How to track hipaa compliance obligations as Small Legal and Compliance Teams
You're a two-person legal team at a 150-person SaaS company. HIPAA touches your business because sales wants to sign a BAA with every healthcare prospect, IT keeps onboarding new SaaS vendors who might touch PHI, and HR is asking whether your payroll provider counts as a covered entity. You're tracking BAA status in a Notion doc that hasn't been updated since Q2, chasing down which vendors have signed what in a Gmail thread from eight months ago, and manually reminding the security team when annual HIPAA training attestations are due. You know there's an audit window coming. You don't have OneTrust. You have a spreadsheet and a lot of anxiety.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch syncs your Gmail data on a schedule (messages and labels, so BAA emails are searchable and surfaced automatically) and connects directly to your Notion workspace on a schedule (pages and databases, so your existing contract tracker rows are the starting point, not a blank slate). Slack connects from Starch's integration catalog so the agent queries it live when sending deadline alerts. DocuSign and Google Drive connect from Starch's integration catalog — the agent queries them live to check signature status and pull executed BAA files. Any HIPAA-adjacent vendor portal that doesn't have an API — a state health department filing portal, a carrier's compliance attestation form — Starch automates through your browser, no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
Q1 2026 HIPAA Audit Prep — 150-Person SaaS Company
| Active vendors flagged as touching PHI | 23 |
| BAAs confirmed signed and on file | 14 |
| BAAs pending or not started | 9 |
| BAAs expiring within 90 days | 3 |
| Annual policy obligations due in Q1 | 5 |
| Hours to produce the above report manually (pre-Starch) | 11 |
In January 2026, your company gets a heads-up that a healthcare enterprise prospect wants to run a security review before signing. Their questionnaire asks for a list of all subprocessors that touch PHI, each one's BAA status, and your last risk analysis date. Before Starch, answering that question meant cross-referencing a stale Notion spreadsheet against your Gmail inbox for forwarded BAA PDFs, pinging the security team for their vendor list, and spending half a day compiling it. With the HIPAA obligation tracker running on Starch, you pull the current state in under five minutes: 23 vendors flagged as PHI-touching, 14 with signed BAAs on file (DocuSign confirmation pulled live), 9 in some state of incomplete. Three of the 14 signed BAAs are expiring before June — Starch already sent a Slack alert two weeks ago and created task entries for each. The five Q1 policy obligations (workforce training attestation due February 28, risk analysis review due March 31, breach notification policy review due March 15, NPP update due January 31, and security incident response plan review due February 15) are all visible in the task manager with owners assigned. You hand the prospect's team a complete subprocessor list with BAA status in 20 minutes instead of a half-day scramble, and the 9 vendors with gaps become your remediation list for the next two weeks.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — task manager, knowledge management all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
Is Starch SOC 2 Type II certified? Should I be worried about putting BAA-related data in it?
We already track BAAs in Notion. Does Starch replace that, or does it connect to it?
Can Starch actually read our executed BAAs from DocuSign or Google Drive?
What if a vendor's HIPAA compliance portal doesn't have an API?
We're a two-person team. How long does it actually take to set this up?
Does Starch replace a CLM tool if we eventually need one?
Related guides for Small Legal and Compliance Teams
SOC 2 evidence collection is the part of an audit where you prove that your controls actually work — not just that they're written down somewhere.
Read guide →A Slack announcement sounds simple — you're just telling your team something.
Read guide →A Data Subject Access Request is a formal ask from an individual — a customer, a former employee, a prospect — for a copy of every piece of personal data your business holds on them.
Read guide →Employee offboarding is the set of steps you run every time someone leaves — voluntary or not.
Read guide →Track HIPAA Compliance Obligations for other operators
The AI stack built for independent clinic owner-operators.
Read guide →The AI stack built for small IT and ITOps teams.
Read guide →The AI stack built for small HR teams.
Read guide →Ready to run track hipaa compliance obligations on Starch?
Request closed-beta access. Everything is free during beta.