Trust

Our HIPAA Business Associate Agreement

Last reviewed 2026-09-28

Yes. Opexia signs a HIPAA Business Associate Agreement (BAA) with every client before anyone on our team can access protected health information (PHI). No PHI is shared with us, migrated or viewed until the agreement is executed. We can sign your organization's BAA or provide ours, and the signed agreement governs.

When a BAA applies

HIPAA defines a business associate as a person or company that creates, receives, maintains or transmits PHI on behalf of a covered entity, and it includes subcontractors doing the same for another business associate (45 CFR 160.103). When our work involves PHI, such as migrating patient records, building against production data or supporting a live system, that describes us, and a BAA is required before we start.

A BAA is not needed for work done entirely on de-identified or synthetic data. Information that meets HIPAA's de-identification standard is not individually identifiable health information (45 CFR 164.514(a)), so no PHI reaches us. A build can run this way until go-live, with the BAA signed before the first production record is in scope.

What our BAA commits us to

HIPAA sets the terms every business associate contract must contain in 45 CFR 164.504(e)(2), and HHS publishes sample provisions that follow them. Our BAA includes each one.

  • Permitted uses and disclosures

    We use and disclose PHI only as the agreement permits or as the law requires, limited to the services you engaged us for.

    45 CFR 164.504(e)(2)(i), (ii)(A)

  • Safeguards

    We use appropriate safeguards and comply with the HIPAA Security Rule for electronic PHI.

    45 CFR 164.504(e)(2)(ii)(B); 164.314(a)(2)(i)(A)

  • Reporting breaches and security incidents

    We report any use or disclosure the agreement does not allow, any security incident, and any breach of unsecured PHI. HIPAA's outer limit for a business associate's breach notice is without unreasonable delay and no later than 60 calendar days after discovery; the exact notice period is set in each signed agreement.

    45 CFR 164.504(e)(2)(ii)(C); 164.314(a)(2)(i)(C); 164.410(b)

  • Subcontractor flow-down

    Any subcontractor that would create, receive, maintain or transmit PHI for us must first agree in writing to the same restrictions and conditions.

    45 CFR 164.502(e)(1)(ii); 164.504(e)(2)(ii)(D)

  • Supporting individual rights

    We make PHI available so you can meet patients' rights to access, amendment and an accounting of disclosures.

    45 CFR 164.504(e)(2)(ii)(E)–(G)

  • Records available to HHS

    We make our internal practices, books and records about PHI available to the Secretary of HHS for determining your compliance.

    45 CFR 164.504(e)(2)(ii)(I)

  • Return or destruction at termination

    When the agreement ends we return or destroy the PHI we hold and keep no copies; where that is not feasible, its protections continue and further use is limited. You may terminate if we violate a material term.

    45 CFR 164.504(e)(2)(ii)(J), (iii)

How we limit PHI exposure in practice

  • Access to PHI is granted by role and recorded in audit logs, the same controls we build into client platforms.
  • Production PHI access is limited to the people and systems the engagement requires.
  • We build and test on de-identified or synthetic data wherever possible.
  • We host PHI only on cloud services covered by the provider's BAA (see our HIPAA-eligible services lookup).
  • Vendors that would touch PHI, such as email, logging or AI APIs, are chosen from those that sign a BAA (see which vendors sign a BAA).

What a BAA does not do

  • It does not make a system compliant by itself. A BAA puts obligations in writing. The safeguards still have to be built and run; we build systems to HIPAA requirements (encryption, audit logging, role-based access).
  • It does not replace your risk analysis. Your organization's own risk analysis, policies and workforce training stay with you.
  • It is not a SOC 2 report. Opexia holds no SOC 2 report. Those are issued by licensed CPA firms; we build and document the controls such an examination tests (see HIPAA & SOC 2 architecture).

Your BAA or ours

We can sign your organization's BAA or provide ours. Either way, the terms above are the baseline. Our free HIPAA BAA review checklist checks an agreement against HIPAA's required terms, whichever template you start from.

This page describes how we work; it is not legal advice. The signed agreement governs.

Sources

Questions buyers ask about our BAA

Does Opexia sign a BAA?

Yes. We sign a HIPAA Business Associate Agreement with every client whose engagement involves protected health information, before anyone on our team can access it.

When is the BAA signed?

At the start of the engagement, before any PHI is shared, migrated or viewed. Work on de-identified or synthetic data can begin first; production data waits for the executed BAA.

Do your subcontractors sign BAAs?

Yes. Any subcontractor that would create, receive, maintain or transmit PHI for us must first sign an agreement with the same restrictions, as 45 CFR 164.502(e)(1)(ii) and 164.504(e)(2)(ii)(D) require. Cloud and software vendors that would touch PHI must be covered by a BAA, whether with us or with your organization directly.

Where is PHI accessed from?

Our team works from Pakistan with US business-hours overlap. Access to PHI is governed by the BAA, role-based access and audit logging, and production PHI access is limited to what the engagement requires. Where possible we build on de-identified or synthetic data instead.

Can we use our own BAA template?

Yes. We can sign your organization's BAA or provide ours. Our free HIPAA BAA review checklist (opexia.io/tools/hipaa-baa-review-checklist) checks either one against the terms HIPAA requires.

Is Opexia SOC 2 audited?

No. Opexia holds no SOC 2 report; those are issued by licensed CPA firms after examining an organization's controls. We build and document the controls a CPA firm examines in the systems we build for clients.

Talk through your BAA and data flow

Bring your BAA template or ask for ours. We will walk through which parts of the work touch PHI and which can run on de-identified or synthetic data.

Book a free consultation