HIPAA, BAA and incident reporting.
What a BAA is, when a report needs one, and how IncidentKit handles patient data and AI.
Short answer
A healthcare incident report usually holds patient details. That makes it protected health information (PHI). HIPAA calls a vendor that holds PHI for you a business associate. It must sign a BAA, a business associate agreement. IncidentKit signs a BAA on Regulated and Network. Lauren runs on a BAA-covered AI provider. The free Open plan blocks patient data.
What each plan covers.
| Plan | Patient information | BAA | AI | Typical use |
|---|---|---|---|---|
| Open (free) | Not allowed | No BAA | Standard AI provider | Workplace injuries, near misses, equipment events, safety checks. |
| Regulated | Allowed | BAA signed | BAA-covered provider, no training on your data | Patient falls, medication events, sentinel events, any report that names a patient. |
| Network | Allowed | BAA signed, with terms for the whole organization | BAA-covered provider, no training on your data | Multi-site groups and health systems that want one agreement and SSO. |
What we do under the BAA.
- Sign a BAA before patient data is loaded.
- Match our controls to the HIPAA Security Rule: access, audit logs, encryption.
- Run Lauren on a BAA-covered AI provider that cannot train on your data.
- Keep patient data out of analytics, email tools and this website.
- Tell you about a breach of unsecured PHI, as the BAA requires.
- Return or delete your data when the agreement ends.
What the facility still owns.
- Decide who gets access, and remove access when people leave.
- Train staff to report facts, not opinions, and to skip unneeded identifiers.
- Set retention periods that match your policy and state rules.
- Keep your own risk analysis current. A vendor BAA does not replace it.
- Ask your privacy officer or counsel before you decide.
HIPAA and incident reporting, answered.
Something we missed? Ask us, and a person answers.
Is an incident report protected health information?
Often, yes. A report is PHI when it has a patient's name, record number, dates of service or other identifiers, and a covered entity or business associate holds it. A report about an employee's needlestick or a broken guard rail may not be. Many reports mix both.
Does my facility need a BAA with an incident reporting vendor?
Yes, if the vendor handles PHI for you. HIPAA calls it a business associate and requires a written BAA. If staff will ever enter patient details, assume you need one.
Is IncidentKit HIPAA compliant?
There is no official HIPAA certification for software. Compliance is shared between the facility and the vendor. We offer a signed BAA, safeguards that map to the HIPAA Security Rule, and the paperwork your privacy officer needs. Review the controls.
Can I use the free plan for patient incidents?
No. The Open plan has no BAA, so keep patient data out of it. Use the Regulated plan for any patient incident.
How does the AI handle PHI?
On Regulated and Network, Lauren runs on an AI provider that signs a BAA and may not train on your data. Inputs and outputs go to the audit trail. AI-drafted fields stay marked until a person approves, and a named person signs every report.
What about the marketing website?
It is not built to receive PHI, so keep patient data out of every form here. Analytics run only after consent, and form fields are masked in session replay. See the privacy policy.
Who do I contact for the BAA?
Request the security packet or book a demo. We send the BAA with the quote and sign before any patient data is loaded.
Sources
- HHS: Business associates (45 CFR 160.103)
- HHS: Sample business associate agreement provisions
- HHS: The HIPAA Security Rule
- HHS: Guidance on HIPAA and cloud computing
This page is general information, not legal advice. Ask your privacy officer or counsel about your duties.
Start with a BAA.
We send the BAA with the quote and sign before patient data is loaded.