Effective February 2, 2026
Compassly makes a Business Associate Agreement available to eligible covered entities and business associates before Compassly handles protected health information on their behalf. This page explains our standard BAA approach; the agreement signed with your organization is the controlling legal document.
What a BAA is
A Business Associate Agreement (“BAA”) is the HIPAA-required contract that defines how a business associate may create, receive, maintain, or transmit protected health information (“PHI”) for a covered entity or another business associate.
A BAA does not certify that either party is automatically HIPAA compliant. Each organization remains responsible for its own policies, risk analysis, workforce training, access decisions, and lawful use of PHI.
Who can obtain one
Compassly, LLC offers a BAA to eligible U.S. healthcare customers whose subscribed use of Compassly involves PHI. This commonly includes covered healthcare providers and business associates serving those providers.
BAA eligibility, the covered Compassly services, and the contracting entity are confirmed during the sales and onboarding process. A BAA must be executed before PHI is placed in a Compassly customer environment.
Services the BAA covers
The executed BAA identifies the Compassly services and customer environment covered by the agreement. Covered services may include clinical documentation, data collection, scheduling, medication-management workflows, notes, forms, role-based access, and audit records included in the customer’s subscription.
The public marketing website, unauthenticated demo inquiries, and unrelated third-party products are not automatically covered services. Do not submit PHI through compassly.io forms or ordinary sales email.
Permitted uses and disclosures
Compassly may use or disclose PHI only as needed to provide the covered services, perform obligations described in the executed BAA and customer agreement, comply with law, or support the customer as HIPAA permits.
Compassly does not use customer PHI for advertising and does not use production customer PHI to train public foundation models.
Safeguards
Compassly applies administrative, technical, and physical safeguards appropriate to the covered services. Our current public control narrative includes encryption in transit, authenticated access, role-based permissions, mobile authentication options, and audit logging.
Security documentation beyond the public Security page is provided during a sales-led diligence review, subject to appropriate confidentiality protections.
Security incidents and breaches
The executed BAA defines how Compassly reports breaches of unsecured PHI and other reportable security events, including the information and timing required by HIPAA and the agreement.
Customers should report suspected unauthorized access promptly through their designated support or security channel. Public website forms should not contain PHI or incident evidence.
Subcontractors
When a subcontractor will create, receive, maintain, or transmit PHI for covered Compassly services, Compassly requires written restrictions and safeguards consistent with applicable HIPAA business-associate obligations.
Material subprocessors relevant to a customer’s deployment are available during security and contracting review. We do not publish an incomplete or speculative vendor list.
Individual rights and records
Compassly supports customers in meeting applicable obligations involving access, amendment, and accounting of disclosures as described in the executed BAA and supported product workflows.
Individuals seeking their health records should contact the healthcare provider or organization responsible for those records. Compassly generally cannot authenticate or release a provider’s records directly from a marketing-site request.
Customer responsibilities
Customers remain responsible for:
- Configuring roles and access according to workforce responsibilities.
- Obtaining authorizations and consents required for their treatment and operational workflows.
- Training users and promptly removing access when it is no longer appropriate.
- Avoiding PHI in non-covered channels, including public forms and ordinary marketing email.
- Maintaining their own HIPAA privacy and security program, risk analysis, and incident procedures.
Return or destruction
When covered services end, PHI is returned, made available for export, retained, or destroyed according to the executed BAA, customer agreement, technical feasibility, and applicable law.
If PHI must be retained after termination, the BAA’s protections continue for that retained information for as long as required.
Request a Compassly BAA
Prospective customers can request a BAA during a demo or by emailing support@compassly.io. Existing customers should use their established support or account contact.
The signed Compassly BAA—not this explanatory webpage—is the binding agreement. Counsel should review the form before your organization executes it.
