Do I need a BAA as a developer?
Yes, if your work touches PHI. Sign it with the clinic before you see any patient data
Every service that touches patient data needs a signed BAA, including the ones Claude wired in
The video, without the music
If you build an app for a US clinic and it touches patient health information (PHI), you are a business associate. You sign a business associate agreement (BAA) with the clinic before you touch any patient data, and every outside service your app sends PHI to (hosting, logs, error tracking, email, AI models) needs a BAA too. Business associates can be fined directly, not just the clinic.
Yes, if your work touches PHI. Sign it with the clinic before you see any patient data
Yes, if PHI passes through it. Many providers only offer one on certain plans
Use fake patient data until every BAA is signed
The clinic, and business associates directly for their own violations
The US law for health information tied to a person, called PHI, which stands for protected health information
Anyone outside the clinic who touches PHI is a business associate and signs a BAA first. That includes you, and every company your app passes PHI to
Every outside service that stores, receives or sends PHI, with the file and line, and whether that company offers a BAA on your plan. It also flags PHI in logs, URLs, analytics, AI prompts and notification text
Whether each BAA has actually been signed. A company offering a BAA is not the same as you having one
When we built our HIPAA app, we worked on fake patient data until every one of them was signed
Ready to copy into Claude. It reads your code and changes nothing
The leaks that hide in error logs, tracking pixels and reminder texts
So you don't chase services that never see a patient
Every BAA to get signed, and the breach plan the code can't do for you
The prompt to give Claude, what to look for in its answer, what you can ignore, and the BAAs you still have to get signed



An engineer checks it, fixes it, tests it and puts their name on it