Cliniko BAA: Does Cliniko Sign a Business Associate Agreement for HIPAA?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Cliniko BAA: Does Cliniko Sign a Business Associate Agreement for HIPAA?

Kevin Henry

HIPAA

May 01, 2026

7 minutes read
Share this article
Cliniko BAA: Does Cliniko Sign a Business Associate Agreement for HIPAA?

Cliniko HIPAA Compliance Overview

If you are a U.S. covered entity or business associate and you plan to create, receive, maintain, or transmit Protected Health Information (PHI) in Cliniko, you must have a signed Business Associate Agreement (BAA) in place. The executed BAA is the formal signal that the vendor will handle PHI under HIPAA’s Privacy Rule and Security Rule.

Cliniko’s ability to function as your Business Associate depends on the presence of that signed agreement and on how you configure and use the platform. HIPAA compliance is shared: Cliniko must implement appropriate safeguards, and you must limit access to the minimum necessary, train your workforce, and operate within the agreement’s permitted data use and disclosure terms.

  • Do not store PHI in any third‑party system until your BAA with that vendor is fully executed.
  • Compliance is a program, not a product; there is no official government “HIPAA certification.”
  • Your policies, risk management, and configuration decisions are as important as vendor features.

Requesting a Business Associate Agreement

Step-by-step process

  • Confirm your status: Determine whether you are a covered entity (e.g., provider, health plan) or a business associate acting on behalf of one.
  • Identify your PHI flows: Map how PHI will enter, be used in, and leave Cliniko (e.g., scheduling, clinical notes, documents, messaging).
  • Prepare contacts: Designate your privacy and security contacts and the authorized signatory for contracts.
  • Initiate the request: Ask Cliniko for a Business Associate Agreement using your account owner/admin channel. Provide your legal entity name, address, and required details.
  • Review the draft: Evaluate permitted uses, breach notification timelines, subcontractor terms, and termination provisions. Seek counsel if needed.
  • Execute the BAA: Complete e-signature or the process Cliniko provides, then store the executed copy in your compliance repository.

Information you may be asked to provide

  • Legal entity name and mailing address; primary contact and security contact.
  • Whether you are a covered entity or business associate, and the services you’ll use.
  • Any specific regulatory requirements (e.g., state privacy laws) that impact your use case.

Patient Privacy Settings Configuration

Once your BAA is executed, configure Cliniko so PHI is protected by default and access is limited to the minimum necessary. The exact options can vary by account and feature set, so review every setting that touches PHI.

Account and access controls

  • Enable two‑factor authentication for all users and require strong, unique passwords.
  • Use role‑based access to restrict staff to only the records they need to perform their duties.
  • Disable or limit any sharing features that could expose PHI beyond your workforce.

Communication and scheduling

  • Configure reminders, messaging, and notices to exclude diagnosis details and other sensitive PHI; keep to identifiers that are truly necessary.
  • If you use online booking, ensure public pages never reveal PHI and that confirmation content is minimal.

Records, documents, and logs

  • Restrict who can upload, view, or download attachments and clinical notes.
  • Turn on and routinely review audit logs to track access, edits, and exports of PHI.
  • Define retention and disposal practices that align with your legal and policy requirements.

Terms and Conditions of Cliniko BAA

Your executed BAA governs how Cliniko may use and disclose PHI and the safeguards it must maintain. While the exact language comes from the signed document, most healthcare BAAs contain the following elements:

  • Permitted data use and disclosure: Clear limits on how PHI may be processed to deliver services to you, and prohibitions on unauthorized secondary uses.
  • Safeguards under the Security Rule: Administrative, physical, and technical measures to protect the confidentiality, integrity, and availability of ePHI.
  • Subcontractors: Requirements that any subcontractors engaged by the vendor who handle PHI agree to the same restrictions and safeguards.
  • Breach and incident reporting: Definitions, notification timelines, and the information that will be provided to you after an incident.
  • Individual rights support: Cooperation to facilitate access, amendment, and accounting of disclosures when patients exercise Privacy Rule rights.
  • Minimum necessary: Commitments to limit PHI handling to what is needed to perform services.
  • Termination, return, or destruction: What happens to PHI when the relationship ends, including secure deletion or return procedures.
  • Audit and documentation: Record‑keeping, audit cooperation, and availability of documentation demonstrating compliance.

Always treat the executed BAA as the single source of truth for obligations and processes. If your needs differ, negotiate addenda before you begin handling PHI in Cliniko.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Responsibilities Under the BAA

A BAA does not make you “HIPAA compliant” by itself. As the covered entity (or upstream business associate), you retain key responsibilities:

  • Governance and training: Maintain written policies, conduct workforce training, and enforce sanctions for violations.
  • Access management: Provision and deprovision users promptly; use the minimum necessary standard across roles and workflows.
  • Risk management: Perform periodic risk analyses; document remediation plans for identified gaps.
  • Patient rights: Respond to requests for access, amendments, and restrictions; coordinate with Cliniko as needed under the BAA.
  • Incident response: Monitor for anomalies, investigate alerts, and meet regulatory reporting duties if a breach occurs.
  • Vendor oversight: Keep an inventory of business associates, store executed BAAs, and review them regularly.
  • Secure endpoints: Protect devices that access Cliniko with encryption, patching, and screen‑locking to prevent unauthorized viewing.

Data Security Measures

Strong technical and administrative controls reduce risk and support HIPAA Compliance. Confirm what Cliniko provides and close any remaining gaps within your environment.

  • Encryption: Ensure encryption in transit for all connections and encryption at rest for stored ePHI; protect backups similarly.
  • Identity and access: Enforce two‑factor authentication, unique user accounts, and least‑privilege permissions.
  • Audit and alerts: Enable logging of access, exports, and administrative changes; review reports and set alert thresholds.
  • Data lifecycle: Define retention, archival, and deletion routines; verify secure disposal when data is no longer needed.
  • Business continuity: Validate backup frequency, recovery point objectives, and disaster‑recovery procedures.
  • Change management and testing: Apply updates promptly and test critical workflows—especially those touching PHI—after changes.

Steps After BAA Approval

  • File the agreement: Store the executed BAA with your vendor inventory and policy documents.
  • Finalize configuration: Apply privacy settings, user roles, and communication templates that reflect minimum necessary PHI.
  • Harden access: Require two‑factor authentication, rotate any shared credentials, and remove unused accounts.
  • Migrate securely: If importing records, use encrypted channels; validate that migrated data is complete and access‑controlled.
  • Train your team: Provide role‑based training on how PHI is handled in Cliniko and what not to include in messages or reminders.
  • Test and verify: Run a mock incident response, verify audit logs, and confirm backup and restore procedures.
  • Review annually: Reassess risks, re‑attest settings, and update SOPs as features or regulations evolve.

Conclusion

For HIPAA‑regulated use, the critical step is obtaining and executing a Business Associate Agreement with Cliniko before handling PHI. Pair that agreement with least‑privilege access, careful configuration, and ongoing oversight to meet the Privacy Rule and Security Rule while protecting your patients and your practice.

FAQs

How do I request a BAA from Cliniko?

Have your account owner or authorized signatory contact Cliniko to request a Business Associate Agreement. Provide your legal entity details, your role (covered entity or business associate), and how you will use the service with PHI. Review the draft, complete e‑signature, and store the executed copy before uploading PHI.

What does Cliniko’s BAA cover?

The BAA typically defines permitted data use and disclosure, required HIPAA safeguards, subcontractor obligations, breach notification procedures, cooperation for individual rights, minimum necessary standards, and what happens to PHI at termination. Your signed version controls, so rely on that document’s exact terms.

Is Cliniko compliant with HIPAA regulations?

HIPAA compliance is shared. There is no official HIPAA certification; instead, you combine Cliniko’s safeguards and contractual commitments under the BAA with your own policies, workforce training, configuration, and risk management to meet the Privacy Rule and Security Rule. Always confirm current vendor terms and features before using PHI.

What are the responsibilities of a covered entity under Cliniko’s BAA?

You must implement minimum‑necessary access, train staff, maintain policies, manage users and devices, monitor logs, respond to patient requests, and follow incident response and reporting duties. Keep the executed BAA on file and review configurations and risks regularly to sustain HIPAA Compliance over time.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles