GLOSSARY · TRUST AND COVERAGE

BAA, the contract that protects patient data.

A BAA (business associate agreement) is a HIPAA contract that binds any vendor handling patient health information to protect it, limit how it is used, and report breaches.

01

What it means

Under HIPAA, a covered entity such as a medical practice must sign a BAA with each business associate, meaning any outside company that creates, receives, stores, or transmits protected health information (PHI) on its behalf. The agreement spells out permitted uses of the data, required safeguards, breach notification duties, and what happens to the data when the relationship ends.

Business associates must sign matching agreements with their own subcontractors, so the protection follows the data down the chain.

02

Why it matters to a brand operator

A telehealth brand handles PHI far beyond its medical records. Intake answers, order history tied to a condition, patient messages, and even an email list built from a weight-loss quiz can count as health information. Every vendor in that path needs a BAA or needs to be kept away from the data, including hosting, email and SMS tools, CRMs, analytics, and support software.

Advertising pixels are the most common gap. Tracking code that sends health-related page activity to an ad platform that will not sign a BAA has led to federal enforcement against health brands. A brand should know exactly what its tracking tags collect on every page past the landing page.

[  03  ]

How Tessic Health handles it

Tessic Health executes a BAA with every client before any PHI is created or transferred. It defines permitted uses, required safeguards, breach notification timelines, and the return or destruction of data at termination, and Tessic's subprocessors are bound by equivalent downstream agreements.

See the published terms