HIPAA Compliance Posture
Clear statement regarding healthcare data protection and Business Associate status. • Notice: Standard compliance disclosure. Must be reviewed by qualified legal counsel.
1. Designed With HIPAA Requirements in Mind
The Health Insurance Portability and Accountability Act (HIPAA) sets federal standards in the United States for the protection of individually identifiable health information. GetIntakes is architected with technical, physical, and administrative safeguards designed to assist our healthcare practice clients in meeting their obligations under the HIPAA Security and Privacy Rules.
2. Business Associate Agreement (BAA) Availability
When GetIntakes processes Protected Health Information (PHI) for or on behalf of a Covered Entity healthcare client, we act in the capacity of a Business Associate. We provide and execute a standard Business Associate Agreement (BAA) with healthcare provider accounts upon request. The BAA defines the permitted uses and disclosures of PHI, breach notification procedures, and mutual safeguarding responsibilities.
3. Technical Safeguards Implemented
- Data Encryption: End-to-end transport layer security (TLS 1.3) across all intake and API endpoints, and AES-256 encryption for data at rest.
- Access Controls & Authentication: Role-based access control, unique user credentials, and session timeout parameters.
- Audit Logging: System event logging tracking administrative access and intake status transitions.
- Zero Model Training: Configured to ensure client patient data is not used for training foundation AI models.
4. Important Clinical Practice Note
GetIntakes is an administrative intake, scheduling, and routing technology. It is not an Electronic Health Record (EHR) system of record, nor a diagnostic medical device. Healthcare practices maintain full professional responsibility for clinical review, informed consent, and medical record retention in their primary EMR.
5. How to Request a BAA
To request our standard BAA for your practice or to submit your organization's custom vendor BAA for review, please contact our compliance desk:
