> ## Documentation Index
> Fetch the complete documentation index at: https://docs.revdesk.com/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA Business Associate Agreement

> Business Associate Agreement for healthcare organizations. Handle protected health information compliantly.

For healthcare organizations handling Protected Health Information (PHI), RevDesk offers a Business Associate Agreement for HIPAA workloads.

***

## What it does

* **Legal coverage** - BAA establishes compliant data handling
* **PHI protection** - Appropriate safeguards for health information
* **Audit support** - Documentation for compliance audits
* **Peace of mind** - Clear responsibilities and protections

***

## Who needs this

A BAA is required if you:

* **Are a healthcare provider** - Doctors, dentists, therapists, clinics
* **Handle PHI** - Patient names, conditions, appointments
* **Transmit health info** - Via calls, texts, or emails
* **Are a business associate** - Handle PHI for covered entities

***

## What's covered

The BAA covers RevDesk's handling of:

| Data type | Examples |
| - | - |
| Patient identifiers | Names, phone numbers, addresses |
| Health information | Conditions mentioned in calls |
| Appointment data | Medical appointments, providers |
| Communication records | Call transcripts, voicemails |

***

## How to get a BAA

<Steps>
  <Step title="Email support">
    Email [support@revdesk.com](mailto:support@revdesk.com) with subject "HIPAA BAA Request". Include your legal entity name, the workspace
    that will handle PHI, and a primary compliance contact.
  </Step>

  <Step title="Verify eligibility">Confirm you're a covered entity or business associate</Step>

  <Step title="Review agreement">
    We send our standard BAA within 2 business days. Customers who can sign as-is get same-day activation;
    legal markup typically closes in 5–10 business days.
  </Step>

  <Step title="Execute agreement">Sign electronically and receive countersigned copy</Step>

  <Step title="Enable HIPAA mode">
    We record `baaSignedAt` on your workspace and flip `hipaa_enabled = true`. Runtime controls activate
    immediately.
  </Step>
</Steps>

***

## HIPAA mode features

When BAA is active, RevDesk enables:

* **BAA-eligible voice routing** - AI voice runs only on BAA-eligible providers
* **Webhook redaction** - Recordings and transcripts are stripped from outbound webhooks
* **API redaction** - Recordings and transcripts are stripped from the public API

***

## Compliance responsibilities

### RevDesk responsibilities

* Secure data storage and transmission
* Access controls and authentication
* Breach notification
* Subcontractor agreements

### Your responsibilities

* Authorized use of RevDesk
* User access management
* Minimum necessary data sharing
* Patient authorization when required

***

## Pricing

BAA terms, including any cost, are confirmed when you request the agreement.

### Platform-wide HIPAA for channel partners

If you're a partner placing healthcare customers on RevDesk at consistent volume, we offer a **platform-wide HIPAA posture**. [Contact sales](https://cal.com/revdesk/30min) for pricing. Your accounts become HIPAA-compatible by default, and we sign BAAs with your downstream customers individually as they need them.

***

## Requirements

* An active RevDesk plan
* Signed BAA before handling PHI
* HIPAA training for your staff
* Compliance policies in place

***

## FAQ

<AccordionGroup>
  <Accordion title="Do I need a BAA for non-healthcare use?">
    No. BAAs are only required when handling PHI. General business use doesn't require one.
  </Accordion>

  <Accordion title="Can I use RevDesk for patient reminders?">
    Yes, with an active BAA. RevDesk can send appointment reminders that include patient information.
  </Accordion>

  <Accordion title="What if there's a breach?">
    RevDesk will notify you within 24 hours of discovering any potential breach, as required by the BAA.
  </Accordion>

  <Accordion title="Does this cover telehealth?">
    The BAA covers call handling and scheduling. For video visits, ensure your telehealth platform is also
    compliant.
  </Accordion>
</AccordionGroup>

***

<Card title="Request BAA" icon="shield-halved" href="mailto:support@revdesk.com?subject=HIPAA%20BAA%20Request">
  Email [support@revdesk.com](mailto:support@revdesk.com) to get started
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.