Calendar Icon White
September 22, 2026
Clock Icon
4
 min read

HIPAA Compliance Guide and Checklist for SaaS

HIPAA compliance for SaaS in 2026: new penalty limits, the pending Security Rule, and how to protect PHI in Slack, tickets and AI tools. Includes a checklist.

HIPAA Compliance Guide and Checklist for SaaS
ChatGPT
Perplexity
Grok
Google AI
Claude
Summarize and analyze this article with:

TL;DR

  • ·      HIPAA compliance for SaaS covers any softwarevendor that handles PHI for a covered entity; that vendor is a businessassociate, directly liable under the Security Rule and bound by a BusinessAssociate Agreement (BAA).
  • ·      PHI no longer stays in the production databaseyou scoped for the audit. It travels into support tickets, Slack threads,shared drives, AI assistants and MCP connectors, and each copy is in scope.
  • ·      Encryption, access control and a signed BAAprotect the system. None of them decide whether a raw diagnosis or a member IDshould sit inside a Zendesk ticket or a ChatGPT prompt in the first place.
  • ·      Strac discovers, classifies and redacts PHIacross SaaS, cloud, endpoint DLP, Browser DLP, AI DLP and MCP DLP, and produces the audittrail the Security Rule asks for.
  • ·       Forthe framework basics, start with the pillar on HIPAA compliance; thispost is the SaaS vendor's slice of it.
  • What Is HIPAA Compliance for SaaS?

    The Health Insurance Portability and Accountability Act (HIPAA) regulates how covered entities (health plans, providers and clearinghouses) and their business associates protect health information. A SaaS company becomes a business associate the moment its product creates, receives, maintains or transmits PHI for one of those customers.

    That status carries direct obligations. A business associate must run its own Security Rule program, sign a BAA with every covered entity customer, flow equivalent terms down to its own subcontractors, and report breaches of unsecured PHI to the customer without unreasonable delay.

    PHI itself is broader than most engineering teams assume. It is any individually identifiable health information: a name next to an appointment date, a member ID in a support ticket, an MRI image attached to a billing dispute. The full list of identifiers lives in HIPAA PHI data elements.

    ✨ Why PHI Escapes the Systems You Certified

    Most SaaS vendors scope HIPAA around the product: the database, the API, the cloud account. That scope is correct and incomplete.

    PHI leaks sideways through the business that runs the product. A customer success manager pastes a patient record into Slack to escalate a bug. An engineer attaches a production export to a Jira ticket so the issue can be reproduced. A support agent downloads a lab report from Zendesk to a laptop. A sales engineer drops a sample file into a Google Drive folder shared with "anyone with the link".

    None of these are attacks. They are ordinary work, and every copy they create is PHI your company now maintains. Encryption protects the file on disk; it does nothing about whether the file should exist in that folder at all.

    This is the gap auditors increasingly probe. A clean production environment tells you the product is compliant. A clean collaboration stack tells you the company is.

    The Three Rules and the Safeguards Behind Them

    HIPAA reaches a SaaS vendor through three rules.

    The Privacy Rule limits how PHI is used and disclosed, and sets the minimum necessary standard: use only the PHI a task actually needs. For a SaaS company, minimum necessary is the principle that argues for redaction over retention.

    The Security Rule requires administrative, physical and technical safeguards for electronic PHI (ePHI).

    • Administrative safeguards cover the risk analysis, risk management, workforce training, sanctions, contingency planning and the assignment of a security official. The risk analysis must be accurate and thorough, which means it has to know where ePHI actually lives. See the HIPAA privacy impact assessment guide for how to run one.
    • Physical safeguards cover facility access, workstations and device and media controls. For a remote SaaS workforce, the workstation is a laptop at home, which puts endpoint DLP inside the physical safeguard conversation.
    • Technical safeguards cover access control, audit controls, integrity, person or entity authentication, and transmission security. Audit controls are where most vendors come up short: logging who logged in is easy; logging what PHI moved where is not.

    The Breach Notification Rule requires notice after a breach of unsecured PHI. PHI that has been properly de-identified or rendered unreadable does not trigger it, which is why HIPAA de-identification and redaction change the math on every incident.

    What Changes in 2026: AI Tools, MCP and the Pending Security Rule

    Three shifts define HIPAA for SaaS this year.

    Generative AI became a disclosure channel. When an employee pastes PHI into ChatGPT, Claude, Gemini or Copilot without a BAA covering that tool, the PHI has been disclosed to a vendor your customers never approved. Most of this happens through personal accounts and browser tabs, which is the core of Shadow AI.

    AI agents now read PHI through connectors. A support copilot connected to the helpdesk over the Model Context Protocol pulls ticket bodies as tool responses. A coding agent with database access can return rows. Every tool call is a potential disclosure, and MCP DLP is the control that inspects it.

    The Security Rule update is still pending. HHS proposed a major revision in January 2025 that would make encryption and multifactor authentication mandatory, require a technology asset inventory and network map, set a 72-hour restoration target, and require business associates to verify their safeguards to customers in writing. At the time of writing it has not been finalized. The prudent reading is that it describes where auditors and enterprise customers already are, not where the law will someday be.

    The common thread is visibility. A covered entity will increasingly ask its SaaS vendors for proof of where PHI lives and what touches it. An asset inventory that lists servers but not the PHI inside Slack, Drive and AI tools will not answer that question. This is also why the healthcare customers who buy from you now ask about AI data governance in the same security questionnaire as encryption.

    ✨ What PHI Redaction Looks Like in Practice

    Strac inspects content at the moment it is created or shared, not in a quarterly scan.

    A customer sends a message in Intercom that includes a date of birth, a member ID and a diagnosis. Strac detects the PHI, masks the identifiers in place, and keeps the conversation readable for the agent. The same agent then opens ChatGPT to draft a reply and pastes the thread. Strac's browser extension catches the PHI before the prompt is submitted and either redacts it or blocks the paste, depending on policy. The agent sees a short explanation naming the data type. The security team sees one event with the user, the destination and the policy.

    ✨ Strac: HIPAA Controls at the Data Layer

    Strac is a Data Loss Prevention (DLP), Data Discovery and DSPM platform covering SaaS, Cloud, Browser, GenAI and MCP, with automated remediation. For a SaaS business associate, it maps onto the Security Rule in four ways.

    Discovery for the risk analysis. Strac scans current and historical data across Slack, Gmail, Office 365, Microsoft Teams, Google Drive, OneDrive, SharePoint, Box, Zendesk, Salesforce, Jira, Confluence, Notion and AWS S3. The result is a map of where PHI actually lives, which is the input the risk analysis has always needed. On the posture side, DSPM flags public links, external shares and stale access on files that contain PHI.

    Classification that reads the content. Detection covers names, dates, medical record numbers, member and policy IDs, diagnosis and procedure codes, and the images and PDFs that carry them, read with optical character recognition rather than filename guessing.

    Remediation in a fixed order:

    • Redact or mask. PHI is replaced in place inside Slack, email, tickets, docs, Google Drive, SharePoint and Box, so the record stays useful and minimum necessary is met.
    • Block. Uploads and pastes carrying PHI are stopped on the endpoint, in the browser, on the way to generative AI tools, and in MCP tool responses.
    • Warn and coach. The employee sees an inline message naming the data type and the policy at the moment of the action, which doubles as workforce training evidence.
    • Revoke access. Public links and external shares on PHI files are pulled back automatically.

    Coverage beyond SaaS. Endpoint DLP runs on Windows and Mac. Browser DLP governs AI tabs and uploads. AI DLP covers ChatGPT, Claude, Gemini and Copilot, and MCP DLP redacts PHI before it reaches the model. Every detection and action is logged, which gives the audit control a record of what PHI moved, where, and what was done about it.

    The design choice matters. Access control decides who can open the record; redaction decides what is inside it when they do. Only the second survives a stolen session, an overpermissioned integration or a prompt-injected agent. Full detail lives on the HIPAA DLP page.

    The HIPAA for SaaS Checklist

    Days 0 to 30, discover. Sign or refresh BAAs with every covered entity customer and every subcontractor that touches PHI. Connect your collaboration, support and storage tools to Strac in read mode and scan historical data. Feed the PHI map into your risk analysis.

    Days 30 to 60, protect. Turn on redaction for PHI in tickets, chats and messages. Revoke public and external shares on PHI files. Extend coverage to endpoints and the browser, including every generative AI tool your staff use.

    Days 60 to 90, prove and scale. Enroll AI assistants and MCP connectors. Route detection events into your SIEM. Produce a report for customers and auditors showing what PHI was found, what was remediated and who requested access.

    Run this checklist before your next audit or customer security review:

    • ☐ BAAs in place with customers and flowed down to subcontractors
    • ☐ Risk analysis updated with where PHI actually lives, including SaaS and AI tools
    • ☐ Encryption at rest and in transit, and MFA on every system with ePHI
    • ☐ PHI redacted in Slack, email, tickets and shared drives
    • ☐ Generative AI tools governed at the browser and the endpoint
    • ☐ MCP connectors and AI agents inspected before PHI reaches a model
    • ☐ Audit logs that show PHI movement, not only logins
    • ☐ Breach response plan tested, with a documented path to notify customers

    For the broader control list, pair this with the HIPAA compliance checklist and the guide to HIPAA compliance in the cloud.

    Related reading:

    The Bottom Line

    HIPAA compliance for SaaS used to end at the production boundary. In 2026 PHI moves through collaboration tools, support desks, laptops, AI assistants and MCP connectors, and every control above the data layer eventually fails: credentials get phished, links get overshared, agents read more than anyone intended. Redact PHI where it is created and a compromise never becomes a reportable breach. Book a demo to see Strac find and redact PHI across your own stack.

    🌶️ Spicy FAQs for HIPAA Compliance for SaaS

    Is a HIPAA-compliant SaaS product the same as a HIPAA-compliant SaaS company?

    No. A compliant product protects PHI inside the application. A compliant company also controls the PHI its employees copy into Slack, tickets, shared drives and AI tools, which the Security Rule treats as ePHI you maintain.

    Doesn't a signed BAA and encryption cover us?

    They are required, and they are not enough. A BAA allocates liability and encryption protects data at rest and in transit. Neither stops an employee from pasting a patient record into an unapproved AI tool or sharing a PHI file publicly.

    Will PHI controls slow down support and engineering?

    No, because the answer is redaction rather than blocking. Identifiers are masked in place, the ticket or thread stays readable, and the original is available through a logged request only when the task needs it.

    Can DLP catch every piece of PHI in free text?

    Not every one. A customer can describe a condition without naming it. Structured identifiers are caught reliably, and redacting them breaks the link between person and condition, which is what makes the data PHI in the first place.

    Can we use ChatGPT or Claude with PHI?

    Only under a BAA with that vendor and with controls on what reaches the tool. Strac redacts PHI in prompts, uploads and MCP tool responses. See AI DLP and Claude DLP for the full picture.

    Discover & Protect Data on SaaS, AI, MCP, Endpoints & Cloud
    Strac provides end-to-end data loss prevention for all SaaS and Cloud apps. Integrate in under 10 minutes and experience the benefits of live DLP scanning, live redaction, and a fortified SaaS environment.
    Trusted by enterprises
    Data Security + Compliance Automation

    Latest articles

    Browse all

    Get Your Datasheet

    Thank you! Your submission has been received!
    Oops! Something went wrong while submitting the form.
    Close Icon