Business Associate Agreement
A contract boundary, not a compliance badge.
The applicable ApprovalHelp BAA defines permitted uses, safeguards, incident duties, subcontractors, return or destruction, and termination. It is paired with a service inventory: an executed vendor BAA does not make every service from that vendor eligible for PHI.
Before PHI is entered
The practice accepts the current product terms and privacy notice, completes the applicable services and BAA flow, identifies authorized users and roles, configures mandatory MFA, and confirms its intended integrations and data flows.
For negotiated agreements
Enterprise customers can review a customer paper BAA or negotiated addendum. Scope, order of precedence, covered services, incident contacts, subcontractor notice, termination, export, and retention are resolved in the signed agreement.
Recorded executed-BAA services
The registry records contract evidence internally. Only the reviewed purposes and approved data classes below are eligible; current configuration must still be verified.
Amazon Web Services
Textract OCR, encrypted S3 backups, Lightsail TLS gateway
Approved data: public, internal, pii, phi, deidentified
Paubox Email API
transactional email
Approved data: public, internal, pii, phi, deidentified
Google Workspace
operator mailbox, administrative notifications
Approved data: public, internal, pii, phi, deidentified
Restricted and non-PHI services
Claude subscription CLI
No executed BAA is asserted; runtime must de-identify and pass the outbound leakage gate
Anthropic API
No executed BAA is asserted for this route; production PHI is blocked
Stripe
Application policy forbids diagnoses, patient names, member IDs, treatments, and other PHI in Stripe
Cloudflare DNS
Proxy is disabled for the healthcare hosts; DNS records only
Sentry
sentry.*.config.ts and lib/sentry-scrub.ts enforce the non-PHI boundary
Telegram Bot API
Alert policy permits only aggregate enums and counts; case IDs, source text, and clinical content are prohibited
Stedi Healthcare Eligibility
01-baa-emails.md — execution and eligible-service evidence not yet recorded; PHI egress is blocked
Google Analytics / PostHog
lib/analytics-gate.ts denies PHI-bearing routes; URLs and identifiers must not cross the boundary
Request the agreement or security review
Do not send patient information. Use the monitored contact channel and identify your organization, intended workflow, and contract contact.
Contact ApprovalHelp →