vendor inventory that records which vendors may receive PHI and whether a BAA is in place.

Technical Safeguards Required by the HIPAA Security Rule

The Security Rule groups requirements into administrative, physical and technical safeguards. Technical safeguards are where engineering decisions matter most. Some specifications are labeled required and others addressable; addressable does not mean optional. It means you must implement the safeguard or document why an equivalent alternative is reasonable. HHS has also proposed updates to the Security Rule that would tighten several of these areas, so design to the stronger standard.

Access Control

Assign every user a unique identifier, with no shared accounts. Enforce role-based access so users see only the PHI their role requires, in line with the minimum necessary standard. Implement automatic session timeout, an emergency access procedure and multi-factor authentication for all workforce access to systems containing PHI. In multi-tenant products, strict tenant data isolation is part of access control, since one clinic must never see another's patients.

Encryption in Transit and at Rest

Encryption is an addressable specification under the current rule, but in practice every modern HIPAA program treats it as mandatory. Use TLS 1.2 or higher for all traffic, including internal service-to-service calls, and encrypt databases, backups, file storage and volumes with keys managed in a cloud KMS. Encryption that meets HHS guidance also matters after an incident: properly encrypted PHI is generally not considered unsecured PHI for breach notification purposes.

Audit Controls

Record who accessed, created, modified or deleted PHI, when and from where, for both application users and administrators. Store audit logs in tamper-resistant, append-only storage with restricted access, review them regularly and alert on unusual patterns such as bulk exports. HIPAA requires certain documentation to be retained for six years, and many teams align audit log retention with that period.

Integrity and Authentication

Protect PHI from improper alteration with checksums, database constraints and versioned records, and verify that a person or system is who it claims to be with strong authentication, short-lived credentials and mutual TLS or signed tokens between services.

Building a PHI-Safe Cloud Architecture

Good architecture reduces how much of your system handles PHI, which shrinks both risk and audit effort. Isolate PHI-processing services and data stores in dedicated accounts or projects and private network segments, with no public database endpoints. Use only HIPAA-eligible services in that boundary. Define all infrastructure as code so security configuration is reviewable and repeatable, and enforce guardrails with policy checks in CI. Keep PHI out of logs, URLs, error messages and analytics events by design: log record IDs rather than names or diagnoses, and scrub payloads before they reach monitoring tools. Be careful with tracking pixels and third-party scripts on authenticated pages, a topic HHS has issued specific guidance on. Where possible, de-identify data for analytics and testing using the Safe Harbor or Expert Determination methods, and never copy production PHI into development environments. Our SaaS security checklist from code to cloud covers the broader hardening steps that apply here.

Administrative Safeguards That Engineering Teams Own

Several administrative safeguards depend directly on engineering work and evidence.

Risk Analysis and Risk Management

HIPAA requires an accurate and thorough risk analysis of threats to PHI, updated as your system changes. Treat it as a living document tied to your architecture, threat models and remediation backlog rather than a one-time spreadsheet.

Workforce Access and Training

Grant production access on a least-privilege, just-in-time basis, remove it promptly when people change roles or leave, and keep records of security awareness training. Access reviews should be scheduled and documented.

Backups, Disaster Recovery and Contingency Planning

Maintain encrypted, tested backups and a documented disaster recovery plan with defined recovery objectives. Restore tests are the evidence auditors and enterprise customers ask for, and they prove that availability, which is part of the Security Rule, is actually protected.

HIPAA Considerations for AI Features and Integrations

Healthcare SaaS products increasingly add AI summarization, transcription and search, and every one of these features is a new PHI flow. Before sending PHI to a model provider, confirm that the provider will sign a BAA for the specific service you use, that data is not retained or used for training beyond what the agreement allows, and that requests stay within the regions your customers expect. Apply the minimum necessary standard to prompts: send only the fields a task needs. Store prompts and outputs that contain PHI with the same encryption, access control and audit logging as the rest of your clinical data, and scope any vector index or retrieval layer by tenant so one organization's records never ground another's answers. The same discipline applies to EHR integrations over HL7 or FHIR APIs: authenticate with scoped credentials, validate inbound data, log every exchange and handle partner downtime without dropping messages. Treat each new integration as an update to your risk analysis, not just a feature ticket.

Breach Response and Ongoing HIPAA Compliance

Under the Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery, and your BAAs will often set shorter timelines. Covered entities must then notify affected individuals, HHS and, for larger breaches, the media. Prepare for this before it happens: maintain an incident response plan, centralize security alerts, practice tabletop exercises and make sure audit logs can answer exactly which records were accessed. Compliance is continuous. Schedule vulnerability scanning and penetration tests, review access and vendor BAAs periodically, and keep policies and evidence current. Many healthcare buyers also expect a SOC 2 report or a HITRUST assessment in addition to HIPAA safeguards, so collecting evidence automatically from your infrastructure and CI pipelines pays off. To make this sustainable, our Cloud Security and DevOps services automate monitoring, logging and evidence collection as part of the platform.

Summary

HIPAA-compliant SaaS development starts with knowing where PHI lives and who touches it. Sign BAAs with customers and with every vendor that handles PHI, and use only HIPAA-eligible cloud services within your PHI boundary. Implement the Security Rule technical safeguards: unique user IDs, role-based access and MFA, encryption in transit and at rest, tamper-resistant audit logs, and integrity and authentication controls. Keep PHI out of logs and third-party tools, maintain a living risk analysis, test backups and prepare for breach notification. This article is general guidance, not legal advice; confirm obligations with healthcare counsel.

Industries:Healthcare

Build Your Healthcare SaaS on a Compliant Foundation

PilotLab builds cloud infrastructure and SaaS platforms to HIPAA requirements, including BAA-covered architectures, encryption, audit logging and automated evidence collection.

Explore Cloud Security & DevOps