We sign your BAA
same day.
No week-long contract loop. No legal back-and-forth. Request it, sign it, return it — and we're live that afternoon.
What's a Business Associate Agreement?
A Business Associate Agreement (BAA) is a legally required contract between a HIPAA Covered Entity (your practice) and a Business Associate (any vendor that handles PHI on your behalf).
The BAA puts four things in writing:
- What the vendor is allowed to do with the PHI (and nothing else).
- What safeguards the vendor must have in place.
- How the vendor must respond to a breach.
- What happens to the PHI when the relationship ends.
Every HIPAA-compliant vendor should have a standard BAA ready to sign on day one. If they don't — or if they want to rewrite the HIPAA statute in the process — that's a warning sign, not a negotiation.
Three reasons every practice needs BAAs on file.
It's a federal requirement
HIPAA requires a BAA with any vendor that handles PHI on your behalf. Without one, you're out of compliance the moment PHI changes hands.
It shifts risk appropriately
A BAA makes the vendor directly liable to HHS for breaches of PHI they handle. Without one, you're holding all of it.
Your cyber insurance will ask
Most cyber and medical-liability carriers require BAAs with every vendor touching PHI.
What our BAA covers.
Standard HIPAA language, no surprises, no traps. Our counsel is happy to walk you through anything.
Permitted Uses & Disclosures
Defines exactly what Perpetua can do with PHI — only what's needed to provide the Service, and only as you direct.
Safeguards
Commits us to administrative, physical, and technical safeguards: encryption, access control, audit logging, employee training.
Breach Notification
We notify you within 24 hours of discovering a breach — faster than HIPAA's 60-day statutory minimum.
Subcontractor Flow-Down
Every subprocessor (Supabase, Twilio, Clerk, etc.) is under a BAA or equivalent. Those obligations flow down.
PHI Return & Destruction
On termination, PHI is returned or destroyed per your instruction. Backups are purged on the standard schedule.
Audit Rights
You can audit our compliance posture on reasonable notice. Security policies and incident-response docs available under NDA.
From request to signed in hours, not weeks.
You request the BAA
Email baa@perpetuahealth.com or click the button below. Include your practice's legal name and signer info.
We send via DocuSign
Pre-filled with your entity details. Our side is already signed — you review and countersign.
You countersign
Executed copies go to both parties' records. A clean audit-ready PDF lives in your dashboard.
We go live
The moment the BAA is executed, your account is cleared to process PHI.
Quick answers.
Is there a fee for the BAA?
Can we redline your BAA?
Can we use our own BAA template?
Where can I see proof you're actually compliant?
Ready to get your BAA?
We'll have it in your inbox within the hour. Executed before your next patient checks in.