Healthcare Provider? Request Your BAA Today.

All Covered Entities using IntakeAccess.ai must execute a Business Associate Agreement before accessing PHI. Request yours in minutes.

Request a BAA — compliance@intakeaccess.ai
1

Our HIPAA Compliance Commitment

IntakeAccess.ai is built from the ground up as a HIPAA-compliant AI healthcare platform. We handle Protected Health Information (PHI) on behalf of Covered Entities — including hospitals, clinics, SNFs, private practices, and FQHCs — and operate as a Business Associate under HIPAA (45 C.F.R. §§ 160–164).

Our compliance program encompasses the full scope of HIPAA's requirements: the Privacy Rule, the Security Rule, the Breach Notification Rule, and the administrative, technical, and physical safeguard standards of the HITECH Act. We do not treat HIPAA compliance as a checkbox — it is embedded in every layer of our platform architecture, operational processes, and workforce culture.

2

HIPAA Security Rule Safeguards

The HIPAA Security Rule (45 C.F.R. §§ 164.302–164.318) requires covered entities and business associates to implement three categories of safeguards. We implement all required and addressable specifications:

🔒

Technical Safeguards

AES-256 at rest, TLS 1.3 in transit, MFA, RBAC, session timeouts, audit controls, PHI access logging, 2FA patient portal

📋

Administrative Safeguards

Designated Security Officer, workforce training, risk analysis, risk management, BAA program, sanction policies, contingency planning

🏢

Physical Safeguards

HIPAA-eligible data centers (Google Cloud, AWS), facility access controls, workstation security policies, device and media controls

Technical Safeguards — Detail

Administrative Safeguards — Detail

3

Business Associate Agreements (BAAs)

Under HIPAA, when a Business Associate handles PHI on behalf of a Covered Entity, a signed BAA is mandatory. IntakeAccess.ai maintains BAAs in two directions:

BAAs We Execute with Covered Entities (Our Customers)

Any healthcare provider, hospital, clinic, SNF, or other Covered Entity using IntakeAccess.ai must execute a BAA with us. We offer a standard BAA that meets all HIPAA requirements. Enterprise customers may negotiate terms through the Order Form process.

To request a BAA: Email compliance@intakeaccess.ai with subject line "BAA Request." We will provide the agreement within 3 business days. A signed BAA must be on file before any PHI flows through the Platform.

BAAs We Execute with Our Subcontractors

SubcontractorRoleBAA Status
TwilioSMS, video, secure messaging✓ BAA Executed
Firebase / Google CloudDatabase, hosting, authentication✓ BAA Executed
StripePayment processing✓ BAA Executed
EDI PartnersClaims, prior auth, insurance verification✓ BAA Executed
SendGridEmail communications✓ BAA Executed
AWSBackend infrastructure✓ BAA Executed
Make.comAutomation (demo use only)⏳ In Progress — No PHI until executed
No PHI Without a BAAIntakeAccess.ai does not permit any subcontractor or vendor to access, process, or transmit PHI until a Business Associate Agreement is fully executed. Make.com is currently limited to non-PHI demo automation until its BAA is complete.
4

Breach Notification Policy

IntakeAccess.ai maintains a documented Breach Notification Policy in full compliance with the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–164.414) and the HITECH Act. Our policy covers detection, risk assessment, notification, and post-incident remediation.

Breach Response Timeline

Report a Security ConcernIf you suspect unauthorized access to PHI, a security vulnerability, or any potential breach, contact our Security team immediately: security@intakeaccess.ai or call 205-855-4545. We respond to all security reports within 4 hours.
5

Audit, Monitoring & Risk Assessment

Continuous Monitoring

Periodic Assessments

Audit Log Retention

All PHI access audit logs are retained for a minimum of 6 years from the date of creation, as required by the HIPAA Security Rule (§ 164.312(b)) and the general documentation retention standard (§ 164.530(j)).

6

HIPAA Privacy Rule Compliance

IntakeAccess.ai complies with the HIPAA Privacy Rule (45 C.F.R. Part 164, Subpart E) governing the use and disclosure of PHI:

7

Contact Our Compliance Team

INTAKEACCESS.AI LLC
DBA: Intake Access Health Solutions
181 W Valley Ave STE 245-1742
Birmingham, AL 35209

For all HIPAA compliance inquiries, BAA requests, breach reports, and regulatory questions:

Our CommitmentIntakeAccess.ai will not retaliate against any patient, provider, or employee who exercises their HIPAA rights or files a good-faith complaint with HHS OCR or any other regulatory authority.