HIPAA-sensitive customers can request BAA review before self-service purchase.

HeliQore can support BAA discussions for approved workflows, but a Business Associate Agreement must be separately reviewed and signed. Ordinary website use and Stripe Checkout do not create one automatically.

When A BAA Is Needed

If a customer plans to disclose HIPAA-regulated PHI to HeliQore as part of an approved workflow, the customer should request BAA review before using self-service checkout for that workflow.

What Self-Service Checkout Does

Stripe Checkout can collect acceptance of HeliQore's Terms of Service and display the Privacy Policy, but that checkout flow does not sign or activate a Business Associate Agreement.

What The BAA Request Process Covers

  • Workflow review for HIPAA-sensitive use cases
  • Discussion of data handling, approved configurations, and residency expectations
  • Review of HeliQore's BAA template and any customer paper
  • Confirmation that PHI workflows should not proceed until the required contract path is complete

Before You Send PHI

Do not assume a BAA exists just because a subscription has been purchased, an account has been created, or a Stripe checkout completed. If your intended workflow requires a BAA, wait for written approval and signature completion first.