How to track hipaa compliance obligations as Small HR Teams
HIPAA compliance for a 2-person HR team supporting 150 employees isn't a project — it's a background anxiety that never resolves. You're responsible for ensuring workforce training completions are documented, tracking who has signed the privacy notice, monitoring Business Associate Agreement renewals with your benefits broker and EAP vendor, and maintaining evidence for any audit. None of that lives in one place. Training completions are in a spreadsheet. BAA expiration dates are in someone's calendar. The attestation forms are in a Google Drive folder with a name nobody can remember. When the compliance consultant asks for documentation, you spend three hours assembling it from four different places.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch syncs your Paylocity data on a schedule — employee roster, departments, hire dates — to power the training tracker. Notion connects from Starch's integration catalog; the agent queries it live to pull your existing policy documents into the knowledge base. Slack connects from Starch's integration catalog so automated alerts land in the right channel. For any vendor BAA portal or benefits broker site that lacks an API, Starch automates it through your browser — no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
Q1 2026 HIPAA readiness check — 150 employees, 11 BAAs
| Employees with training completed and current | 138 |
| Employees with overdue annual recertification (>12 months) | 9 |
| Employees missing initial attestation signature | 3 |
| BAAs tracked in the system | 11 |
| BAAs expiring within 90 days (EAP vendor, dental broker) | 2 |
| Hours to assemble this view (before Starch) | 4 |
| Hours to assemble this view (with Starch dashboard) | 0.2 |
Coming into Q1 2026 compliance review, your HR team of two needed to confirm HIPAA readiness before a broker audit. Before Starch, that meant pulling the Paylocity headcount export, cross-referencing it against a Google Sheet of training completions you'd been maintaining manually, and then digging through a Drive folder called 'BAA Agreements — FINAL' to find which ones were still active. It took about four hours and you still weren't confident you'd caught everything. With the Starch training tracker live, the Monday morning Slack automation flagged 9 employees with overdue recertification and 3 missing initial attestations two weeks before the audit — enough time to chase managers and close the gaps. The BAA tracker surfaced that your EAP vendor's agreement expires in 67 days and your dental broker's in 41 days. Both renewals got captured as P1 tasks in the Task Manager with the renewal owner assigned. On audit day, generating the evidence package took 12 minutes: training completions export by department, BAA inventory with execution dates, and a policy version log from the Knowledge Management app. The compliance consultant's exact words: 'This is more organized than companies three times your size.'
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — task manager, knowledge management all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
Does Starch store our employee PHI or HIPAA-sensitive documents?
What if our BAA documents live in a vendor portal that doesn't have an API?
We use Gusto, not Paylocity or ADP — can we still build the training tracker?
Can Starch send the overdue-training alerts somewhere other than Slack?
What about Contract Lifecycle Management for our BAAs — is that available now?
We don't have a formal training program — we just send a PDF and ask people to reply. Can Starch track that?
Related guides for Small HR Teams
A customer knowledge base is the document — or collection of documents — that answers the questions your customers ask repeatedly.
Read guide →SOC 2 evidence collection is the part of an audit where you prove that your controls actually work — not just that they're written down somewhere.
Read guide →A Slack announcement sounds simple — you're just telling your team something.
Read guide →Benefits enrollment is one of those operator workflows that looks manageable until it isn't.
Read guide →Track HIPAA Compliance Obligations for other operators
The AI stack built for independent clinic owner-operators.
Read guide →The AI stack built for small in-house legal and compliance teams.
Read guide →The AI stack built for small IT and ITOps teams.
Read guide →Ready to run track hipaa compliance obligations on Starch?
Request closed-beta access. Everything is free during beta.