On-Kare
    Log inDemo
    Back to Blog
    Compliance & Security

    HIPAA Compliance Checklist for Healthcare SaaS in 2026

    A comprehensive, actionable checklist for healthcare SaaS providers to achieve and maintain HIPAA compliance, covering the Security Rule, Privacy Rule, Breach Notification Rule, and the proposed 2025 updates.

    Anthony Chevalier

    Co-Founder & CPO

    Nielsen Norman Group certified UX professional focused on patient-centered digital health experiences and regulatory compliance.

    Published March 8, 202611 min read1,580 words

    Why HIPAA Compliance Is Non-Negotiable for Healthcare SaaS

    Healthcare SaaS providers operate in one of the most regulated technology environments in the world. Every platform that creates, receives, maintains, or transmits electronic protected health information on behalf of a covered entity is classified as a business associate under HIPAA, subject to the full weight of the Security Rule, the Privacy Rule, and the Breach Notification Rule.

    The HHS Office for Civil Rights settled or imposed penalties in 18 HIPAA enforcement actions in 2024, with individual settlements ranging from $75,000 to $4.75 million. The most common findings involved failures in risk analysis, insufficient access controls, and inadequate encryption. The Office of Inspector General's 2025 work plan explicitly targets cloud-based health IT systems for audit.

    Beyond enforcement risk, HIPAA compliance is a market requirement. A 2025 HIMSS survey found that 78 percent of health system CIOs rank security and compliance posture as the top criterion in SaaS vendor evaluation. NIST Special Publication 800-66 Revision 2, updated in 2024, provides the most authoritative mapping between HIPAA Security Rule requirements and technical controls. This publication, combined with the HITRUST Common Security Framework, forms the foundation of a defensible compliance program.

    Administrative Safeguards Checklist

    Administrative safeguards form the governance backbone of HIPAA compliance. They encompass the policies, procedures, and organizational measures that manage security.

    Risk Analysis and Management: Conduct a comprehensive, documented risk analysis at least annually, identifying all systems that create, receive, maintain, or transmit ePHI. Document each identified risk with a severity rating and likelihood assessment. Implement a risk management plan with specific mitigation measures, responsible parties, and completion timelines.

    Security Management Process: Establish a formal information security program with designated security officer accountability. Implement sanctions policies for workforce members who violate security policies.

    Workforce Security: Implement authorization procedures for workforce access to ePHI based on role-based access control. Establish clearance procedures including background checks. Implement termination procedures ensuring immediate revocation of access upon separation.

    Information Access Management: Implement policies consistent with the minimum necessary standard. Maintain documentation of access authorizations and periodic access reviews.

    Security Awareness Training: Conduct training for all workforce members upon hire and at least annually thereafter. Include modules on phishing recognition, password management, workstation security, and incident reporting. Document completion and maintain records for six years.

    Security Incident Procedures: Establish formal incident response procedures including identification, containment, eradication, recovery, and post-incident analysis. Conduct tabletop exercises at least annually.

    Contingency Planning: Develop and maintain data backup, disaster recovery, and emergency mode operation plans. Test contingency plans at least annually with documented results.

    Technical Safeguards Checklist

    Technical safeguards are the technology-based controls that protect ePHI. The proposed 2025 HIPAA Security Rule update strengthens several requirements from addressable to required.

    Access Controls: Implement unique user identification for every workforce member. Deploy multi-factor authentication for all access to systems containing ePHI. Implement automatic logoff after defined inactivity. Deploy encryption for ePHI at rest and in transit.

    Audit Controls: Implement mechanisms that record and examine activity in systems containing ePHI. Maintain audit logs for a minimum of six years. Implement automated monitoring for unusual access patterns, failed authentication, and bulk data access.

    Integrity Controls: Implement mechanisms to authenticate ePHI and verify it has not been altered or destroyed in an unauthorized manner. Deploy file integrity monitoring for critical systems.

    Transmission Security: Implement encryption for all ePHI transmitted over electronic networks using TLS 1.2 or higher. Deploy certificate management and rotation procedures.

    The proposed 2025 update introduces new requirements: annual penetration testing, vulnerability scanning at least every six months, network segmentation between ePHI systems and general IT infrastructure, and anti-malware protection. Healthcare SaaS providers should implement these controls now.

    Physical Safeguards and Cloud Considerations

    For SaaS providers, physical safeguards extend beyond traditional facility security to encompass cloud infrastructure and data center controls. The shared responsibility model requires clear delineation of security obligations.

    Facility Access Controls: Document physical security controls for all facilities where ePHI is accessed. For cloud-hosted infrastructure, obtain and review the cloud provider's SOC 2 Type II report. Implement visitor access procedures and maintain visitor logs.

    Workstation Security: Deploy endpoint management enforcing encryption, screen lock, and remote wipe on all devices accessing ePHI. Implement mobile device management. Establish policies prohibiting local storage of ePHI.

    Cloud-Specific Controls: Maintain an inventory of all cloud services and regions where ePHI is stored or processed. Implement cloud security posture management for continuous configuration monitoring. Deploy cloud access security broker controls. Document data residency requirements.

    Device and Media Controls: Implement disposal procedures for hardware and electronic media containing ePHI, including certificates of destruction. Deploy encryption on all removable media. Maintain records of hardware and media movements.

    Privacy Rule, Breach Notification, and BAA Requirements

    Healthcare SaaS providers must comply with applicable Privacy Rule provisions and the Breach Notification Rule.

    Privacy Rule: Implement the minimum necessary standard. Deploy de-identification capabilities compliant with HIPAA Safe Harbor or Expert Determination methods. Implement procedures for responding to individual access requests within 30 days. Maintain accounting of disclosures for all non-TPO uses.

    Breach Notification Rule: Implement automated breach detection including unauthorized access detection, data exfiltration monitoring, and anomalous behavior analysis. Establish breach risk assessment procedures following the four-factor test. Maintain notification procedures meeting the 60-day individual notification requirement.

    Business Associate Agreements: Maintain a current BAA with every covered entity client. Ensure BAAs address all required provisions. Maintain a register of all subcontractors with access to ePHI and ensure downstream BAAs are in place. Review and update BAAs at least annually.

    Documentation: Maintain all HIPAA-required documentation for a minimum of six years. Implement version control for all policies and procedures.

    On-Kare's compliance infrastructure implements every item in this checklist natively, providing healthcare organizations with a platform that meets HIPAA requirements out of the box.

    Continuous Compliance: Beyond the Checklist

    Achieving HIPAA compliance is not a one-time event but an ongoing operational discipline. A sustainable compliance program requires continuous monitoring, regular reassessment, and organizational commitment.

    Continuous Monitoring: Deploy SIEM systems that aggregate and analyze logs from all ePHI systems in real time. Implement automated compliance monitoring that validates configuration against HIPAA requirements. Conduct ongoing vulnerability management with defined SLAs for remediation.

    Regular Reassessment: Conduct formal risk analysis updates at least annually. Perform internal audits at least semi-annually covering rotating safeguard categories. Engage third-party assessors for annual independent evaluations.

    HITRUST Certification: Consider pursuing HITRUST CSF certification as comprehensive compliance validation. HITRUST r2 certification encompasses HIPAA, NIST, and multiple other frameworks in a single assessment.

    Regulatory Change Management: Establish a process for monitoring and incorporating regulatory changes. The proposed 2025 Security Rule update will require significant implementation effort.

    Vendor Risk Management: Implement a formal program evaluating security posture of all subcontractors with access to ePHI. Require SOC 2 Type II reports, penetration test results, and documented compliance programs from critical vendors.

    2,156 clinical and operational capabilities. One single platform.

    8 business domains, 25 specialties, 7 care settings and 343 AI-augmented capabilities — without stacking more software.

    See the coverage