Business Associate Agreement (BAA)
Last updated: April 29, 2026
1. Purpose
This page describes the Business Associate Agreement (BAA) framework for customers using bldrAgent in HIPAA-regulated workflows. If your organization is a Covered Entity or Business Associate and your project handles Protected Health Information (PHI), a BAA is required before production use.
This public page is a summary for operational guidance. Your executed legal agreement, if any, governs in the event of conflict.
2. When a BAA applies
A BAA generally applies when all of the following are true:
- You are subject to HIPAA as a Covered Entity or Business Associate.
- Your bldrAgent project creates, receives, stores, or transmits PHI.
- bldrAgent provides services involving PHI on your behalf.
3. HIPAA mode and BAA acknowledgement
During project creation, users can enable HIPAA Compliance Mode and acknowledge BAA terms. This acknowledgement is recorded as part of project compliance metadata.
HIPAA mode availability is plan-gated. If your current plan does not include HIPAA mode, the toggle is disabled and you must upgrade before enabling HIPAA controls.
4. Core BAA commitments
Executed BAAs typically address the following obligations:
- Permitted and required uses/disclosures of PHI.
- Safeguards for confidentiality, integrity, and availability of PHI.
- Subcontractor flow-down obligations where applicable.
- Security incident and breach notification requirements.
- Access, amendment, and accounting support as required by law.
- Return or destruction of PHI at termination, where feasible.
5. Shared responsibility model
Compliance is shared between platform controls and your organization's operational policies.
- bldrAgent responsibilities: Platform-level safeguards, HIPAA mode controls, and compliance-aware operational governance.
- Customer responsibilities: Role design, workforce training, minimum-necessary access, policy enforcement, and lawful use of integrations.
6. Requesting or reviewing BAA terms
For BAA review, execution status, or legal questions, contact legal@bldragent.com.
For platform security details, see Privacy Policy. For operational setup guidance, see the HIPAA documentation in the resources center.
7. No legal advice
Nothing on this page is legal advice. You should consult your legal counsel to evaluate your HIPAA obligations and confirm whether your implementation meets all applicable regulatory requirements.
8. Contact
Questions about this BAA summary or related terms:
bldrAgent Legal
Email: legal@bldragent.com
