Legal Infrastructure for Healthcare SaaS & AI
I am Sergei Tokmakov, a California attorney. I help digital health startups, healthcare AI companies, and telehealth platforms build the legal foundation they need: HIPAA-compliant agreements, BAAs, Terms of Service, and a privacy stack mapped to all 50 states plus DC.
Tiered pricing: core stack plus scoped extensions
The core stack is a flat fee. Healthcare AI and medico-legal work are add-ons because they are extra drafting, not because they are hidden charges. Anything audit-grade is scoped and quoted on its own.
- Submit your question and key documents
- Written attorney response: issues, risks, next steps
- Best when you are not sure what you need yet
- Permitted uses, safeguards, breach notification
- Subcontractor flow-down, term, and PHI return or destruction
- Up to three rounds of email revisions
- When you already have your MSA, Terms, and Privacy
- MSA + Order Form
- HIPAA BAA (Part 2 / CMIA schedule where needed)
- DPA framework
- Terms of Service + Privacy Policy
- Vendor-stack compliance gap memo
- Workroom delivery, up to three revision rounds
- Startup HIPAA Security Rule oriented risk note (not an audit-grade SRA)
- AI-use / model-input addendum
- No-training terms on your inputs
- AI vendor / subprocessor terms
- AI output and reliance limits
- Human-review terms
- AI / PHI data-flow map
- AI-specific risk notes
- IME, life-care-planning, and medical-cost-projection drafting
- Claims / expert-review and litigation-support workflows
- Report ownership terms
- Retention / deletion terms
- Legal-process handling
- Onboarding structure
A full HIPAA Security Rule risk analysis (the audit-grade assessment under 45 CFR 164.308(a)(1)(ii)), a technical security audit, SOC 2 readiness, a penetration test, a forensic assessment, certification, audit-defense, or enterprise AI governance are quoted as their own engagements. The core package includes a practical compliance gap memo and a startup HIPAA Security Rule oriented risk note, but not an audit-grade SRA. I confirm what folds into the flat fee, in writing, before you pay.
Each tier is a flat or quoted fee agreed before work starts. Prefer a written opinion first? The $240 Written Attorney Consultation is the lower-friction entry point.
Ask my AI Legal Analyst about your healthcare SaaS legal stack?
Tap a question for an instant, free answer (no email needed), or describe your product and the analyst routes you to the right next step. Answers draw on the HIPAA, BAA, DPA, FDA SaMD, and 50-state privacy material on this page.
Common healthcare SaaS questions, always free
Healthcare SaaS Legal Stack Scoper8 quick questions, then a likely document + review list. Informational, not legal advice.
Informational only, fictional scoping logic, not legal advice and not a scope of representation. A real matter is confirmed in writing.
Healthcare SaaS, HIPAA and Health-Data Resource Center
Everything below is free reference: what the stack requires, healthcare AI and PHI risk, the 50-state privacy landscape, document generators, calculators, and a glossary. The commercial offer is above; the deep reference is here.
What a healthcare SaaS legal stack actually requires
Every section on this page is folded. Open only what you need. The short version is below; the detail is one click away.
Short answer
If your software creates, receives, maintains, or transmits protected health information (PHI) for a covered entity, HIPAA treats you as a business associate and a signed Business Associate Agreement is mandatory before you touch patient data. HIPAA is the federal floor, not the ceiling: state laws such as California's CMIA and Washington's My Health My Data Act can reach health data and companies HIPAA never touches. A complete healthcare SaaS legal stack is usually six documents: an MSA with order form, a HIPAA BAA, Terms of Service, a Privacy Policy, a DPA framework, and a vendor-stack compliance gap memo. I am Sergei Tokmakov, a California attorney (CA Bar #279869). I draft that full stack as a $2,500 flat-fee package, or a standalone BAA at $575.
🩺 The 60-second overviewWhy HIPAA is the floor, not the ceiling, and what documents follow from that ▾
If your platform creates, receives, maintains, or transmits protected health information (PHI) for a covered entity, HIPAA pulls you in as a business associate and a Business Associate Agreement (BAA) becomes mandatory. But HIPAA is a federal floor. State medical-privacy and consumer-health-data laws layer on top, and several do not care whether you signed a BAA.
Who this page is for
- Digital health and telehealth startups preparing to sign their first hospital or clinic customer.
- Healthcare AI companies that need to position their product relative to FDA software-as-a-medical-device rules.
- Behavioral-health and substance-use-disorder platforms that also touch 42 CFR Part 2 data.
- Founders selling nationally who need to know which states reach beyond HIPAA.
Healthcare AI, PHI, and model-input risk
If your SaaS uses AI to summarize medical records, generate reports, support physician review, assist with claims or IME workflows, draft life-care plans, estimate future medical costs, triage users, or analyze patient or claimant data, the legal stack has to do more than a generic BAA. It has to map the data flow and the responsibility for the model.
🤖 AI use case → main legal risk → contract or policy responseThe six patterns I see most in healthcare and medico-legal AI products ▾
| AI use case | Main legal risk | Contract / policy response |
|---|---|---|
| Medical record summarization | PHI disclosure, hallucination, audit trail | BAA, AI addendum, output-reliance limits, human review |
| Life care planning / medical cost projection | Expert-report accuracy, litigation reliance | MSA, Order Form, medico-legal AI addendum, report ownership, review process |
| IME / claims / expert review | Not ordinary treatment, litigation-purpose limits, retention / subpoena | Role-specific MSA, BAA/DPA analysis, retention / deletion, confidentiality |
| Clinical decision support / predictive scoring | FDA / ONC predictive DSI / Section 1557 flags | Regulatory issue-spotting memo, human-in-the-loop terms |
| AI chatbot / intake assistant | Unauthorized advice, privacy, reliance | ToS, chatbot disclaimer, scope limits, escalation |
| Third-party AI model / API processing PHI | Unauthorized disclosure, training, subprocessor chain | BAA / subprocessor terms, no-training clause, deletion, audit / security terms |
🔐 Does an AI vendor need a BAA, and can it train on your inputs?Business-associate status, no-view encryption, and no-training terms ▾
Under 45 CFR 160.103, a person or company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a business associate, and the definition expressly reaches a subcontractor that does the same on behalf of a business associate. So an AI vendor or model API that processes PHI in your workflow can be a business associate or a subcontractor in your chain, which generally means a BAA is required. Whether a specific data flow is PHI, and which party a given AI vendor is acting for, depends on your facts.
Training is a separate contractual question from status. Whether an AI vendor may use your inputs to train a general model is controlled by the terms you negotiate, so the AI addendum in the extension is where no-training, deletion, and subprocessor terms get written. See the HIPAA BAA generator for a starting BAA draft and does HIPAA apply to my startup for the threshold question.
Medico-legal, IME, life-care-planning, and medical-cost-projection platforms
Not every physician workflow is treatment. Some platforms support physicians acting as independent medical examiners, expert reviewers, life-care planners, medical-cost-projection reviewers, claims consultants, or litigation-support professionals, and that does not make the data low-risk.
⚖️ Workflow → usual risk → drafting implicationTreating-provider SaaS versus IME, LCP, MCP, and AI-on-records platforms ▾
| Workflow | Usual risk | Drafting implication |
|---|---|---|
| Treating-provider SaaS | Ordinary PHI handling for a covered entity; BAA territory | Vendor-side BAA, safeguards, breach reporting, subprocessor flow-down |
| IME / expert review | Litigation purpose, not treatment; records often from a covered entity or counsel; subpoena and retention exposure | Role-specific MSA, per-stream BAA/DPA analysis, confidentiality, retention / deletion, legal-process handling |
| Life care planning | Expert-report accuracy and reliance in litigation; report ownership disputes | Report-ownership terms, review process, reliance limits, medico-legal addendum |
| Medical cost projection | Projection accuracy relied on in claims and litigation; source-data provenance | Reliance and disclaimer terms, data-source terms, review workflow, retention |
| AI analysis on health records | PHI disclosure to the model, training, hallucination, subprocessor chain | AI / PHI data-flow map, no-training clause, human review, output-reliance limits, deletion |
Related reading: my independent medical exam claims analysis and the healthcare SaaS terms scanner.
The healthcare SaaS regulatory landscape
Four overlapping regimes touch most healthcare SaaS products. Open each for the operative rule.
📋 HIPAA (federal floor)Privacy Rule, Security Rule, Breach Notification Rule, and business-associate liability ▾
HIPAA applies to covered entities and to business associates that handle PHI on their behalf. Since the HITECH amendments, business associates (including SaaS vendors) are directly liable to the HHS Office for Civil Rights, not just contractually liable to their customer.
- Privacy Rule: limits use and disclosure of PHI; requires minimum-necessary practices.
- Security Rule: administrative, physical, and technical safeguards for electronic PHI.
- Breach Notification Rule: notice obligations triggered by an impermissible use or disclosure (see the breach timeline section).
🏛️ State medical-privacy and consumer-health-data lawsCMIA, MHMDA, CTDPA health amendments, and the data-level-exemption trap ▾
This is where most national products get surprised. Some states regulate consumer health data that HIPAA never reaches, and some comprehensive privacy laws exempt PHI but not the company. The full 50-state map is below.
- California CMIA can be stricter than HIPAA and carries a private right of action.
- Washington My Health My Data Act reaches consumer health data outside HIPAA, with a private right of action via the Consumer Protection Act.
- Oregon, Maryland, New Jersey, Delaware use data-level (not entity-level) HIPAA exemptions, so being a business associate does not exempt your organization.
🤖 FDA software as a medical device (SaMD)When AI clinical software crosses into FDA-regulated territory ▾
If your software provides patient-specific information used to drive a clinical decision, the FDA may regulate it as Software as a Medical Device. A narrow Clinical Decision Support exemption can apply where the basis for a recommendation is transparent enough that a clinician can independently review it. The screening tree is below.
Open the FDA SaMD screening tool →🌍 GDPR / UK GDPR and the DPA layerWhen non-PHI personal data pulls in a separate data-processing regime ▾
A HIPAA BAA does not satisfy GDPR, and a GDPR-style DPA does not satisfy HIPAA. If you process personal data of EU or UK residents, or non-PHI data subject to US state laws like CCPA/CPRA, you generally need a separate Data Processing Agreement alongside the BAA.
See the BAA vs DPA comparison →Document generators
Free starting drafts. The flagship package is where I tailor and connect these into a coherent, attorney-drafted stack.
🧰 Open the generator libraryHIPAA BAA, healthcare NDAs, SaaS terms, privacy policies, and more ▾
How healthcare SaaS documents fit together
Six layers, each doing a distinct job. Open for the stack diagram.
🧱 The six-layer document stackFrom the master agreement down to the compliance gap memo ▾
BAA vs DPA: when you need which (or both)
A frequent and expensive confusion. They cover different data under different laws.
⚖️ Side-by-side comparisonDifferent regulators, different data, often both required ▾
| Dimension | HIPAA BAA | Data Processing Agreement |
|---|---|---|
| Governing law | HIPAA / HITECH (US) | GDPR Art. 28, UK GDPR, CCPA/CPRA |
| Data covered | Protected health information (PHI) | Personal data generally (analytics, marketing, HR) |
| Triggered by | Handling PHI for a covered entity | Processing personal data of EU/UK or in-scope state residents |
| Breach clock | 60 days from discovery (HIPAA) | 72 hours to supervisory authority (GDPR) |
| Satisfies the other? | No, a BAA does not satisfy GDPR | No, a DPA does not satisfy HIPAA |
HIPAA breach penalty calculator
A rough exposure estimate using the current per-violation tiers. Open to run it.
🧮 Estimate potential HIPAA penalty exposureRecords affected × culpability tier, with annual cap context ▾
HIPAA compliance checklist for SaaS
A working checklist. Progress is saved in your browser for this session.
📑 Open the compliance checklistAdministrative, technical, and contractual safeguards ▾
Contractual
Administrative
Technical
0 of 9 complete
HIPAA breach notification timeline
The clock runs from discovery, not from when you finish investigating. Open the timeline.
⏱️ The notification clock, step by stepBusiness-associate, covered-entity, HHS, and media tracks ▾
Is your AI product a medical device?
A quick screen, not a regulatory determination. Open to step through it.
🔬 FDA SaMD screening questionsDoes the software drive a clinical decision, and can a clinician review the basis? ▾
State health-privacy laws beyond HIPAA
HIPAA is the floor. This map shows, for every state plus DC, the health-privacy posture and what it implies for your documents. Color-coded by tier: red/amber for special health-data regimes, blue for comprehensive privacy laws, green for HIPAA-plus-baseline.
🎯 Pick a state to see what it implicatesSelect a state for its tier, the governing law, and which package documents it affects ▾
🗺️ Open the full 50-state + DC tableSearchable and filterable by tier; one-line implication per state ▾
| State | Governing law / posture | What it implies for your stack |
|---|
Must-flag states: the ones that change the stack
Five states (plus two structural traps) most often force extra documents or schedules. Each is folded.
🐻 California: CMIA + CCPA/CPRAA SaaS vendor can itself be a "provider of health care" under CMIA ▾
Under CMIA Civil Code 56.06, a SaaS vendor that maintains medical information or offers health or wellness software, mobile apps, or reproductive/sexual-health digital services can itself be deemed a "provider of health care" directly subject to the CMIA. CMIA can be more stringent than HIPAA and carries a private right of action.
🌲 Washington: My Health My Data Act (RCW 19.373)Private right of action; reaches consumer health data outside HIPAA ▾
MHMDA exempts HIPAA PHI and intermingled data held by a covered entity or business associate, but any consumer health data collected outside the HIPAA-covered stream (direct-to-consumer, app, or web data) falls squarely within it.
That triggers opt-in consent to collect, separate consent to share, valid authorization to sell, a distinct consumer-health-data privacy policy linked on the homepage, consumer access and deletion rights, and a geofencing ban, all backed by a private right of action via the Washington Consumer Protection Act.
Read the full MHMDA guide →⭐ Texas: HB 300 / Medical Records Privacy Act + SB 1188Heaviest lift: broad covered-entity reach plus US data-localization for EHRs ▾
Texas defines "covered entity" far more broadly than HIPAA, reaching any out-of-state vendor that handles PHI of Texas residents, and adds 90-day privacy training, electronic-disclosure limits, and breach notice to the Texas AG at a 250-resident threshold.
🎰 Nevada: SB 370 consumer health data (NRS 603A)Fully exempts HIPAA data, but reaches DTC and pre-relationship health data ▾
SB 370 fully exempts both HIPAA-covered entities and HIPAA PHI, so a vendor acting solely as a HIPAA business associate processing only PHI is generally exempt. But any consumer health data collected outside the HIPAA-covered relationship (direct-to-consumer app data, marketing, or pre-relationship intake) triggers SB 370.
That means a separate consumer-health-data privacy policy, prior affirmative opt-in consent to collect and (separately) to share, written authorization to sell, and a prohibition on geofencing around health-care facilities. Enforced by the Nevada AG; no private right of action.
🌳 Connecticut: CTDPA health-data amendments (PA 23-56)Consent, sale ban, and a 1,750-foot geofencing prohibition ▾
PHI handled under the BAA is exempt at the entity and data level, but any consumer health data the vendor touches outside HIPAA (behavioral-health-adjacent app data, marketing, geolocation) triggers PA 23-56: opt-in consent to process, a ban on selling consumer health data without consent, and a prohibition on geofencing within 1,750 feet of any mental-health, reproductive, or sexual-health facility.
🪤 Structural trap: data-level HIPAA exemptions (OR, MD, NJ, DE)Being a business associate does not exempt your company as an organization ▾
Three comprehensive-law states do not grant an entity-level HIPAA exemption, so being a HIPAA business associate does not exempt the SaaS as an organization. Oregon (OCPA) and Maryland (MODPA) exempt only PHI at the data level; New Jersey (NJDPA) exempts PHI at the data level and does not exempt HIPAA-regulated entities.
For all three, the MSA and privacy-policy stack must build full controller/processor obligations (including opt-in consent for health-condition/diagnosis data) on top of the BAA. Maryland goes further with a strict-necessity minimization rule and an absolute ban on selling sensitive/consumer-health data regardless of consent. Delaware (DPDPA) is the related outlier: no entity-level exemption, a 35,000-consumer threshold with no revenue floor, and coverage of nonprofits.
🧠 Structural trap: behavioral-health / SUD overlay (IL, MI, MN, NY, PA + 42 CFR Part 2)State consent rules stricter than HIPAA, layered on Part 2 ▾
For behavioral-health and substance-use-disorder customers, several states layer consent rules stricter than HIPAA on top of 42 CFR Part 2: the Michigan Mental Health Code (MCL 330.1748), the Minnesota Health Records Act (144.293, requiring signed consent even for treatment, payment, or operations), New York Mental Hygiene Law 33.13, and Pennsylvania's Act 148 (HIV), Mental Health Procedures Act, and Drug and Alcohol Abuse Control Act.
Illinois adds BIPA/GIPA private-right-of-action exposure for any biometric or genetic data. Consent flows and the BAA/MSA must permit honoring these more-stringent state authorizations.
Washington consumer-health-data library
Washington's My Health My Data Act (RCW 19.373) reaches consumer health data far beyond HIPAA, with a private right of action. These guides go deeper than the 50-state map on the issues a mental-health, behavioral-health, or AI-health SaaS hits most.
🗺️ Open the Washington MHMDA libraryMy Health My Data, HIPAA-vs-MHMDA, AI-health checklists, processor contracts, breach analysis ▾
Which documents do you need?
Four common healthcare SaaS shapes and the documents each typically needs. Open to compare.
🧩 Match your product to a document setTelehealth, analytics, behavioral-health, and wellness-app patterns ▾
- MSA + Order Form
- HIPAA BAA
- Terms of Service with clinical disclaimer
- Privacy Policy (state-specific)
- MSA + DPA framework
- HIPAA BAA + subcontractor BAAs
- De-identification terms (AB 713 where CA)
- SLA / API license
- HIPAA BAA with 42 CFR Part 2 schedule
- State mental-health consent terms
- Privacy Policy with consumer-health-data disclosures
- MHMDA / SB 370 controls where applicable
- Terms of Service
- Consumer-health-data Privacy Policy (WA, NV, CT)
- DPA for analytics vendors
- Geofencing and consent controls
7 legal mistakes healthcare SaaS startups make
The recurring, expensive ones. Open the list.
🚩 The seven most common mistakesFrom "encryption means no BAA" to "a BAA covers GDPR" ▾
90-day legal launch roadmap
A practical order of operations for a pre-launch healthcare SaaS. Open the phases.
🗓️ Pre-launch, launch, and post-launch phasesWhat to do before the first hospital signature, and after ▾
Real enforcement against tech vendors
Regulators have pursued technology vendors, not just hospitals. Open for representative actions.
⚖️ Representative enforcement themesTracking pixels, business-associate failures, and consumer-health-data actions ▾
Healthcare SaaS legal glossary
Tap a card to flip it for the definition. Open the deck.
🔖 Flip-card glossaryPHI, BAA, DPA, SaMD, CMIA, MHMDA, and more ▾
How my pricing compares
A flat fee against the usual BigLaw and mid-firm ranges for the same stack. Open the table.
💲 Flat fee vs hourly firm rangesSame six-document stack, very different invoices ▾
| The stack | BigLaw | Mid-firm | Terms.Law |
|---|---|---|---|
| MSA + Order Form | $6,000+ | $2,500+ | Included |
| HIPAA BAA (+ Part 2 schedule) | $4,000+ | $1,800+ | Included |
| Terms of Service + Privacy Policy | $6,000+ | $2,500+ | Included |
| DPA framework | $3,000+ | $1,500+ | Included |
| Compliance gap memo | $3,000+ | $1,200+ | Included |
| Total | $22,000+ | $9,500+ | $2,500 flat |
Ranges are illustrative of typical market pricing, not quotes from specific firms. My flat fee includes up to three rounds of revisions; overflow beyond that bills at $300 per hour.
Attorney services for healthcare SaaS
Three ways to engage, from a single-document review to ongoing counsel. Open to compare.
🤝 Compare the three engagement optionsDocument review, the flagship package, and ongoing counsel ▾
- One document reviewed
- Written risk flags
- Recommended revisions
- MSA + Order Form
- HIPAA BAA (Part 2 / CMIA schedule)
- Terms of Service + Privacy Policy
- DPA framework
- Compliance gap memo
- Private interactive workroom
- Up to three revision rounds
- Customer and vendor redlines
- Privacy and compliance questions
- Monthly check-ins
Prefer a written opinion first? The $240 Written Attorney Consultation is the lower-friction entry point.
Frequently asked questions
Each answer is folded. Open the ones you need.
❓What legal documents does a healthcare SaaS company need?▾
At minimum: Terms of Service, Privacy Policy, a HIPAA BAA, and a SaaS subscription agreement. If you integrate with hospital systems or handle PHI through APIs, you also need a DPA, an API license, and an SLA. Companies selling to enterprises typically need an MSA/SOW framework as well.
❓When is a HIPAA Business Associate Agreement required?▾
Whenever your platform creates, receives, maintains, or transmits PHI on behalf of a covered entity (hospital, clinic, insurer). That includes cloud-hosting PHI, processing claims data, or running analytics on patient records. Even storing encrypted PHI generally triggers the requirement.
❓Which states have health-privacy laws beyond HIPAA?▾
Several. Washington (MHMDA), Nevada (SB 370), and Connecticut (CTDPA health amendments) regulate consumer health data outside HIPAA. California's CMIA can be stricter than HIPAA with a private right of action. Texas adds data-localization duties. Oregon, Maryland, New Jersey, and Delaware use data-level rather than entity-level HIPAA exemptions. See the 50-state table above; the applicable laws depend on where your users are.
❓Do digital health startups need a DPA in addition to a BAA?▾
Often yes. A BAA covers HIPAA PHI; a DPA covers general personal data under GDPR, UK GDPR, and CCPA/CPRA. They are not interchangeable, and most companies operating nationally need both.
❓What does the $2,500 Healthcare SaaS Legal Package include?▾
An MSA with order form, a HIPAA BAA (with a 42 CFR Part 2 / CMIA schedule where needed), Terms of Service, a Privacy Policy, a DPA framework, and a compliance gap memo across your vendor stack, with up to three rounds of revisions included. Overflow beyond that bills at $300 per hour. Everything is delivered in a private, interactive workroom, not just Word files.
❓Is the AI Legal Analyst on this page legal advice?▾
No. It is attorney-directed AI that provides legal information, not legal advice, and using it does not create an attorney-client relationship. For advice tailored to your facts, the engagement is where that happens.
🤖Can a healthcare SaaS use AI on PHI?▾
It can, but the AI layer has to be papered. If your product creates, receives, maintains, or transmits protected health information for a covered entity, HIPAA treats you as a business associate and the same rules apply when a model touches that data. The stack needs to map the PHI flow, confirm whether each AI vendor is a business associate or a subcontractor, and set terms on training, human review, output reliance, and deletion. Whether a given data flow is PHI depends on your facts. This is the work in the Healthcare AI Extension.
🔐Does an AI vendor need a BAA?▾
Generally, if the AI vendor creates, receives, maintains, or transmits PHI on your behalf, it fits the 45 CFR 160.103 business-associate definition, which expressly reaches subcontractors, so a BAA is usually required. HHS cloud guidance is explicit that a provider holding ePHI is a business associate even if it lacks the encryption key and cannot view the data, so a no-view or encrypted-only AI vendor is not automatically exempt. Which party a vendor acts for, and whether the data is PHI, depends on the facts.
🩻Is AI clinical decision support regulated by FDA or ONC?▾
It may be, and it is a flag for attorney review rather than a settled answer. Depending on intended use, FDA Software as a Medical Device rules, ONC predictive decision-support transparency requirements, and HHS Section 1557 nondiscrimination in patient-care decision tools can each be in play, and the EU AI Act may apply to EU-facing products. Transparent support tools that a clinician can independently review sit differently from autonomous or black-box scoring. Which regime applies turns on the facts of your feature, so this is issue-spotting, not a determination.
🧠Can the model train on patient data?▾
Only if your contracts allow it, and for PHI you generally do not want it to. Training is a contractual question separate from business-associate status: whether an AI vendor may use your inputs to train a general model is governed by the terms you negotiate. The AI addendum in the extension is where no-training, use-limitation, subprocessor, and deletion terms get written so patient or claimant data is not absorbed into a general model.
📑What is the difference between a BAA, a DPA, and an AI Addendum?▾
They cover different obligations and often stack. A BAA addresses HIPAA PHI handled for a covered entity or business associate. A DPA covers general personal-data obligations under frameworks like GDPR and CCPA/CPRA for data that is not PHI, such as analytics or employee data. An AI Addendum covers the model-specific terms a BAA and DPA do not reach: no-training on inputs, output-reliance limits, human review, AI subprocessor terms, and the AI/PHI data-flow map. A national healthcare AI product often needs all three.
🛡️Is the included risk assessment a full HIPAA audit?▾
No. The core package includes a practical vendor-stack compliance gap memo and a startup HIPAA Security Rule oriented risk note, which is what most pre-launch companies need first. It is not an audit-grade HIPAA Security Rule risk analysis under 45 CFR 164.308(a)(1)(ii). A full Security Rule risk analysis, a technical security audit, SOC 2 readiness, a penetration test, forensic assessment, certification, or audit-defense are separately scoped and quoted engagements.
📞Can we jump on a quick call?▾
Not for free. I do not do free quick calls, free initial consultations, free case evaluations, free reviews of your documents or materials, discovery calls, or unpaid let's-hop-on-a-call chats, even for large or ongoing work. The fastest way to actually get me on a call is the $400 one-hour Zoom Strategy Session; for written analysis without a call, the $240 Written Attorney Consultation is the lower-cost option. Once you book, I work directly on your facts and documents. Everything else on the site is free so you can evaluate my approach first.
Build your healthcare SaaS legal stack
The flagship package gives you the full six-document stack, tailored to your product, your vendors, and the states your users live in. Flat fee, up to three revision rounds included, no surprises.
Sergei Tokmakov, Esq., CA Bar #279869. Attorney advertising. Prefer a written opinion first? The $240 Written Attorney Consultation is the lower-friction entry.
Try a HIPAA-aware contract workroom
If you are building a healthcare SaaS stack, this is how I actually deliver the BAAs and policies behind pages like this one. Change a breach-notice window or a marketing claim and watch the room flag the risk in real time: live preview with surgical yellow highlighting, click-any-clause comments, and track-changes style suggestions.
Open the live demo workroom How I build these for firms