Skip to main content
← Back to glossary
Compliance & consent

BAA — Business Associate Agreement

ما هو BAA?

هذا المصطلح متوفر حاليًا باللغة الإنجليزية فقط.

A Business Associate Agreement (BAA) is the contract HIPAA requires between a covered entity and any third party touching protected health information (PHI) on its behalf. For a healthcare tenant on Devotel Orbit, the executed BAA records the permitted uses of the PHI you submit, commits the platform to the safeguards the Security Rule demands, and allocates breach-notification duties. Until an executed BAA is on file, PHI stays out of scope on Orbit.

More detail

When a BAA is required — HIPAA applies when a covered entity (provider, health plan, clearinghouse) sends PHI through a vendor, or when a business associate hands that PHI to a downstream subcontractor. Appointment reminders containing a person's name, treatment context, or clinic address are PHI, so a healthcare tenant needs an executed BAA before any patient-identifying content touches the platform. If you never process PHI — no patient names, diagnoses, or appointment details in message bodies or voice content — attest 'no PHI in scope' on the Trust Center instead, and the gate lifts without a signature.

The executed / pending / expired lifecycle — an organization's BAA has a status you read from the current-BAA state endpoint: it starts as none, moves to pending once you attest PHI is in scope and request execution, and flips to executed when an org owner completes the e-sign (signer recorded against the template version, with the executed PDF downloadable for 24 hours at a time from the Trust Center). An executed BAA carries a term; once that term lapses the status rolls to expired and PHI-scope must be re-attested and re-executed. You can also revert an executed or expired BAA back to the Devotel Orbit default, and decline PHI scope entirely — both owner-gated actions, both audit-logged.

Trust Center controls — the whole lifecycle is self-serve on the Trust Center under Documentation and Legal: preview the current template, attest 'PHI in scope' to open the execution flow, execute (owner-only, type-the-name e-sign), decline scope, or download the executed copy. Every transition writes an audit event naming the actor and the template version, so your compliance file and the platform's record never drift apart. Related compliance actions — the HIPAA PHI-scope attestation and the GDPR Data Processing Agreement — live in the same Trust Center surface.

الأسئلة الشائعة

When do I need a BAA with Devotel Orbit?
As soon as any protected health information — patient names, treatment or appointment context, clinic details tied to an individual — enters your messages, voice content, or contact data. HIPAA requires the BAA to exist before the PHI flows, not after. If none of your communications contain PHI, you can attest 'no PHI in scope' on the Trust Center and operate without one.
How do I execute the BAA on Devotel Orbit?
From the Trust Center: an org owner opens the Business Associate Agreement, reviews the current template version, completes the type-the-name e-sign, and the executed PDF becomes available for download. The organization's BAA status moves from pending to executed, and every state transition is written to the audit log with the signer details.
What happens when my BAA expires, or if my scope changes?
An executed BAA has a validity term; once it lapses, the organization's status becomes expired and PHI-scope sending is no longer covered until you re-attest and execute against the current template version. If PHI drops out of scope entirely, an owner can decline; reverting returns the organization to the default non-executed state. All three transitions are recorded in the compliance audit trail.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.