HIPAA Compliance SaaS — selling the Security Rule
Entry signal — what decides who wins here
One thing must be trueEntry turns on a single condition that can be named and tested before much is spent. Clear it and this becomes an execution question; fail it and no amount of operating skill helps.
Find something that compounds. Entry is achievable and so is the first customer; what is missing is a reason the next entrant cannot repeat it as easily as you did.
Measured, not forecast: the share of US establishments opening in one year that were still active later. It counts good operators and bad ones together, which is exactly why it is the honest answer to “what are the odds”. It is for the whole sector rather than this market, and the ten-year figure comes from an older cohort because no younger one has reached ten years.
This is not a probability of success, and it is not a verdict on you. No survival probability is published per market, and inventing one would be worse than saying so. What the bar reads is how much of the outcome sits inside an operator's control: green means the hurdles are ones a better operator clears, red means the binding constraint is capital, an asset or a permission rather than execution. Someone arriving with an advantage this screen did not assume can win a market shown in red.
Companies named in this market · 17
The binding constraint — defensibility
The control set is public, the regulator gives the artefact away, and the platforms that sell a dozen frameworks throw this one in — there is no ground here that can be held. The floor is zero: ONC, with OCR, publishes the Security Risk Assessment Tool free (v3.7, a 72.5MB Windows installer plus an Excel workbook), aimed in its own words at "medium and small providers" — the exact buyer a HIPAA-only vendor sells to — and NIST SP 800-66 Rev. 2 (February 2024) maps every Security Rule standard to CSF subcategories and SP 800-53r5 controls, machine-readable through NIST's CPRT. The ceiling is the multi-framework platform: Vanta, Secureframe and Scytale each list HIPAA as one item on a menu beside SOC 2, ISO 27001, PCI DSS, GDPR, ISO 42001 and CMMC (vendor pages opened 2026-09-20). A health-tech buyer who needs SOC 2 to close enterprise deals gets HIPAA out of the same control set, at no separate line on the quote. Between floor and ceiling sits a thin, transparent price: Accountable HQ publishes $2,028 to $8,148 a year for 15–20 employees, and its own navigation carries comparison pages against Vanta, Sprinto, Secureframe, consultants and spreadsheets — the pure-play conceding the squeeze on its own site. The one pure-play that ever reached a public market settles it. CynergisTek's revenue fell from $21.36M (2019) to $16.30M (2021); Clearwater Compliance, an Altaris portfolio company, took it private at $1.25 cash a share on 2022-09-01 — about $16.6M for the equity, roughly one times revenue, and below every outstanding option strike, so all options were cancelled for nothing. The honest screening outcome is that this is a framework inside a broader compliance product, not a standalone market.
Sectors joined: HealthTech · Healthcare · Health SaaS · Health Tech · Healthcare/AI · Healthcare/VR
[UNVERIFIED] Sector-to-NAICS mapping is analyst judgment — see data/angel-sector-map.json. Counts are a per-record cross-reference and are not additive across records.
The incumbent
Who owns this market and who is coming for it. Fields a screen never reached say so rather than guessing.
Financials & market size — sourced
Figures that came from a filing, a results release or reputable reporting, each carrying its evidence tier.
Market size, derived
Built from the competitor set upward rather than quoted from a forecast. Published TAMs in these categories are frequently reverse-engineered from each other, so any published figure is checked against the vendor arithmetic rather than trusted on its own.
Disclosed revenue from 2 of 8 named vendors. The market is at least this large.
No vendor has both a disclosed revenue and a published share.
Only a revenue floor is known — the true market is larger by whatever the undisclosed vendors earn.
Competitor set · 8 named · 2 disclose revenue
| Name | Revenue | Share | Note |
|---|---|---|---|
| HealthStreamNASDAQ: HSTMA | $304M | — | FY2025 total revenue (year ended 2025-12-31), 10-K filed 2026-02-27. Company-wide, NOT a HIPAA figure: HealthStream has had a single reportable segment since 2023-01-01 and discloses no compliance, GRC or HIPAA revenue line, though it describes its origin as GRC offerings and sells the HIPAA-mandated training and documentation that hospitals must evidence. Confirmed still listed on the Nasdaq Global Select Market by an 8-K filed 2026-09-15 reporting a $40.0M share issue at $29.50 |
| Intraprise Health (Health Catalyst)NASDAQ: HCATA | not disclosed | — | No product revenue is disclosed. What is disclosed: Health Catalyst acquired Intraprise Health, LLC on 2024-11-08 for $44.9M of consideration — $25.4M net cash plus $19.5M in HCAT shares — and allocated it $12.4M to client relationships, $4.2M to developed technology, $0.3M to trademarks and $29.6M to goodwill, assuming $2.877M of deferred revenue (10-K for FY2025, filed 2026-03-12). The ratio of client relationships to technology is the finding. Health Catalyst itself reported $311.1M of FY2025 revenue and a $178.0M net loss including a $105.4M goodwill impairment driven by its own share price — a company-wide charge, not an Intraprise write-down. The identification of HIPAA One as Intraprise's product comes from the brief, not from the filing [UNVERIFIED] |
| CynergisTekA | $16M | — | FY2021, the last published full year (10-K filed 2022-03-28) — a closing figure, not a current one. No longer public: Form 25-NSE filed 2022-09-01, Form 15-12G filed 2022-09-13, effective 2022-09-19. Revenue was falling — $21,364,810 (FY2019), $18,872,235 (FY2020), $16,301,905 (FY2021), with a $2.25M net loss in the final year. Clearwater Compliance LLC, a portfolio company of Altaris Capital Partners, acquired it at $1.25 cash per share, completed 2022-09-01; on 13,256,570 shares that is about $16.6M of equity value (not enterprise value), roughly 1.0x revenue, and below every outstanding option strike — all options were cancelled for no consideration. The business was advisory-led rather than pure software, which is itself the point about this market's shape |
| VantaC | not disclosed | — | Private; no revenue published. Reported at $300M ARR in April 2026, +69% YoY, ~16,000 customers by private-market research [C] and not relied on here. Its own site (opened 2026-09-20) lists HIPAA and HITRUST as two frameworks beside SOC 2, ISO 27001, GDPR, USDP, ISO 42001, NIST AI RMF and custom frameworks, carries a Healthcare industry page, and publishes no prices |
| Accountable HQC | not disclosed | — | Private; no revenue published. Publishes list prices — $199 / $299 / $799 a month, or $2,028 / $3,048 / $8,148 a year, for 15–20 employees, extra seats $9–$19 a month — and claims "10,000+ companies" and "30 days average time to compliance" on the same page (vendor page opened 2026-09-20; the claims are unaudited). Its navigation carries comparison pages headed Accountable vs. Vanta, vs. Secureframe, vs. Sprinto, vs. Compliancy Group, vs. consultants and vs. DIY |
| Drata / Secureframe / Sprinto / Scytale / ThoropassC | not disclosed | — | All private; none publishes revenue. Secureframe and Scytale each list HIPAA as one framework among CMMC 2.0, SOC 2, ISO 27001, PCI DSS, ISO 42001, SOX ITGC, CCPA and GDPR (vendor pages opened 2026-09-20). Drata's pricing page was behind a bot challenge on the same date and could not be read |
| Compliancy Group / MedTrainer / Censinet / Clearwater / SymplrC | not disclosed | — | All private; none publishes revenue. Clearwater is an Altaris Capital Partners portfolio company and owns the former CynergisTek [A, from CynergisTek's own merger filings]; ownership of the others was not verified on this screen [UNVERIFIED] |
| Paubox / VirtruC | not disclosed | — | Private; no revenue published. Encrypted email and data protection sold into the same buyer on a HIPAA pretext — adjacent rather than competing, and a reminder that the willingness to pay attaches to a working product, not to the compliance paperwork [C] |
Vendor landscape
Market leaders, the full paid field, and every open-source alternative. Where a free tier exists it is what sets the price floor, so it is analysis rather than an appendix.
$304.064M FY2025 revenue, one reportable segment, no HIPAA line disclosed [A]
$300M ARR April 2026, ~16,000 customers, by private-market research [C]; HIPAA is one framework of many on its own menu
No leader can be named. Every pure-play is private and discloses nothing, and the only one that ever published — CynergisTek — was shrinking when it left the market
Paid field · 10 vendors
HIPAA as one framework beside SOC 2 and ISO 27001. No published prices
Private. Consultant-led delivery, which is how the segment has always sold
Private. The transparent-priced end: $2,028–$8,148 a year
Private. Training, credentialing and compliance documentation together
Private, Altaris-backed; advisory-led, and owns the former CynergisTek
Private. Vendor risk exchange rather than a compliance workbook
Private; ownership not verified on this screen. Compliance arrives inside a governance and credentialing workflow suite
Nasdaq: HSTM. The HIPAA-mandated training and its documented completion
Owned by Health Catalyst (Nasdaq: HCAT) since November 2024
Private. Sells a working product on a HIPAA pretext, not the paperwork
Open source · 3 projects — the price floor
v3.7: Windows desktop application (72.5MB MSI) plus an Excel workbook edition. Walks a provider through the risk analysis the Security Rule requires; stated target audience is medium and small providers. Nothing entered leaves the user's machine
February 2024. Maps every HIPAA Security Rule standard to NIST CSF subcategories and SP 800-53r5 controls; the tables are republished machine-readable in NIST's CPRT, which is the control library a compliance platform would otherwise build
The standards, implementation specifications and the six-year documentation retention at 164.316(b)(2)(i) are public text. Nothing in the framework is proprietary to anyone
This category is bounded above and below by things that are not for sale. Below it, the regulator publishes the risk analysis tool and NIST publishes the control mapping, both free. Above it, the multi-framework platforms carry HIPAA as one framework in a menu, so the buyer who needs SOC 2 anyway never sees a HIPAA line on the quote. What is left in between is policy templates, training completions and a BAA register — real work, thin product, and priced accordingly. The NAICS anchor 6211 is navigational convenience only: this software is sold to physician practices, dental and behavioural health practices, hospitals, health plans, billing companies, digital-health startups and any business associate that touches PHI, so no single code contains it.
Evidence
Evidence. SOURCED, tier A, all opened 2026-09-20: HealthStream's FY2025 10-K (filed 2026-02-27) for $304,064,000 of revenue, one reportable segment and no compliance line, and its 8-K of 2026-09-15 confirming it is still Nasdaq-listed — checked before citing, as instructed. Health Catalyst's FY2025 10-K (filed 2026-03-12) for the Intraprise Health purchase price allocation. CynergisTek's full EDGAR history: FY2021 revenue $16,301,905, the merger 8-Ks of 2022-05-23 and 2022-09-01, Form 25-NSE and Form 15-12G — it is NOT public and carries no ticker on this record. 45 CFR 102.3 and 45 CFR 164.316 via the eCFR API for the penalty tiers and the retention duty. Federal Register API for NPRM 90 FR 898 and for the absence of any final rule under RIN 0945-AA22. HealthIT.gov for the SRA Tool v3.7 and NIST CSRC for SP 800-66r2. Vendor pages opened for Accountable HQ's list prices and for the framework menus of Vanta, Secureframe and Scytale — tier B/C, vendor-published and unaudited. NOT SOURCED, and the absence is the finding: no HIPAA-compliance revenue figure exists anywhere on the public record. Compliancy Group, MedTrainer, Censinet, Clearwater, Symplr, Sprinto, Scytale, Thoropass, Paubox and Virtru are all private and disclose nothing — no revenue, no customer count, no price. No category size is claimed; the market-research figures that circulate were not used. OCR enforcement volumes are UNVERIFIED — hhs.gov returned 403 to this research agent on 2026-09-20, so only the codified penalty tiers are cited and no settlement totals or breach counts appear on this record. Vanta's $300M ARR is private-market research [C], carried for consistency with the atlas's GRC record and not relied on. Drata's prices could not be read (bot challenge). That HIPAA One belongs to Intraprise Health is the brief's statement, not a filing's [UNVERIFIED]. Verify before acting.
Where the industry talks
The associations, forums and events where people in this trade actually talk shop — where to listen before entering, and where the first customers are found. Each link was opened on the date shown.
Individual members (90,000+ per its About page); privacy, AI-governance certifications (CIPP etc.), 160+ local chapters incl. Canada; runs the Canada Privacy Symposium.
Individual members (6,800) plus 245 member organizations per its homepage; runs e-Health, Canada's largest digital-health conference (e-Health27, June 16-18 2027, Vancouver).
Health-information members ('more than 6,200' per homepage); the Canadian privacy/records profession that HIPAA-equivalent (PHIPA/PIPEDA) compliance tools sell to.
Main health-IT trade show; April 5-8 2027, McCormick Place, Chicago; site says 24,000+ attended the prior edition.
Daily HIPAA enforcement, breach and compliance news; articles dated Sept 22 2026 at check. Also sells training; no readership figure stated.
Member-driven health-sector cybersecurity information-sharing body for hospitals, payers and vendors; no member count stated on its About page.
US healthcare compliance officers' association (part of SCCE & HCCA); 31st Compliance Institute April 11-14 2027, Nashville per search results. Site blocked automated access (Cloudflare).
HCCA blocks automated access, so it is tier C. Reddit r/healthIT could not be verified from this network.