How to track hipaa compliance obligations as Small IT and ITOps Teams
You're two people managing HIPAA obligations across a 300-person company, and nobody handed you a compliance playbook. BAAs need to be tracked across every SaaS vendor that touches PHI — your EHR integration, your SFTP provider, the random analytics tool a product manager connected six months ago. Risk assessments are due annually but live in a Google Doc that's two versions stale. Audit logs exist across AWS CloudWatch, Jira, and Okta, but pulling them together when your security officer asks takes a half-day of tab-switching. Training completion records are in Rippling or BambooHR. Nothing connects, and the next breach notification or OCR audit is the moment you find out what slipped.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Connect AWS (Starch syncs your AWS Cost Explorer and CloudWatch data directly — on-demand queries, no scheduled snapshot), Jira from Starch's integration catalog (the agent queries it live when your compliance tracker runs), Slack from Starch's integration catalog for digest delivery, and Notion if your current runbooks live there (Starch syncs your Notion pages on a schedule). BambooHR or Rippling for workforce training records are reachable from Starch's integration catalog; the agent queries them live. Any vendor portal without an API — such as a BAA signing portal or insurance carrier dashboard — Starch automates through your browser with no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
April 2026 OCR Audit Prep — 2-person IT team, 300 employees
| Vendors requiring BAA review | 23 |
| BAAs confirmed on file | 17 |
| BAAs missing or expired | 6 |
| Employees with incomplete annual HIPAA training | 34 |
| AWS services flagged for PHI-network risk review | 4 |
| Hours to produce audit evidence packet (pre-Starch) | 18 |
| Hours to produce audit evidence packet (with Starch) | 3 |
In early April, your compliance officer tells you an OCR audit readiness review is happening in three weeks. Before Starch, this would mean pulling a vendor list from memory and old Jira tickets, emailing six SaaS admins to confirm BAA status, exporting a training completion CSV from BambooHR, and compiling AWS service inventory by hand from the console — roughly 18 hours across two weeks. With Starch, you open the BAA tracker (built from your Jira vendor-review tags) and immediately see 6 of 23 vendors are flagged: 4 have expired BAAs and 2 have no BAA on file at all. One of the 2 missing BAAs is a recently onboarded analytics vendor that a product manager connected in January — exactly the kind of thing that would have surfaced during the audit instead of before it. The Monday AWS digest has already flagged 4 new services deployed in March that need risk assessments before the review. You open your Starch documentation hub and pull the current risk assessment, incident response plan, and training log in under two minutes. The 34 employees with incomplete training get Jira tickets automatically routed to HR. You walk into the audit review with a complete evidence packet instead of an apology.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — knowledge management, task manager all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
Does Starch store our PHI or HIPAA-covered data?
Can Starch connect to our EHR or specific HIPAA-adjacent vendor portals?
What about the Contract Lifecycle Management app for tracking BAAs specifically?
We already have Notion for runbooks. Does Starch replace that?
Can Starch track when new AWS services are deployed and flag PHI exposure risk automatically?
How do we handle workforce HIPAA training tracking if HR owns the records in BambooHR?
Related guides for Small IT and ITOps Teams
Vendor and category spend analysis means knowing, at any point in time, where your money is actually going — which vendors are getting paid, how much, how often, and whether that number is creeping up or down relative to last month.
Read guide →A customer knowledge base is the document — or collection of documents — that answers the questions your customers ask repeatedly.
Read guide →SOC 2 evidence collection is the part of an audit where you prove that your controls actually work — not just that they're written down somewhere.
Read guide →A Slack announcement sounds simple — you're just telling your team something.
Read guide →Track HIPAA Compliance Obligations for other operators
The AI stack built for independent clinic owner-operators.
Read guide →The AI stack built for small in-house legal and compliance teams.
Read guide →The AI stack built for small HR teams.
Read guide →Ready to run track hipaa compliance obligations on Starch?
Request closed-beta access. Everything is free during beta.