HIPAA Policy Checklist for SaaS EHR Subprocessors
HIPAA Compliance Requirements
Scope and accountability
As a SaaS EHR subprocessor, you handle your customer’s customers’ data, which still qualifies as Protected Health Information (PHI). You must implement safeguards equivalent to those of the covered entity and primary business associate, and you need a documented governance program that demonstrates continuous compliance.
Core HIPAA rules you must operationalize
- Privacy Rule: limit uses and disclosures, enforce minimum necessary, and support individual rights when your services involve PHI handling.
- Security Rule: implement administrative, physical, and technical safeguards for ePHI, including access controls and ePHI Encryption.
- Breach Notification Rule: maintain an Incident Response Plan that enables timely assessment and notification paths.
- Omnibus Rule: ensure subcontractor obligations flow down through each Business Associate Agreement.
Foundational policies and documentation
- Designate Security and Privacy Officers with clear responsibilities and decision authority.
- Publish policies covering access control, encryption, device use, logging, media handling, disposal, and change management.
- Maintain a policy library, version control, approvals, and review cycles; align Audit Log Retention with your documentation retention policy.
- Document system boundaries, data classes, and shared-responsibility with cloud providers.
Data Mapping and Risk Assessment
Inventory PHI data flows
Map where PHI and ePHI enter, move, and rest across your stack. Include ingestion APIs, storage layers, caches, backups, analytics, message queues, logs, and downstream subprocessors. Identify which teams, roles, and services can touch PHI at each point.
- Create a living data-flow diagram that ties components to owners and environments (dev, test, prod).
- Classify data by sensitivity and legal constraints; tag datasets that contain Protected Health Information for special handling.
- Record encryption states, key custodians, and exposure points for integrations and support tooling.
Establish a Risk Assessment Methodology
Adopt a repeatable method that scores likelihood and impact for threats to confidentiality, integrity, and availability. Use it to prioritize mitigations, budget, and timelines. Reassess after material changes, new features, or incidents to keep risk posture current.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
- Identify assets, threats, vulnerabilities, and existing controls for each data flow.
- Evaluate vendor and subprocessor risks alongside internal risks.
- Record residual risk decisions and owners; link them to remediation tasks and due dates.
Control validation and monitoring
- Define key risk indicators (KRIs) such as failed Multi-Factor Authentication attempts, privileged access spikes, or anomalous data exports.
- Continuously test controls with tabletop exercises, access reviews, and backup restores.
- Ensure logging covers authentication, authorization, administrative actions, data queries, and exports to support investigation and Audit Log Retention.
Technical Safeguards Implementation
Access control and identity
- Enforce least privilege with role-based access control and just-in-time elevation for break-glass scenarios.
- Require Multi-Factor Authentication for all workforce members accessing systems with ePHI, especially admins and support engineers.
- Use unique user IDs, short-lived credentials, automated session timeouts, and immediate revocation during offboarding.
ePHI Encryption and key management
- Implement ePHI Encryption in transit (TLS for all services and APIs) and at rest using strong, industry-standard ciphers.
- Centralize key management; restrict key access, rotate keys regularly, and monitor for anomalous key operations.
- Encrypt backups, snapshots, and message queues; validate restore integrity and access controls.
Audit controls, integrity, and monitoring
- Collect security and application logs from identity providers, gateways, databases, and admin tools; time-sync all systems.
- Define Audit Log Retention, immutability, and separation-of-duties for log access; protect logs as sensitive data.
- Use integrity checksums and tamper-evident storage for critical records; alert on unexpected changes to configurations and policies.
Secure engineering and platform hygiene
- Adopt secure SDLC practices: code reviews, dependency scanning, SAST/DAST, container image scanning, and timely patching.
- Segment networks and tenants, restrict management plane access, and harden CI/CD secrets handling.
- Implement rate limits, anomaly detection, and data-loss prevention on export paths and reporting modules.
Administrative Safeguards and Training
Policy-driven operations
- Maintain formal risk management, change management, and access review processes tied to your Risk Assessment Methodology.
- Perform periodic third-party security assessments or audits and track corrective actions to closure.
- Enforce workforce security through background checks, least-privilege onboarding, and rapid offboarding.
Security awareness and role-based training
- Deliver recurring training for all staff on HIPAA, Protected Health Information handling, phishing, and data classification.
- Provide specialized training for developers, SREs, and customer support on ePHI-specific procedures and tooling.
- Run incident tabletop exercises that walk through your Incident Response Plan and breach decision-making.
Contingency and continuity planning
- Maintain tested backup, disaster recovery, and business continuity plans with defined recovery objectives.
- Document emergency mode operations for critical clinical workflows and support channels.
- Track dependencies on cloud regions, managed services, and subprocessors; design for failover where feasible.
Physical Security Measures
Facilities and device protections
Even as a cloud-first SaaS, you must address physical risks to endpoints, support devices, and any on-prem equipment. Define standards for secure workspaces, device encryption, and media disposal to prevent unauthorized PHI exposure.
- Require full-disk encryption, automatic screen locks, and device inventory with remote wipe capabilities.
- Limit local storage of PHI; prefer secure, access-controlled applications and approved data paths.
- Use visitor management and access controls for offices; log and review badge events where applicable.
- Sanitize or destroy hardware and removable media before disposal or reuse.
Cloud and colocation considerations
- Document shared-responsibility with your IaaS/PaaS providers; obtain and review relevant facility and control attestations.
- Validate data residency constraints, backup locations, and cross-region replication settings.
Incident Response and Breach Notification
Build and rehearse your Incident Response Plan
- Define intake channels, severity levels, roles, and decision criteria for potential PHI incidents.
- Standardize playbooks for credential compromise, data exfiltration, ransomware, and misconfiguration.
- Practice cross-functional exercises with security, legal, privacy, engineering, and customer success.
Investigation, containment, and recovery
- Leverage centralized logging to reconstruct timelines; preserve forensic artifacts with chain-of-custody.
- Contain exposure by revoking credentials, isolating systems, and rotating keys; verify eradication before restoring services.
- Conduct a HIPAA breach risk assessment, document findings, and decide on notification obligations with counsel and stakeholders.
Communication and documentation
- Prepare templates for customer notices, regulator notifications, and internal updates.
- Document lessons learned, control improvements, and any updates to policies, training, and monitoring.
- Ensure your Audit Log Retention supports incident investigations and regulatory inquiries.
Vendor Management and Business Associate Agreements
Due diligence and onboarding
- Perform risk assessments for each subprocessor that may handle PHI; review their controls, attestations, and Incident Response Plan.
- Validate encryption, access control, availability commitments, and data location practices before authorizing use.
- Require a signed Business Associate Agreement and ensure obligations flow down to any of their subcontractors.
Essential BAA components to verify
- Permitted uses and disclosures of PHI and ePHI; prohibition on unauthorized secondary use.
- Security safeguards, breach reporting timelines, cooperation duties, and access to logs relevant to investigations.
- Subcontractor flow-down, right to audit, termination rights, and return or destruction of PHI at end of services.
- Requirements for ePHI Encryption, Multi-Factor Authentication, and Audit Log Retention where applicable.
Ongoing oversight
- Track vendor performance via SLAs, security KPIs, and periodic reassessments.
- Review penetration test summaries, vulnerability remediation cadence, and notable incident histories.
- Reconfirm BAA terms during renewals and after scope changes; update risk records accordingly.
Conclusion
By mapping PHI flows, applying a consistent Risk Assessment Methodology, hardening technical controls like ePHI Encryption and Multi-Factor Authentication, and enforcing strong governance through training, incident readiness, and BAAs, you create a defensible HIPAA program. Treat this checklist as a living system you iterate as your platform and threat landscape evolve.
FAQs
What are the key HIPAA rules SaaS EHR subprocessors must follow?
You must operationalize the Privacy, Security, and Breach Notification Rules. That means limiting PHI use to permitted purposes, safeguarding ePHI with administrative, physical, and technical controls, and executing timely assessments and notifications when an incident may compromise PHI. Your obligations flow from your Business Associate Agreement and apply to any subcontractors who touch PHI.
How often should risk assessments be conducted for ePHI?
Perform a comprehensive risk assessment at least annually and whenever you introduce significant changes—such as new features, integrations, regions, or vendors. Use a documented Risk Assessment Methodology so results are comparable over time, and link findings to remediation plans with clear owners and deadlines.
What are the essential components of a Business Associate Agreement?
A solid BAA defines permitted PHI uses and disclosures, required safeguards (including ePHI Encryption and access controls), breach reporting duties and timelines, subcontractor flow-down, right to audit, cooperation during investigations, and terms for returning or destroying PHI at termination. It should also address Audit Log Retention expectations relevant to security events.
When must a breach notification be reported under HIPAA?
Notify without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI. For incidents involving 500 or more individuals in a state or jurisdiction, notice to affected individuals and regulators follows the same outside deadline; smaller breaches are reported to regulators on an annual basis. Coordinate timing and content through your Incident Response Plan and contractual commitments.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.