Skip to main content

HIPAA Business Associate Agreement (BAA)

If your organization is a HIPAA-covered entity or business associate that processes Protected Health Information (PHI), you must accept DocuTrust’s Business Associate Agreement before using the platform to handle PHI. The BAA establishes the responsibilities of both parties for safeguarding PHI.

When Is a BAA Required?

A BAA is required when you use DocuTrust to:
  • Collect signatures on documents containing patient health information
  • Store documents that include diagnoses, treatment plans, or medical records
  • Process forms that contain health insurance information
  • Send documents to patients or healthcare providers that reference PHI
If your documents do not contain PHI, a BAA is not required but can still be accepted as a precautionary measure.

Check BAA Status

Query whether a BAA has been accepted for the current account.
Response 200 OK (BAA accepted)
Response 200 OK (BAA not accepted)

Accept the BAA

Accept the current version of the Business Associate Agreement. Only account administrators can accept the BAA.
Request Body Response 200 OK
Accepting a new BAA version automatically supersedes any previously accepted version. Only one BAA version can be active at a time.

Revoke the BAA

Revoke the currently accepted BAA. This should only be done if your organization no longer processes PHI through DocuTrust.
Response 200 OK
Revoking the BAA does not delete any existing documents or data. However, your organization assumes full responsibility for PHI compliance once the BAA is no longer in effect.

What the BAA Covers

DocuTrust’s BAA establishes obligations for:

Error Responses