HIPAA Compliance

HIPAA Business Associate Agreement

How DocsMD™ operates as a HIPAA Business Associate to contracted healthcare practices, including our standard BAA structure.

EFFECTIVE MARCH 27, 2026 · LAST UPDATED MARCH 27, 2026

About this page: This page describes DocsMD™'s HIPAA Business Associate practices and provides access to our standard Business Associate Agreement template. A signed BAA is required before DocsMD accesses, processes, or stores any Protected Health Information ("PHI") on behalf of a healthcare practice.

What is a Business Associate Agreement?

Under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and implementing regulations at 45 C.F.R. Parts 160 and 164, a healthcare practice ("Covered Entity") that engages a third-party service provider to perform functions involving Protected Health Information must enter into a written Business Associate Agreement with that service provider ("Business Associate"). The BAA is a legally required contract that ensures the Business Associate will safeguard PHI in accordance with HIPAA.

DocsMD operates as a HIPAA Business Associate to every contracted healthcare practice. We execute a BAA with each Practice before any PHI is transmitted, accessed, or stored.

DocsMD's HIPAA Commitments

As a Business Associate, DocsMD agrees to:

Subprocessor Business Associate Agreements

DocsMD has executed Business Associate Agreements with all subprocessors that handle PHI:

SubprocessorFunctionBAA Status
Airtable, Inc.Database / data storeBAA executed (Business plan)
Make.com (Celonis)Workflow automationBAA executed (Team plan)
Twilio Inc.SMS / telephonyHIPAA-eligible configuration; BAA via Twilio HIPAA program
Anthropic, PBCAI / LLM processingPer Anthropic enterprise terms; PHI minimized in prompts

Standard BAA Template

DocsMD's standard Business Associate Agreement covers the following provisions in alignment with 45 C.F.R. § 164.504(e):

  1. Permitted Uses and Disclosures of PHI
  2. Obligations and Activities of Business Associate
  3. Safeguards (Administrative, Physical, Technical)
  4. Reporting of Breaches and Security Incidents
  5. Subcontractor Obligations
  6. Access, Amendment, and Accounting of PHI
  7. HHS Audit Cooperation
  8. Term and Termination
  9. Return or Destruction of PHI Upon Termination
  10. Indemnification and Liability
  11. Governing Law (Arizona)
  12. Survival of Obligations

Request the BAA: Practices ready to engage DocsMD will receive the standard BAA via DocuSign as part of onboarding. To request a copy in advance for legal review, contact hello@docsmd.com.

Patient Rights Under HIPAA

Patients have the following rights with respect to their PHI:

To exercise these rights, contact your healthcare practice directly. DocsMD processes PHI only at the direction of and on behalf of the practice.

Reporting a Privacy Concern

If you believe your privacy rights have been violated, you may file a complaint with:

You will not be retaliated against for filing a complaint.

Contact

DocsMD™ HIPAA Compliance
DocsMD LLC
HIPAA Privacy Officer
24871 S Ellsworth Rd, Suite 100-170
Queen Creek, Arizona 85142, USA
Email: hello@docsmd.com