Business Associate Agreement (BAA)
Summary for US covered entities and business associates that use PsycSuit to create, receive, maintain, or transmit protected health information (PHI).
Not a substitute for counsel. This page explains our standard BAA topics in plain language. Your practice receives the executed BAA (PDF or e-sign) during onboarding before production PHI use.
Last updated: May 2026
Parties & purpose
When your practice is a HIPAA covered entity (or another business associate acting on behalf of a covered entity), PsycSuit acts as your business associate for PHI processed in the service. The BAA supplements your Terms of Service.
Permitted uses
- Process PHI only to provide the subscribed service and as required by law.
- Not use or disclose PHI for marketing unrelated to your instructions.
- Use subprocessors under written agreements with comparable safeguards (see Trust center).
Safeguards
We implement administrative, physical, and technical safeguards appropriate to the service, including access controls, encryption in transit, audit logging, and staff training. Details are on the Trust & security page.
Breach notification
We will notify you without unreasonable delay after discovering a breach of unsecured PHI in our systems, and provide information reasonably required for your notification obligations, consistent with HIPAA and the HITECH Act.
Access, amendment & accounting
We will make PHI available for access, amendment, and accounting of disclosures as directed by you and required by the BAA, using product tools or support processes where applicable.
Return or destruction
Upon termination, we will return or destroy PHI where feasible, except where retention is required by law or permitted by your export and backup settings.
Your practice’s duties
- Provide minimum necessary PHI to the service.
- Maintain policies, workforce training, and patient notices.
- Ensure BAAs with other vendors that handle PHI.
- Report suspected misuse or security incidents promptly.
How to obtain the BAA
Complete practice registration. After approval and account setup, PsycSuit provides the countersigned BAA for your records. Contact us if you need a copy resent.
Contact
← Plans & pricing · Trust center · BAA · DPA