Skip to content

HIPAA Business Associate Agreement

We sign BAAs.

Keep patient documents in Ademero with the agreement HIPAA requires. Request a copy of our Business Associate Agreement to review with your team.

01What a BAA is

The contract HIPAA requires of every vendor that touches PHI.

A Business Associate Agreement (BAA) is a legally binding contract required under HIPAA. When a covered entity engages a business associate to perform functions involving the use or disclosure of protected health information (PHI), a BAA is mandatory. It sets the legal framework for handling patient data under federal privacy and security standards.

Healthcare providers, health plans and clearinghouses must have a BAA with any vendor, processor or service provider that handles PHI. The HITECH Act extended direct liability to business associates for breaches, which makes the BAA more important than ever.

Request one if you use Ademero to:

  • Store, process or transmit patient health information
  • Manage documents that contain PHI
  • Run healthcare workflows involving protected data
  • Meet HIPAA requirements for business associate relationships

02What a BAA addresses

What HIPAA expects, and the controls that help.

Our agreement sets out its own terms; request a copy to read them in full. As general background, HHS guidance describes the topics a business associate agreement covers, and our products include controls that help you protect patient documents.

Topics a BAA covers under HIPAA

  • Permitted uses and disclosures

    How the business associate may use and disclose PHI.

  • Safeguards

    That the business associate protects PHI as the HIPAA Security Rule requires.

  • Reporting

    Reporting uses or disclosures the agreement does not allow, including breaches.

  • Subcontractors

    That subcontractors who handle PHI agree to the same restrictions.

  • Individual rights

    Helping the covered entity respond to requests for access and amendment.

  • End of the relationship

    What happens to PHI when the agreement ends.

Controls in the software

  • Permissions

    Role-based access so the right people see each document.

  • Audit trail

    A record of who viewed, changed or shared each document.

  • Retention and legal holds

    Keep records for as long as your policies require.

  • Sign-in controls

    Active Directory, SAML single sign-on and authenticator-app MFA in Content Central.

The federal rules behind BAAs

03Request

Request your BAA.

By submitting this form, you agree to our Privacy Policy and Terms of Service.

04Questions

BAA basics.

When do I need a BAA?

You need a BAA with any vendor or service provider that will have access to protected health information (PHI). That includes document management systems, cloud storage, email services and any technology platform that processes healthcare data. If a vendor touches patient data in any form, a BAA is required.

Does Ademero sign BAAs?

Yes. Request a copy with the form on this page and review it with your own team and counsel.

What terms does the BAA include?

The terms are set out in the agreement itself. Request a copy to review them, and send any questions to support@ademero.com.

We need changes to the agreement. Who do we talk to?

Note them in the request form or email support@ademero.com, and we can discuss them with you.

Which Ademero products are used for patient documents?

Healthcare teams can use CapturePoint 6 to scan and read patient paperwork on their own PCs, Content Central to manage patient documents in the cloud or on their own servers, and Nucleus One for team projects, forms and client portals. Ask us which fits your setup.

05Built for healthcare documents

Software that helps you meet HIPAA.

Scanning and capture

CapturePoint 6

Cutting-edge local AI on your own PC splits, sorts, reads and names patient paperwork. Documents are processed on your PC, not in a cloud service.

Document management

Content Central

Runs in the cloud or on your own servers, your choice, with permissions on every document, a full audit trail, retention rules and legal holds.

Team projects and client portals

Nucleus One

A lighter cloud app for projects, tasks, forms, e-signatures and client portals, hosted on Google Cloud. Google holds SOC 2 and ISO 27001 certifications for its own Google Cloud infrastructure.

Fortune 500 companies and government agencies run on Ademero. Their security, IT and legal teams review us every year and keep renewing.