HIPAA & compliance

HIPAA and the BAA: what every practice should verify

A signed Business Associate Agreement is the baseline for handling PHI. Here is what a BAA covers, why tier-gating it is a red flag, and what to check before you sign.

If a vendor touches your patients' protected health information, you need a signed Business Associate Agreement (BAA). It is not optional, and it is not a nice-to-have.

What a BAA actually does

A BAA is the contract that makes a vendor legally responsible for safeguarding PHI on your behalf. It defines permitted uses, breach-notification duties, and the security standards the vendor must meet. Without one, storing PHI with that vendor is a compliance violation, regardless of how secure the product feels.

The tier-gating red flag

Some form builders put HIPAA compliance and the BAA behind their higher-priced plans. That means their lower tiers explicitly cannot be used for PHI, and compliance becomes a surprise cost as you scale. Compliance should not be a feature you upgrade into.

What to verify before you sign

  • BAA on every plan, not just the top tier.
  • Encryption at rest and in transit (AES-256 and TLS 1.2 are the common baseline).
  • HIPAA-eligible infrastructure and independent audits such as SOC 2 Type II.
  • Audit logging and role-based access so you can see who touched what.

Zentake includes a signed BAA on every plan, because a compliance baseline that only some customers get is not a baseline at all.

Start your free trial← Back to the journal