HIPAA

Business Associate Agreement

If your organization is a HIPAA Covered Entity and ATTENDING AI will create, receive, maintain, or transmit protected health information on your behalf, we need an executed Business Associate Agreement in place before any PHI touches the system. We treat this as a precondition of a pilot, not paperwork to catch up on later.

We will sign yours or provide ours. If your compliance team has standard BAA paper, send it — that is usually the fastest path. If you'd rather start from ours, ask and we'll send it over.

Request a BAA

What our BAA covers

Subprocessors that may handle PHI

We will disclose the current, specific list during BAA negotiation. Categories:

CategoryPurposeStatus
Cloud infrastructure and database hostingRunning the application and storing recordsBAA required before production use
AI model providersClinical language understanding and reasoning supportBAA required before production use
Error monitoring and observabilityFault diagnosis; configured to mask PHIBAA required where PHI could be incidentally captured

We will give you advance notice before adding a subprocessor that handles PHI, and you may object.

What to send us

Security documentation

Provider organizations commonly ask for our security posture alongside the BAA. We can share our information security policy, access control policy, risk assessment, incident response plan, and business continuity plan under NDA. Ask when you request the BAA and we'll send the package together.


Request a BAA

HIPAA Compliance · Privacy Policy · Terms of Service