COMPLIANCE · ANALYSIS
HIPAA and your CRM: who is responsible for what
Signing a BAA is the beginning of the conversation, not the end of it. Here is the part of the split that lands on your practice regardless of which vendor you choose.
This is a general description of how responsibility divides, not legal advice. TheraCRM.pro is not a covered entity and does not provide legal advice; your own counsel should review anything you rely on.
The sentence that causes the trouble
It usually goes: we signed a BAA with our CRM vendor, so we are HIPAA compliant. Every clause in it is doing damage. A BAA is a contract that allocates responsibility; it does not discharge yours, and no vendor can sign away obligations that attach to your practice as a covered entity.
Compliance is also not a state a product can be in. Software can be configured to support compliance, and infrastructure can be HIPAA-enabled, but "a HIPAA compliant CRM" describes something that does not exist. When a vendor says it, the useful follow-up is: which of my obligations does that remove? The answer is none.
BUSINESS ASSOCIATE AGREEMENT
The split is three ways, not two
Most explanations of this describe a vendor and a practice. In a reseller arrangement, which covers a large share of healthcare CRMs, there are three parties, and knowing which one owns what is the difference between a real posture and a paper one.
- The platform provides the technical safeguards: encryption in transit and at rest, access controls, audit logging, and the infrastructure those run on.
- We configure them: which fields collect what, who can see which records, what the automated messages are allowed to contain, retention on transcripts and recordings, and the BAA chain being executed end to end.
- Your practice maintains everything a vendor cannot touch: workforce training, access reviews when staff leave, device and password policy, your own risk analysis, and the judgement calls your team makes daily.
The part practices most often miss
Not the encryption. It is the everyday operational habits that quietly put PHI where it should not be:
- Clinical detail typed into an SMS because it was faster than opening the record. Text is a channel with weak assumptions; the less it carries, the better.
- A shared front-desk login, which makes the audit log describe a chair rather than a person.
- Staff who left three months ago and still have access, because offboarding is a checklist nobody owns.
- Call recordings and voice transcripts retained indefinitely by default. A transcript containing clinical detail is PHI, and default-forever is a decision even when nobody made it.
This is why our voice agent is scoped to scheduling and logistics rather than clinical questions, and why retention on transcripts and recordings is configurable rather than assumed. Those are configuration choices with compliance consequences, and they belong to the build.
What to ask any vendor before you sign
- Will you sign a BAA, is it included, and can I read it before I buy?
- Is there a subcontractor in the chain, and is a BAA executed with them too?
- What exactly is encrypted, and where does the data live?
- Can I control retention on messages, recordings and transcripts?
- When I leave, what happens to the data, and in what format do I get it?
A vendor that answers these plainly is telling you something about how the rest of the relationship will go. A vendor that answers "we are fully HIPAA compliant" has not answered any of them.
Questions we get asked about this
Does signing a BAA make my practice HIPAA compliant?
No. A BAA allocates responsibility between the parties; it does not discharge obligations that attach to your practice as a covered entity. No vendor can sign those away.
Who is responsible for HIPAA in a CRM: the vendor or the practice?
Both, and in a reseller arrangement there are three parties. The platform provides technical safeguards, we configure them, and your practice maintains workforce training, access reviews, device and password policy, and its own risk analysis.
Is it safe to put clinical detail in an SMS to a patient?
Text is a channel with weak assumptions, and the less clinical detail it carries the better. This is why our voice agent is scoped to scheduling and logistics rather than clinical questions, and why retention on transcripts and recordings is configurable rather than assumed.
What should I ask a CRM vendor about HIPAA before signing?
Whether they will sign a BAA and let you read it first, whether a subcontractor is in the chain and has one too, what is encrypted and where the data lives, whether you control retention, and what happens to your data when you leave.
Related
Want the split applied to your practice?
A 30-minute consultation goes through which side of the line each of your current tools sits on, before anything changes.