Skip to content
Databasezy

Business Associate Agreement

Databasezy signs a Business Associate Agreement (BAA) with organisations on Team and Enterprise that enable secure hosting for protected health information. The BAA is a per-organisation agreement; secure placement is then chosen per database, so only the instances that hold PHI pay for the HIPAA cell.

What the BAA covers

  • Instances with secure placement (HIPAA cell, nodes dedicated to your org), their backups and the HIPAA backup buckets.
  • The control plane, customer portal and admin portal, which never store PHI but handle instance metadata and audit logs.
  • Databasezy staff, sub-processors and the break-glass procedure that notifies you and requires a second approver.

What it does not cover

  • Free and standard cells: PHI must not be stored on shared placement, and the portal labels which instances are covered.
  • Your application, de-identification and access decisions inside the database (see the shared responsibility matrix).

Key terms

  • Permitted uses: only to provide the service; no de-identification, aggregation or analytics on PHI.
  • Safeguards: the HIPAA Security Rule controls listed on the security page, including customer-managed keys, immutable backups, 6-year audit retention and audit export.
  • Breach notification: to you within 60 days as the rule requires, with a 72-hour internal target from discovery.
  • Subcontractors: bound by written agreements with the same obligations; the list is on the sub-processors page.
  • Access, amendment and accounting requests are supported through export and the audit log.
  • Termination: on termination PHI is returned or destroyed within the retention window, or immediately with the full-erasure option, with an erasure certificate written to the audit log.

How to sign

An organisation owner opens Compliance in the portal and chooses "Enable secure hosting (HIPAA)". The current BAA version is shown; Team signs by click-through, Enterprise signs through the contract flow. On acceptance MFA becomes mandatory for members with access to secure instances and the secure placement unlocks in the wizard and the API. The steps are documented in Secure hosting and the BAA.

Full text

The full text of BAA v1 is being finalised with counsel and is published here at the HIPAA launch; the version you sign in the portal is always the one shown at signing time. To receive the current draft for your legal review, email [email protected].