Has anyone here been asked about Business Associat...
# general
s
Has anyone here been asked about Business Associate Agreement (BAA) and HIPAA compliance even though you SaaS does not directly handle Protected Health Information (PHI) data? If so, how did you handle these scenarios? Thanks!
m
Depends on byoc or saas. Byoc the answer is “it’s your walls, we don’t see your data.” For saas I normally say something like: it’s up to you what data you put in, we are not hipaa complaint. But if you encrypt your data before sending to us it may work. Let’s talk to your complacence folks and get their input
🙏 1
s
I am asking specifically from a SaaS perspective. If they go the self-hosted route, everything is in their control anyhow.