When a BAA may be needed
A BAA may be appropriate when a firm plans to submit protected health information and the parties determine that HIPAA applies to the intended service. ClaireAI does not make that determination for the firm. The firm should review its workflow and compliance requirements with qualified counsel before enabling regulated-data processing.
Ask about the applicable agreement
- Contact ClaireAI with the firm name, intended workflow, and the regulated-data question to be reviewed.
- Review the current product and security documentation as part of the sales or implementation process.
- If the parties agree a BAA or other agreement is appropriate, review and execute it before the relevant data is submitted to the Service.
- Keep the fully executed agreement with the firm's compliance records.
Author
Cal Stein
Engineering, ClaireAI
Cal works on ClaireAI's integration platform and security documentation.