About ComplySaaS
Educational SaaS compliance research for regulated workflows
ComplySaaS helps healthcare-adjacent teams investigate public HIPAA, Business Associate Agreement, PHI, and SOC 2 signals before software is introduced into a regulated workflow.
Page reviewed: July 25, 2026
Why this research exists
Vendor pages often separate HIPAA language, BAA terms, security reports, plan requirements, and product limitations across many documents. ComplySaaS organizes those public signals into a cautious starting point for vendor review.
The goal is not to declare that software is compliant. The goal is to help readers identify what is publicly supported, what remains uncertain, and what must be verified directly with the vendor before PHI or other regulated data is involved.
Research scope
Vendor compliance profiles
Public HIPAA, BAA, PHI, and SOC 2 signals for specific SaaS products, including unresolved questions and source dates.
Workflow-focused categories
Research organized around real software use cases such as forms, scheduling, databases, payments, CRM, and AI.
Verification guides
Practical questions for reviewing agreements, covered services, configuration, access, retention, support, and integrations.
Who it is for
ComplySaaS is designed for healthcare-adjacent founders, operators, IT teams, security and privacy teams, consultants, and procurement reviewers who need a structured first pass before formal legal, compliance, security, or contract review.
What it does not do
ComplySaaS is not a law firm, auditor, certification body, healthcare provider, or substitute for vendor due diligence. A listing, status label, or BAA signal does not approve a vendor or make a customer workflow compliant.
Research standards and corrections
The methodology explains source selection, status labels, unresolved questions, update limits, and editorial independence. Corrections should include the affected URL and a current first-party source.