HIPAA for Canadian SaaS companies selling into the US

A Canadian SaaS company becomes a HIPAA business associate when it handles protected health information for a US covered entity, such as a provider or health plan. It then signs a business associate agreement (BAA), must meet the HIPAA Security Rule for that data, and must report breaches to its customer. Where the company is incorporated does not change the definition.

Are you a business associate?

You are one when you create, receive, maintain or transmit protected health information on behalf of a US covered entity, or on behalf of one of its business associates. Hosting the data counts, even if nobody at your company ever looks at it. The definition in 45 CFR 160.103 turns on the function you perform, not on your location. It also covers subcontractors: if your US customer is itself a vendor to a hospital, you are a business associate one link down the chain.

Whether US regulators could act against a Canadian company directly is a question for counsel. In practice it rarely decides anything, because the BAA binds you by contract either way.

What does a BAA commit you to?

Under 45 CFR 164.314, the agreement must require you to:

  • comply with the Security Rule for electronic protected health information;
  • flow the same terms down to any subcontractor that handles it, including your hosting and support providers;
  • report to the customer any security incident you become aware of, including breaches.

The privacy terms in 164.504(e) add two that matter to a foreign vendor: making your records on that data available to HHS, and returning or destroying the data when the contract ends, where feasible.

The last item is broader than most vendors expect. “Any security incident” is not limited to breaches, so agree with the customer, and with your counsel, what gets reported and how.

What does the Security Rule require of a small vendor?

As of September 2026, the rule sets administrative, physical and technical safeguards, and 164.306 lets you choose measures in light of your size, complexity, infrastructure, cost and the risks involved. That flexibility rests on one required document: an accurate and thorough risk analysis under 164.308. Without it, every other control is hard to defend.

The common myth is that compliance can be bought as a badge. Can you get a HIPAA certificate? No. There is no body that issues a HIPAA certificate. What a customer can reasonably ask for is evidence: your risk analysis, your safeguards, and the contract you signed. HHS warns about marketing claims that suggest otherwise.

Who do you notify after a breach?

Your obligation is to notify the covered entity, without unreasonable delay and no later than 60 calendar days after discovery, unless law enforcement asks for a delay under 45 CFR 164.412. The covered entity notifies individuals. A subcontractor notifies the business associate above it. Under 164.410 (the delay rule is 164.412), discovery is the first day the breach is known, or would have been known with reasonable diligence. Weak detection does not stop the clock; it only means you learn late how much of it has run.

Does Canadian privacy law still apply? Yes. Canadian privacy law still governs your own handling of personal information; HIPAA arrives on top of it through your US customers, not instead of it. The federal baseline is PIPEDA, and the Canadian privacy law map covers the provinces.

Where should a Canadian SaaS vendor start?

Inventory where health data lives and which subprocessors touch it, then do the risk analysis. That work is part of regulated-sector readiness; wider buyer questions are in security for SaaS selling to enterprise.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

When is a Canadian SaaS vendor a HIPAA business associate?

When you create, receive, maintain or transmit protected health information on behalf of a US covered entity, or on behalf of one of its business associates. Hosting the data counts, even if nobody at your company ever looks at it.

Can we get a HIPAA certificate?

No. There is no body that issues a HIPAA certificate. What a customer can reasonably ask for is evidence: your risk analysis, your safeguards, and the contract you signed.

Who notifies patients if we have a breach?

Your obligation is to notify the covered entity, without unreasonable delay and no later than 60 calendar days after discovery, unless law enforcement asks for a delay under 45 CFR 164.412. The covered entity notifies individuals. A subcontractor notifies the business associate above it.

Does Canadian privacy law still apply?

Yes. Canadian privacy law still governs your own handling of personal information; HIPAA arrives on top of it through your US customers, not instead of it.

Before you sign the BAA

Send us the draft agreement or the customer’s security questionnaire, and the reply says which commitments you can meet today. More of our writing is indexed at writing.

Discuss a scope