Baykscloud Consultants LogoBayksCloud Consultants
    Book Free AI Strategy Call
    AI Digital Connections Background

    HIPAA Business Associate Policy

    Effective Date: July 10, 2026

    1. Our Role as a Business Associate

    Under the Health Insurance Portability and Accountability Act (HIPAA), a "Business Associate" is an entity that performs certain functions or activities that involve the use or disclosure of Protected Health Information (PHI) on behalf of, or provides services to, a covered entity.

    Baykscloud Consultants builds and manages AI Voice Receptionists for med spas and aesthetic clinics. Because our AI agents handle inbound calls and appointment scheduling, we may receive limited PHI. Therefore, we act as a Business Associate for our covered entity clients.

    • What PHI we may access: Appointment scheduling data only, which typically includes patient names, phone numbers, email addresses, and appointment preferences.
    • What PHI we do NOT access: Medical records, treatment history, medical diagnoses, insurance information, or payment details.

    We are fully committed to maintaining HIPAA-compliant practices to protect the confidentiality, integrity, and availability of the limited PHI we handle.

    2. Business Associate Agreement (BAA)

    A signed Business Associate Agreement (BAA) is required before any med spa client's AI system goes live. The BAA outlines our responsibilities and obligations regarding the safeguarding of your patients' PHI.

    • What the BAA covers: Permitted uses and disclosures of PHI, safeguard requirements, breach notification protocols, and subcontractor obligations.
    • How to request a BAA: Email info@baykscloudconsultants.io with the subject line "BAA Request".

    We provide the BAA at no additional cost. The typical turnaround time for providing a signed BAA is 3 to 5 business days.

    Need a BAA for your clinic?

    Request Your BAA

    3. Safeguards We Maintain

    To protect the PHI entrusted to us, we implement comprehensive safeguards:

    • Administrative Safeguards: Regular staff awareness training, strict access controls based on the principle of least privilege, and a designated privacy contact within our organization.
    • Technical Safeguards: Industry-standard encryption for data in transit and at rest, secure access controls (including multi-factor authentication), and comprehensive audit logs.
    • Physical Safeguards: Secure data storage environments and strictly limited physical access to systems housing data.

    We also conduct regular risk assessments to identify and mitigate potential vulnerabilities.

    4. Permitted Uses of PHI

    We use PHI strictly for the specific purposes described in the Business Associate Agreement. This is limited to appointment scheduling and call handling operations.

    We will never use PHI for marketing purposes, AI model training, or any other secondary purpose not explicitly authorized. We will never sell PHI or share it with third parties outside the scope of the BAA.

    5. Breach Notification

    In the unlikely event of a security incident involving PHI, Baykscloud Consultants will notify our covered entity clients within 30 days of discovering a breach.

    Our notification will include the nature of the breach, the specific PHI involved, the steps we have taken to mitigate the breach, and recommended actions for the client to take.

    We maintain an active incident response plan at all times to ensure swift and effective action.

    6. Subcontractors

    Any subcontractors engaged by Baykscloud Consultants who may access PHI are required to sign their own Business Associate Agreement with us, holding them to the same strict standards.

    Our primary operational platforms operate under their own robust HIPAA compliance programs. Telephony providers and other technical infrastructure partners operate under strict data processing agreements.

    7. Minimum Necessary Standard

    Baykscloud Consultants adheres strictly to the "Minimum Necessary" standard. We only access, use, or request the minimum PHI necessary to perform the contracted service.

    Our AI agents are specifically configured to collect only basic scheduling information: name, phone number, email, and appointment preference. Under no circumstances are our AI agents configured to collect medical history, treatment details, or insurance information.

    8. Patient Rights Support

    Under HIPAA, patients have rights regarding their PHI, including the right to access, amend, or request deletion of their information.

    Baykscloud Consultants supports our covered entity clients in honoring these rights. Any direct requests we receive from patients for PHI access, correction, or deletion will be forwarded immediately to the respective covered entity client. We do not independently respond to patient PHI requests.

    9. Important Disclaimer

    This policy page is intended for informational purposes only and does not constitute legal advice.

    Med spa owners and clinic directors should consult their own HIPAA compliance officer or healthcare attorney to ensure their overall operations meet regulatory requirements. Baykscloud Consultants strongly recommends that all clients conduct their own comprehensive HIPAA risk assessment.

    10. Contact for HIPAA Matters

    If you have any questions regarding our HIPAA policies or need to discuss compliance matters, please contact us:

    We aim to respond to all HIPAA-related inquiries within 5 business days.

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept", you consent to our use of cookies.