← Glossary · security
HIPAA
A U.S. law governing the privacy and security of protected health information, with corresponding obligations on covered entities and business associates.
HIPAA applies if a SaaS vendor handles protected health information (PHI) on behalf of a healthcare provider, payer, or clearinghouse. The vendor must sign a Business Associate Agreement (BAA), implement specific technical and administrative safeguards, and report breaches within 60 days. HIPAA fines can reach $50K per violation with annual caps in the millions. Vendors selling into healthcare almost always advertise HIPAA compliance and will sign a BAA.