HIPAA and the BAA: what every practice should verify
A signed Business Associate Agreement is the baseline for handling PHI. Here is what a BAA covers, why tier-gating it is a red flag, and what to check before you sign.
If a vendor touches your patients' protected health information, you need a signed Business Associate Agreement (BAA). It is not optional, and it is not a nice-to-have.
What a BAA actually does
A BAA is the contract that makes a vendor legally responsible for safeguarding PHI on your behalf. It defines permitted uses, breach-notification duties, and the security standards the vendor must meet. Without one, storing PHI with that vendor is a compliance violation, regardless of how secure the product feels.
The tier-gating red flag
Some form builders put HIPAA compliance and the BAA behind their higher-priced plans. That means their lower tiers explicitly cannot be used for PHI, and compliance becomes a surprise cost as you scale. Compliance should not be a feature you upgrade into.
What to verify before you sign
- BAA on every plan, not just the top tier.
- Encryption at rest and in transit (AES-256 and TLS 1.2 are the common baseline).
- HIPAA-eligible infrastructure and independent audits such as SOC 2 Type II.
- Audit logging and role-based access so you can see who touched what.
Zentake includes a signed BAA on every plan, because a compliance baseline that only some customers get is not a baseline at all.