Business Associate Agreements
A Business Associate Agreement (BAA) is required before certain vendors handle protected health information (PHI). Workforce AI is HIPAA compliant and signs BAAs with customers who need one.
Business Associate Agreements
A BAA may be required before a vendor handles PHI. Workforce AI is HIPAA compliant and signs BAAs with customers who need one.
This page is general information about BAAs, not a signed agreement. Workforce AI is HIPAA compliant, and customers on an eligible plan can request a BAA.
1. What a BAA is
A BAA is a written contract between a HIPAA covered entity or business associate and a vendor that will create, receive, maintain, or transmit PHI on its behalf. It defines permitted use, safeguards, reporting, subcontractors, and what happens to PHI when service ends.
2. Current Workforce AI status
Workforce AI is HIPAA compliant. Customers on an eligible plan can request a BAA before PHI is handled in meetings, email, chat, SMS, WhatsApp, integrations, uploads, prompts, or support requests.
3. Security review
Our security program covers every feature, model provider, integration, support path, log, backup, storage location, and sub-processor in scope. See our HIPAA information and security page.
4. Legal review
The BAA confirms the parties, permitted uses, breach-notification duties, subcontractor terms, data return or destruction, and any state-law requirements. The final signed contract, not website copy, controls.
5. Subprocessors
Every provider in the PHI data path is reviewed for eligibility and covered by the required agreement. Our providers are listed on the sub-processors page.
6. Product activation
On a HIPAA-eligible deployment, we activate the approved workspace, workflows, providers, retention settings, support path, and access controls that a BAA requires.
7. Customer responsibilities
On a HIPAA-eligible deployment, you remain responsible for appropriate access, authorizations, configuration, workforce practices, and use within the approved scope and signed agreement.
8. Ongoing review
We review and revalidate the deployment after material changes to features, providers, data paths, or agreements.
Request a BAA
Email privacy@hireworkforce.ai or contact us with the workflows and systems you need covered. Customers on an eligible plan can request a BAA, and you can review our program at the Workforce AI Trust Center.
This is general information about BAAs. Workforce AI is HIPAA compliant and signs a BAA with customers who need one.
1. What a BAA is
A BAA is a written contract covering permitted PHI use, safeguards, reporting, subcontractors, and data return or destruction.
2. Current status
Workforce AI is HIPAA compliant. Customers on an eligible plan can request a BAA before PHI is handled in meetings, messages, integrations, uploads, prompts, or support.
3. Security review
Our security program covers every feature, provider, integration, log, backup, support path, and storage location in scope. See our HIPAA information.
4. Legal review
The BAA sets the parties, scope, incident duties, subcontractors, and data disposition. The signed contract controls.
5. Subprocessors
Each provider in the PHI data path is eligible and covered by the required agreement.
6. Product activation
We activate the approved workspace, scope, and provider path that a BAA requires.
7. Customer responsibilities
Customers remain responsible for appropriate access, authorization, configuration, and use within the approved scope.
8. Ongoing review
We review the deployment after material product, provider, or data-path changes.
Request a BAA
Email privacy@hireworkforce.ai or contact us to request a BAA. Review our program at the Workforce AI Trust Center.
Talk to a real person.
We will set up a BAA where you need one.