It’s one of the most common questions Canadian SaaS founders ask before their first US healthcare deal: “HIPAA is an American law — does it actually apply to us?” The honest answer is nuanced, but the practical answer is almost always yes. And the companies that get this wrong tend to find out during a security review, right when a lucrative contract is on the line. By then, retrofitting compliance under deadline pressure costs far more — in engineering time and lost momentum — than building it in from the start.
HIPAA follows the data, not the border
HIPAA doesn’t contain a clause limiting it to American companies. It regulates two kinds of players: Covered Entities (providers, health plans, clearinghouses) and Business Associates (the vendors that handle Protected Health Information on their behalf). Nothing in that framework says the Business Associate has to be incorporated in Delaware. If a US hospital hires a Canadian analytics firm to process patient records, that firm is a Business Associate, full stop. Its nationality is irrelevant.
Since the HITECH Act of 2009 and the Omnibus Rule of 2013, Business Associates carry direct liability for large parts of HIPAA — the Security Rule, breach notification, and the ban on impermissible uses and disclosures. So the real question isn’t “does HIPAA apply to Canadians?” It’s “are we handling US PHI on behalf of a Covered Entity?” If yes, you’re in scope.
“But can US regulators even enforce it against us?”
This is the smarter version of the question, and it deserves a straight answer. Enforcement against a foreign company with no US assets or presence is genuinely more complicated for regulators. But betting your business on jurisdictional friction is a bad strategy, for three reasons.
First, contract. Your US customer will require you to sign a Business Associate Agreement, and that BAA makes your HIPAA obligations directly enforceable by them — in a forum and under terms you agreed to. Breach it and you’re facing breach-of-contract and indemnity claims, not an abstract regulatory debate.
Second, the deal itself. No competent US health system will hand you PHI without evidence of compliance. Fail the security questionnaire and you simply don’t get the contract. Compliance isn’t the punishment for doing business; it’s the ticket to entry.
Third, breach exposure. If you leak US patient data, notification duties, state privacy laws, and plaintiffs’ lawyers don’t wait for a federal ruling. The cross-border angle rarely saves you.
What “actually complying” involves
- A signed BAA with every Covered Entity you serve — and with your own subcontractors.
- The Security Rule safeguards: risk analysis, access controls, encryption, audit logs, workforce training, and a written incident-response plan.
- Breach-notification processes so you can alert the Covered Entity within the required window.
- Documentation — because in HIPAA world, if it isn’t written down, it didn’t happen.
None of that requires a US office. It requires discipline and evidence.
The overlooked upside
Here’s what founders miss: HIPAA readiness is portable. The controls you build — encryption, least-privilege access, logging, vendor management — are the same ones SOC 2, ISO 27001, and Canada’s own privacy laws reward. Treating HIPAA compliance as a foundation rather than a one-off checkbox means you clear multiple bars at once and shorten every future procurement cycle. Buyers increasingly ask for a SOC 2 report or an ISO 27001 certificate in the same breath as a signed BAA; the vendor who has already invested in the underlying controls answers all three questions with a single body of evidence instead of scrambling three times.
So, do Canadian vendors actually need to comply? If US PHI touches your systems, yes — and the smart ones stop asking whether they can dodge it and start treating it as the credential that unlocks the largest healthcare market on earth. The HHS guidance for professionals is the primary source worth reading before you sign anything; everything downstream flows from understanding whether you’re a Business Associate in the first place.



