Technology guide
SaaS and HIPAA
Evaluate hosted applications through data flows, support, retention, identity, subprocessors, and the actual service contract.
Reviewed August 2026
Key considerations
- A SaaS product can handle PHI through primary records, support tickets, telemetry, exports, or integrations.
- Review the exact plan, settings, BAA, retention, deletion, and support access.
- Customers still own configuration, workforce, access, and workflow decisions.
Questions to ask
- Does the vendor sign a BAA for this service and plan?
- What is retained in logs, backups, analytics, and support tools?
- How can access be reviewed, revoked, and investigated?