Scope
When a software development engagement requires Medplaza personnel to access PHI — for example, when working within a client’s environment on systems that process patient records — Medplaza executes a Business Associate Agreement with the covered entity or business associate as required under the HIPAA Privacy Rule. BAAs are executed between the client and Medplaza, Inc. and are scoped to the specific engagement.
The medplaza.com marketing site itself does not collect, store, or process PHI. No BAA is required for routine use of this Site.
Request process
- Submit a request through our contact form with your company name, a description of the engagement, and a primary contact for the agreement.
- We return our standard BAA template within three business days.
- We accommodate customer-specific edits through a normal redline cycle.
- Execution is coordinated with engagement kickoff so the BAA is in place before any PHI is accessed.
Third-party BAA forms
We cannot accept third-party BAA forms unmodified. Customer templates must be reviewed and negotiated against our operational and technical controls. Submitting a customer template is welcome and will be handled through the same redline cycle described above.
Disclaimer
A Business Associate Agreement is a separate written agreement between the client and Medplaza, Inc. Engagement-specific terms, privacy notices, and security documentation may also apply. Nothing on this page constitutes a BAA or an offer to enter into one; an executed agreement is required before any PHI is shared.