Healthcare messaging on Orbit
If your organization handles Protected Health Information (PHI) through Orbit — appointment reminders, care-team notifications, patient follow-ups — this page explains exactly what HIPAA mode does, how the Business Associate Agreement (BAA) lifecycle works end-to-end in the dashboard, and which gates the platform enforces once you opt in. HIPAA posture on Orbit is tenant-owned: you attest that PHI is in scope, you execute the agreement, and the controls below activate for your workspace only. The platform is not HIPAA-enabled by default, and that is the right default — HIPAA applies to how your workspace handles PHI, not to accounts.
What HIPAA mode turns on
HIPAA mode is an opt-in, per-organization toggle switched by a workspace owner. Once active, these enhanced controls apply to the workspace:
- Encryption at rest for message bodies, media URLs, and metadata on top of TLS 1.2+ in transit — PHI confidentiality relies on the platform's at-rest encryption layer.
- Access controls: PHI access restricted to designated roles, with every message-content read recorded.
- Audit logging: every PHI access event is logged with reason codes into the workspace's audit chain.
- Data retention: automatic deletion of PHI after the retention period you configure.
- BAA tracking: the platform records the Business Associate Agreement status that backs these controls.
Enabling HIPAA mode requires an executed BAA on file — the toggle returns a 403 until the agreement is signed, so a workspace cannot flip the posture on without the legal instrument.
The BAA lifecycle, self-serve in the dashboard
The complete agreement lifecycle runs in the dashboard under Settings → Compliance → BAA — no email thread, no waiting on a sales or legal queue:
- Attest PHI scope — the workspace declares PHI is in scope. That attestation opens the execute step and is itself a recorded audit event.
- Preview the template — read the finalized agreement text rendered with your organization's legal name before signing.
- Execute with a type-the-name e-signature — the signer re-types their legal name to bind the agreement; execution is owner-only because it binds the organization.
- Download the executed copy — fetch the executed agreement for your records, a customer audit, or a regulator via a fresh download URL.
- Re-execute before expiry — executed agreements carry a one-year term. A re-execute banner surfaces 60 days before expiry and the same owner flow renews it.
- Revert when PHI leaves scope — an owner can remove the on-file agreement after HIPAA mode is disabled; the audit history and executed document are preserved.
The same lifecycle is available over the API for teams that prefer scripting: preview the template, attest scope, execute, download, and revert under /api/v1/compliance/baa.
PHI-audience registry
HIPAA apply-to-use means identifying which contact audiences carry PHI. Orbit keeps a per-organization registry of PHI-adjacent audience ids — lists and segments you designate as PHI-bearing — over /api/v1/compliance/hipaa/phi-audiences. The registry is the workspace's own register; you list the designated ids, replace the set as audiences change, and the designation itself attests that members carry PHI. Send gates (below) treat traffic to designated audiences accordingly.
Send-time gates
Once a workspace attests PHI is in scope, outbound sends that touch PHI are gated until an in-term BAA is on file — attempts before execution are rejected with a 422 HIPAA_BAA_REQUIRED verdict (with a reason of pending or expired), and an invalid agreement surfaces 422 HIPAA_BAA_INVALID. An executed, in-term BAA removes the rejection. If the one-year term lapses, the verdict closes again until the workspace re-executes.
These are tenant controls, not platform mandates: they enforce the posture you attested, and they fail closed in your favor, not as a platform-wide block on outbound.
A tenant-owned posture, by design
Orbit's HIPAA posture is deliberately opt-in. Executing the BAA records the platform's obligations to you as a business associate — it does not by itself enable HIPAA mode, does not determine that your processing is lawful, and does not replace your own HIPAA program. Designating PHI audiences, setting retention windows, and deciding PHI is in scope all remain decisions your compliance team owns; the platform supplies the e-sign pipeline, the audit chain, the registry, and the gates to make those decisions durable.
Where to go next
- Security page — the platform-wide encryption, tenant isolation, and operational posture the HIPAA controls sit on.
- Trust Center — data residency, subprocessor list, and downloadable agreements.
- Data Processing Agreement — the GDPR-side processing terms; the BAA is the HIPAA-side instrument.
Questions about the BAA or HIPAA onboarding: compliance@devotel.io.
Evaluating Orbit for healthcare?
If your procurement review needs a signed DPA, a BAA under NDA discussion, or a security questionnaire response, talk to us about enterprise terms.