Cross-industry software58% entry signalMarket screen8 sourced figuresOne thing must be truedefensibility

HIPAA Compliance SaaS — selling the Security Rule

Prepared 2026-09-20

Entry signal — what decides who wins here

One thing must be true
Structure decides One thing must be true Execution decides

Entry turns on a single condition that can be named and tested before much is spent. Clear it and this becomes an execution question; fail it and no amount of operating skill helps.

What you would have to beat

Find something that compounds. Entry is achievable and so is the first customer; what is missing is a reason the next entrant cannot repeat it as easily as you did.

How it was read
Binding constraintUNVERIFIEDdefensibility — Executional — a better operator can move it.
Measured inputsUNVERIFIEDnot applied — This is a software market. The industry’s business counts describe its BUYERS, not the market being entered, so they are left out of the signal.
How many new establishments are still tradingA
Health Care and Social Assistance, US · opened 2020
84%
1 year
65.3%
3 years
52.6%
5 years
36.4%
10 years
opened 2015

Measured, not forecast: the share of US establishments opening in one year that were still active later. It counts good operators and bad ones together, which is exactly why it is the honest answer to “what are the odds”. It is for the whole sector rather than this market, and the ten-year figure comes from an older cohort because no younger one has reached ten years.

This is not a probability of success, and it is not a verdict on you. No survival probability is published per market, and inventing one would be worse than saying so. What the bar reads is how much of the outcome sits inside an operator's control: green means the hurdles are ones a better operator clears, red means the binding constraint is capital, an asset or a permission rather than execution. Someone arriving with an advantage this screen did not assume can win a market shown in red.

Companies named in this market · 17

The binding constraint — defensibility

The control set is public, the regulator gives the artefact away, and the platforms that sell a dozen frameworks throw this one in — there is no ground here that can be held. The floor is zero: ONC, with OCR, publishes the Security Risk Assessment Tool free (v3.7, a 72.5MB Windows installer plus an Excel workbook), aimed in its own words at "medium and small providers" — the exact buyer a HIPAA-only vendor sells to — and NIST SP 800-66 Rev. 2 (February 2024) maps every Security Rule standard to CSF subcategories and SP 800-53r5 controls, machine-readable through NIST's CPRT. The ceiling is the multi-framework platform: Vanta, Secureframe and Scytale each list HIPAA as one item on a menu beside SOC 2, ISO 27001, PCI DSS, GDPR, ISO 42001 and CMMC (vendor pages opened 2026-09-20). A health-tech buyer who needs SOC 2 to close enterprise deals gets HIPAA out of the same control set, at no separate line on the quote. Between floor and ceiling sits a thin, transparent price: Accountable HQ publishes $2,028 to $8,148 a year for 15–20 employees, and its own navigation carries comparison pages against Vanta, Sprinto, Secureframe, consultants and spreadsheets — the pure-play conceding the squeeze on its own site. The one pure-play that ever reached a public market settles it. CynergisTek's revenue fell from $21.36M (2019) to $16.30M (2021); Clearwater Compliance, an Altaris portfolio company, took it private at $1.25 cash a share on 2022-09-01 — about $16.6M for the equity, roughly one times revenue, and below every outstanding option strike, so all options were cancelled for nothing. The honest screening outcome is that this is a framework inside a broader compliance product, not a standalone market.

Angel-backed companies39
in the Canadian portfolio dataset
Province mixAB 12, ON 10, QC 8, BC 3, NB 2, SK 1, YT 1, NL 1, NS 1

Sectors joined: HealthTech · Healthcare · Health SaaS · Health Tech · Healthcare/AI · Healthcare/VR

[UNVERIFIED] Sector-to-NAICS mapping is analyst judgment — see data/angel-sector-map.json. Counts are a per-record cross-reference and are not additive across records.

I

The incumbent

Who owns this market and who is coming for it. Fields a screen never reached say so rather than guessing.

Incumbent
Nobody owns it as a category. The nearest thing to an incumbent is the multi-framework compliance platform — Vanta, Drata, Secureframe — for which HIPAA is one framework among many, with HealthStream holding the hospital training and documentation half
Scale
HealthStream reported $304,064,000 of FY2025 revenue and runs a single reportable segment, so no HIPAA or GRC line is visible inside it [A, 10-K filed 2026-02-27]. Vanta is reported at $300M ARR in April 2026 with ~16,000 customers by private-market research [C] — carried elsewhere in this atlas at the same tier and not relied on here
Share
No share figure exists and none is offered. No vendor discloses a HIPAA-compliance revenue line, no government series counts the category, and the analyst quadrants that circulate are marketing artefacts rather than measurement
Challengers
Compliancy Group, Accountable HQ, MedTrainer, Clearwater, Censinet, Symplr and Intraprise Health on the healthcare-native side; Sprinto, Scytale, Thoropass and the SOC 2 platforms from above; Paubox and Virtru on the encrypted-communications edge; HHS's own free SRA Tool from below
Lock-in mechanism
Weak, and weaker than the compliance framing suggests. The retention duty — six years from creation or last effect, 45 CFR 164.316(b)(2)(i) — falls on the covered entity, not on the vendor, so the policies, training records and BAA register are the buyer's documents and they export. What a switch costs is a year of habit and a re-upload, not a migration of a system of record
Price movement
Down, and increasingly invisible. Accountable HQ publishes list prices of $199, $299 and $799 a month, or $169, $254 and $679 billed annually ($2,028 / $3,048 / $8,148 a year) for 15–20 employees with extra seats at $9–$19 a month. Vanta, Drata and Secureframe publish no prices at all, which is how a bundle wins: HIPAA never appears as a line the buyer can compare
Is the buyer consolidating?
Yes — The software is consolidating whether or not the buyer is. Privacy, security compliance, vendor risk and framework evidence keep merging into one platform, which removes the standalone HIPAA purchase; on the healthcare side the parallel claim that physician practices are being absorbed into systems and PE platforms with one shared compliance office is plausible and was NOT sourced on this screen [UNVERIFIED]
F

Financials & market size — sourced

Figures that came from a filing, a results release or reputable reporting, each carrying its evidence tier.

HIPAA civil money penalty tiers, currently codifiedA Per violation: tier 1 (did not know) $145 minimum; tier 2 (reasonable cause) $1,461 minimum; tier 3 (willful neglect, corrected) $14,602 minimum; tier 4 (willful neglect, uncorrected) $73,011 minimum. Tiers 1–3 cap at $73,011 per violation; every tier carries a calendar-year cap of $2,190,294 for identical violations. 45 CFR 102.3, the 2025 adjusted column (eCFR current as of 2026-09-01; last amended 91 FR 3666, 2026-01-28; CPI factor 1.02598)
The pending Security Rule rewrite — still pendingA "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information", NPRM at 90 FR 898, published 2025-01-06, RIN 0945-AA22, 125 pages, comments closed 2025-03-07. No final rule had been published under that RIN as of 2026-09-20 — twenty months of a tailwind every vendor in this category sells against, and it has not landed
The government's free artefactA HHS ONC, with OCR, publishes the Security Risk Assessment Tool at no charge: v3.7, a 72.5MB Windows MSI plus an Excel workbook edition, target audience stated as "medium and small providers". Page last updated 2026-09-18; HHS states nothing entered is collected or transmitted
The government's free control mappingA NIST SP 800-66 Rev. 2, "Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide", February 2024 — maps every Security Rule standard and implementation specification to NIST CSF subcategories and SP 800-53r5 controls, with the tables published machine-readable through NIST's CPRT
What the only listed pure-play was worthA CynergisTek: FY2021 revenue $16,301,905 on a falling three-year line, acquired by Clearwater Compliance (Altaris) at $1.25 cash per share, completed 2022-09-01 — about $16.6M of equity value on 13,256,570 shares, roughly 1.0x revenue, below every option strike. Deregistered September 2022
What a strategic paid for a healthcare compliance bookA Health Catalyst paid $44.9M for Intraprise Health on 2024-11-08 ($25.4M net cash, $19.5M in shares), allocating $12.4M to client relationships against $4.2M to developed technology and assuming $2.877M of deferred revenue
What a HIPAA-only seat actually costsB Accountable HQ list prices, opened 2026-09-20: $2,028 / $3,048 / $8,148 a year for 15–20 employees (or $199 / $299 / $799 a month), extra seats $9–$19 a month. The only published price in the category — Vanta, Drata and Secureframe publish none
HealthStream, the listed comparatorA FY2025 revenue $304,064,000, net income $18,342,000, one reportable segment, no compliance line broken out (10-K filed 2026-02-27); still Nasdaq-listed, confirmed 2026-09-15
$

Market size, derived

Built from the competitor set upward rather than quoted from a forecast. Published TAMs in these categories are frequently reverse-engineered from each other, so any published figure is checked against the vendor arithmetic rather than trusted on its own.

Revenue floor
$320M

Disclosed revenue from 2 of 8 named vendors. The market is at least this large.

Implied total — revenue ÷ share
—

No vendor has both a disclosed revenue and a published share.

Published forecast
—Floor only

Only a revenue floor is known — the true market is larger by whatever the undisclosed vendors earn.

Competitor set · 8 named · 2 disclose revenue

NameRevenueShareNote
HealthStreamNASDAQ: HSTMA $304M — FY2025 total revenue (year ended 2025-12-31), 10-K filed 2026-02-27. Company-wide, NOT a HIPAA figure: HealthStream has had a single reportable segment since 2023-01-01 and discloses no compliance, GRC or HIPAA revenue line, though it describes its origin as GRC offerings and sells the HIPAA-mandated training and documentation that hospitals must evidence. Confirmed still listed on the Nasdaq Global Select Market by an 8-K filed 2026-09-15 reporting a $40.0M share issue at $29.50
Intraprise Health (Health Catalyst)NASDAQ: HCATA not disclosed — No product revenue is disclosed. What is disclosed: Health Catalyst acquired Intraprise Health, LLC on 2024-11-08 for $44.9M of consideration — $25.4M net cash plus $19.5M in HCAT shares — and allocated it $12.4M to client relationships, $4.2M to developed technology, $0.3M to trademarks and $29.6M to goodwill, assuming $2.877M of deferred revenue (10-K for FY2025, filed 2026-03-12). The ratio of client relationships to technology is the finding. Health Catalyst itself reported $311.1M of FY2025 revenue and a $178.0M net loss including a $105.4M goodwill impairment driven by its own share price — a company-wide charge, not an Intraprise write-down. The identification of HIPAA One as Intraprise's product comes from the brief, not from the filing [UNVERIFIED]
CynergisTekA $16M — FY2021, the last published full year (10-K filed 2022-03-28) — a closing figure, not a current one. No longer public: Form 25-NSE filed 2022-09-01, Form 15-12G filed 2022-09-13, effective 2022-09-19. Revenue was falling — $21,364,810 (FY2019), $18,872,235 (FY2020), $16,301,905 (FY2021), with a $2.25M net loss in the final year. Clearwater Compliance LLC, a portfolio company of Altaris Capital Partners, acquired it at $1.25 cash per share, completed 2022-09-01; on 13,256,570 shares that is about $16.6M of equity value (not enterprise value), roughly 1.0x revenue, and below every outstanding option strike — all options were cancelled for no consideration. The business was advisory-led rather than pure software, which is itself the point about this market's shape
VantaC not disclosed — Private; no revenue published. Reported at $300M ARR in April 2026, +69% YoY, ~16,000 customers by private-market research [C] and not relied on here. Its own site (opened 2026-09-20) lists HIPAA and HITRUST as two frameworks beside SOC 2, ISO 27001, GDPR, USDP, ISO 42001, NIST AI RMF and custom frameworks, carries a Healthcare industry page, and publishes no prices
Accountable HQC not disclosed — Private; no revenue published. Publishes list prices — $199 / $299 / $799 a month, or $2,028 / $3,048 / $8,148 a year, for 15–20 employees, extra seats $9–$19 a month — and claims "10,000+ companies" and "30 days average time to compliance" on the same page (vendor page opened 2026-09-20; the claims are unaudited). Its navigation carries comparison pages headed Accountable vs. Vanta, vs. Secureframe, vs. Sprinto, vs. Compliancy Group, vs. consultants and vs. DIY
Drata / Secureframe / Sprinto / Scytale / ThoropassC not disclosed — All private; none publishes revenue. Secureframe and Scytale each list HIPAA as one framework among CMMC 2.0, SOC 2, ISO 27001, PCI DSS, ISO 42001, SOX ITGC, CCPA and GDPR (vendor pages opened 2026-09-20). Drata's pricing page was behind a bot challenge on the same date and could not be read
Compliancy Group / MedTrainer / Censinet / Clearwater / SymplrC not disclosed — All private; none publishes revenue. Clearwater is an Altaris Capital Partners portfolio company and owns the former CynergisTek [A, from CynergisTek's own merger filings]; ownership of the others was not verified on this screen [UNVERIFIED]
Paubox / VirtruC not disclosed — Private; no revenue published. Encrypted email and data protection sold into the same buyer on a HIPAA pretext — adjacent rather than competing, and a reminder that the willingness to pay attaches to a working product, not to the compliance paperwork [C]
V

Vendor landscape

Market leaders, the full paid field, and every open-source alternative. Where a free tier exists it is what sets the price floor, so it is analysis rather than an appendix.

HealthStreamA

$304.064M FY2025 revenue, one reportable segment, no HIPAA line disclosed [A]

VantaC

$300M ARR April 2026, ~16,000 customers, by private-market research [C]; HIPAA is one framework of many on its own menu

The HIPAA-only segmentC

No leader can be named. Every pure-play is private and discloses nothing, and the only one that ever published — CynergisTek — was shrinking when it left the market

Paid field · 10 vendors

Vanta / Drata / SecureframeSMB to enterprise, multi-framework

HIPAA as one framework beside SOC 2 and ISO 27001. No published prices

Compliancy GroupSmall practice

Private. Consultant-led delivery, which is how the segment has always sold

Accountable HQSmall practice / health-tech startup

Private. The transparent-priced end: $2,028–$8,148 a year

MedTrainerPractice and clinic groups

Private. Training, credentialing and compliance documentation together

ClearwaterHospital / health system

Private, Altaris-backed; advisory-led, and owns the former CynergisTek

CensinetHealth system third-party risk

Private. Vendor risk exchange rather than a compliance workbook

SymplrHealth system governance and credentialing

Private; ownership not verified on this screen. Compliance arrives inside a governance and credentialing workflow suite

HealthStreamHospital workforce

Nasdaq: HSTM. The HIPAA-mandated training and its documented completion

Intraprise HealthProvider risk and security

Owned by Health Catalyst (Nasdaq: HCAT) since November 2024

Paubox / VirtruEncrypted communications

Private. Sells a working product on a HIPAA pretext, not the paperwork

Open source · 3 projects — the price floor

HHS ONC / OCR Security Risk Assessment (SRA) ToolNot open source — a U.S. Government work, published free of charge

v3.7: Windows desktop application (72.5MB MSI) plus an Excel workbook edition. Walks a provider through the risk analysis the Security Rule requires; stated target audience is medium and small providers. Nothing entered leaves the user's machine

NIST SP 800-66 Rev. 2Not open source — a U.S. Government publication, free of charge

February 2024. Maps every HIPAA Security Rule standard to NIST CSF subcategories and SP 800-53r5 controls; the tables are republished machine-readable in NIST's CPRT, which is the control library a compliance platform would otherwise build

The Security Rule itselfPublic law, 45 CFR Part 164 Subpart C

The standards, implementation specifications and the six-year documentation retention at 164.316(b)(2)(i) are public text. Nothing in the framework is proprietary to anyone

This category is bounded above and below by things that are not for sale. Below it, the regulator publishes the risk analysis tool and NIST publishes the control mapping, both free. Above it, the multi-framework platforms carry HIPAA as one framework in a menu, so the buyer who needs SOC 2 anyway never sees a HIPAA line on the quote. What is left in between is policy templates, training completions and a BAA register — real work, thin product, and priced accordingly. The NAICS anchor 6211 is navigational convenience only: this software is sold to physician practices, dental and behavioural health practices, hospitals, health plans, billing companies, digital-health startups and any business associate that touches PHI, so no single code contains it.

Evidence

Evidence. SOURCED, tier A, all opened 2026-09-20: HealthStream's FY2025 10-K (filed 2026-02-27) for $304,064,000 of revenue, one reportable segment and no compliance line, and its 8-K of 2026-09-15 confirming it is still Nasdaq-listed — checked before citing, as instructed. Health Catalyst's FY2025 10-K (filed 2026-03-12) for the Intraprise Health purchase price allocation. CynergisTek's full EDGAR history: FY2021 revenue $16,301,905, the merger 8-Ks of 2022-05-23 and 2022-09-01, Form 25-NSE and Form 15-12G — it is NOT public and carries no ticker on this record. 45 CFR 102.3 and 45 CFR 164.316 via the eCFR API for the penalty tiers and the retention duty. Federal Register API for NPRM 90 FR 898 and for the absence of any final rule under RIN 0945-AA22. HealthIT.gov for the SRA Tool v3.7 and NIST CSRC for SP 800-66r2. Vendor pages opened for Accountable HQ's list prices and for the framework menus of Vanta, Secureframe and Scytale — tier B/C, vendor-published and unaudited. NOT SOURCED, and the absence is the finding: no HIPAA-compliance revenue figure exists anywhere on the public record. Compliancy Group, MedTrainer, Censinet, Clearwater, Symplr, Sprinto, Scytale, Thoropass, Paubox and Virtru are all private and disclose nothing — no revenue, no customer count, no price. No category size is claimed; the market-research figures that circulate were not used. OCR enforcement volumes are UNVERIFIED — hhs.gov returned 403 to this research agent on 2026-09-20, so only the codified penalty tiers are cited and no settlement totals or breach counts appear on this record. Vanta's $300M ARR is private-market research [C], carried for consistency with the atlas's GRC record and not relied on. Drata's prices could not be read (bot challenge). That HIPAA One belongs to Intraprise Health is the brief's statement, not a filing's [UNVERIFIED]. Verify before acting.

#

Where the industry talks

The associations, forums and events where people in this trade actually talk shop — where to listen before entering, and where the first customers are found. Each link was opened on the date shown.

AssociationInternationalA
IAPP (International Association of Privacy Professionals)
iapp.org · 90,000 members (2026-09)

Individual members (90,000+ per its About page); privacy, AI-governance certifications (CIPP etc.), 160+ local chapters incl. Canada; runs the Canada Privacy Symposium.

Checked 2026-09-22
AssociationCanadaA
Digital Health Canada
digitalhealthcanada.com · 6,800 members (2026-09)

Individual members (6,800) plus 245 member organizations per its homepage; runs e-Health, Canada's largest digital-health conference (e-Health27, June 16-18 2027, Vancouver).

Checked 2026-09-22
AssociationCanadaA
CHIMA (Canadian Health Information Management Association)
echima.ca · 6,200 members (2026-09)

Health-information members ('more than 6,200' per homepage); the Canadian privacy/records profession that HIPAA-equivalent (PHIPA/PIPEDA) compliance tools sell to.

Checked 2026-09-22
EventNorth AmericaA
HIMSS Global Health Conference & Exhibition (HIMSS27)
himssconference.com

Main health-IT trade show; April 5-8 2027, McCormick Place, Chicago; site says 24,000+ attended the prior edition.

Checked 2026-09-22
PublicationUSA
HIPAA Journal
hipaajournal.com

Daily HIPAA enforcement, breach and compliance news; articles dated Sept 22 2026 at check. Also sells training; no readership figure stated.

Checked 2026-09-22
AssociationInternationalA
Health-ISAC
health-isac.org

Member-driven health-sector cybersecurity information-sharing body for hospitals, payers and vendors; no member count stated on its About page.

Checked 2026-09-22
AssociationUSC
HCCA (Health Care Compliance Association) - Compliance Institute
hcca-info.org

US healthcare compliance officers' association (part of SCCE & HCCA); 31st Compliance Institute April 11-14 2027, Nashville per search results. Site blocked automated access (Cloudflare).

Checked 2026-09-22

HCCA blocks automated access, so it is tier C. Reddit r/healthIT could not be verified from this network.