COMPLIANCE · ANALYSIS
HIPAA and your CRM: who is responsible for what
A BAA is the start of the compliance conversation rather than the end of it. This is the part that stays with your practice whichever vendor you pick.
A note on what this is: a general description of how responsibility divides, not legal advice. TheraCRM.pro is not a covered entity, and your own counsel should review anything you act on.
The sentence that causes the trouble
It usually goes something like: we signed a BAA with our CRM vendor, so we are covered. It is an easy assumption to make. A BAA allocates responsibility between the parties, but it does not discharge yours, and a vendor cannot sign away obligations that sit with your practice as a covered entity.
Compliance is also not a state a product can be in. Software can be configured to support it, and infrastructure can be HIPAA-enabled, but "a HIPAA compliant CRM" is not really a thing. If a vendor says it, a fair follow-up is which of your obligations it removes, and the answer is generally none of them.
BUSINESS ASSOCIATE AGREEMENT
The split is three ways, not two
Most explanations of this describe two parties, a vendor and a practice. In a reseller arrangement, which covers a good share of healthcare CRMs, there are three, and it helps to know which one owns what.
- The platform provides the technical safeguards: encryption in transit and at rest, access controls, audit logging, and the infrastructure those run on.
- We configure them: which fields collect what, who can see which records, what the automated messages are allowed to contain, retention on transcripts and recordings, and the BAA chain being executed end to end.
- Your practice maintains everything a vendor cannot touch: workforce training, access reviews when staff leave, device and password policy, your own risk analysis, and the judgement calls your team makes daily.
Where it usually slips
It is rarely the encryption. More often it is the everyday habits that put PHI somewhere it should not be:
- Clinical detail typed into an SMS because it was faster than opening the record. Text is a channel with weak assumptions; the less it carries, the better.
- A shared front-desk login, which makes the audit log describe a chair rather than a person.
- Staff who left three months ago and still have access, because offboarding is a checklist nobody owns.
- Call recordings and voice transcripts retained indefinitely by default. A transcript containing clinical detail is PHI, and default-forever is a decision even when nobody made it.
This is why our voice agent is scoped to scheduling and logistics rather than clinical questions, and why retention on transcripts and recordings is configurable rather than assumed. Those are configuration choices with compliance consequences, and they belong to the build.
What to ask any vendor before you sign
- Will you sign a BAA, is it included, and can I read it before I buy?
- Is there a subcontractor in the chain, and is a BAA executed with them too?
- What exactly is encrypted, and where does the data live?
- Can I control retention on messages, recordings and transcripts?
- When I leave, what happens to the data, and in what format do I get it?
How a vendor handles these tends to tell you something about how the rest of the relationship will go. "We are fully HIPAA compliant" is not an answer to any of them.
Questions we get asked about this
Does signing a BAA make my practice HIPAA compliant?
No. A BAA allocates responsibility between the parties; it does not discharge obligations that attach to your practice as a covered entity. No vendor can sign those away.
Who is responsible for HIPAA in a CRM: the vendor or the practice?
Both, and in a reseller arrangement there are three parties. The platform provides technical safeguards, we configure them, and your practice maintains workforce training, access reviews, device and password policy, and its own risk analysis.
Is it safe to put clinical detail in an SMS to a patient?
Text is a channel with weak assumptions, and the less clinical detail it carries the better. This is why our voice agent is scoped to scheduling and logistics rather than clinical questions, and why retention on transcripts and recordings is configurable rather than assumed.
What should I ask a CRM vendor about HIPAA before signing?
Whether they will sign a BAA and let you read it first, whether a subcontractor is in the chain and has one too, what is encrypted and where the data lives, whether you control retention, and what happens to your data when you leave.
Related
Want the split applied to your practice?
A 30-minute consultation goes through which side of the line each of your current tools sits on, before anything changes.