HIPAA-BAA
The Business Associate Agreement required under the US Health Insurance Portability and Accountability Act. Any third party handling Protected Health Information on behalf of a HIPAA-covered entity must sign a BAA — committing to specific safeguards required under HIPAA's Security and Privacy Rules.
What HIPAA requires
HIPAA's Privacy Rule governs the use and disclosure of Protected Health Information. The Security Rule governs the safeguards required to protect electronic PHI: access controls, audit controls, integrity controls, transmission security. The Breach Notification Rule requires notification of certain breaches.
The BAA mechanism
HIPAA-covered entities (health plans, healthcare clearinghouses, most healthcare providers) cannot share PHI with third-party service providers unless a Business Associate Agreement is in place. The BAA establishes the third party's obligations under HIPAA — including the requirement to implement the same Security Rule safeguards.
The "BAA-able" architecture question
For a cloud provider to be BAA-able, the architecture must support HIPAA's safeguards: encryption of PHI at rest and in transit, access controls with audit, integrity verification, breach detection and notification. Most major hyperscalers will sign BAAs for specific service tiers.
SkyeConnex's zero-knowledge architecture exceeds HIPAA's baseline by construction: the storage operator cannot access PHI in any operational mode. This simplifies the BAA negotiation — there's less for the covered entity to worry about because there's less surface where the business associate could fail.
Cross-border health data
HIPAA does not require US residency for PHI, but most healthcare organisations apply additional residency requirements driven by state laws, provider agreements, and risk management. For organisations operating across PIPEDA, PHIPA, and HIPAA simultaneously, SkyeConnex's per-jurisdiction policy makes residency a configuration rather than a contract.
HITECH and OCR enforcement
The HITECH Act (2009) strengthened HIPAA penalties and tied them to corrective-action requirements. The Office for Civil Rights enforces HIPAA aggressively; multi-million-dollar settlements are common. Architectures that prevent breaches by construction reduce both the probability and severity of OCR enforcement exposure.
How SkyeConnex maps
The HIPAA-BAA preset pack pre-configures encryption, audit, breach-detection, and PHI-handling defaults. The BAA-able architecture is documented for covered-entity legal review. See the healthcare industry page →
Related terms
See also
Posts that mention HIPAA-BAA
Healthcare data residency: PIPEDA + HIPAA + provincial — a survival guide
Healthcare data in 2026 must satisfy PIPEDA, HIPAA, provincial health acts, and emerging AI compliance — often simultaneously. The architect…
Read → Cryptography · 7 min readWhy customer-managed keys aren't zero-knowledge
Customer-managed keys (CMK) are hyperscalers' answer to the sovereignty question. They're better than provider-managed keys. They don't deli…
Read → Regulation · Canada · 7 min readPIPEDA and cloud storage: what most providers get wrong
PIPEDA predates the cloud. Applying it to multi-cloud workloads requires architectural thinking that most providers don't do. Here's the gap…
Read →