โ„น๏ธ

Please note: Complern is an early-stage platform. Our BAA documentation is currently being prepared with legal counsel. We do not process identifiable PHI until a BAA is in place. Contact us to discuss your timeline and what compliance documentation we can provide today.

HIPAA Compliance Roadmap

HIPAA BAA:
Our Approach & Roadmap

Complern executes a HIPAA-compliant Business Associate Agreement with every hospital and health system customer. Here's what that means, what it covers, and how to request yours.

Request a BAA View Security Docs
Understanding the BAA

What is a Business Associate Agreement?

A BAA is a required contract under HIPAA between your hospital (the Covered Entity) and any vendor that may create, receive, maintain, or transmit Protected Health Information (PHI) on your behalf. Here's how we are approaching this as an early-stage platform.

๐Ÿฅ Your hospital is the Covered Entity

As a hospital or health system, you are a HIPAA Covered Entity subject to the full requirements of the Privacy and Security Rules. Any vendor you share PHI with must be bound by a BAA.

๐Ÿค Complern is your Business Associate

When your staff complete compliance training on Complern, their identities and training records may be associated with PHI access roles. This makes Complern a Business Associate requiring a BAA before any PHI flows.

โš–๏ธ What the BAA obligates Complern to do

Safeguard PHI with appropriate technical, physical, and administrative safeguards. Report breaches within 60 days. Restrict subcontractor access. Return or destroy PHI upon contract termination.

โœ… BAA protects your hospital, not just us

A signed BAA will give your compliance team documented evidence that your relationship with Complern is HIPAA-accountable. We are committed to having this in place before any PHI is handled.

What's Covered

Key terms in Complern's BAA

These are the core provisions we are building into our BAA. Our legal team is preparing the full agreement, which will cover all material HIPAA requirements before any PHI is processed.

โœ“ Included

Permitted Uses of PHI

Complern may use PHI only to provide compliance training services described in your subscription and as required by law. No marketing, analytics, or secondary use.

โœ“ Included

Safeguards Obligation

Implementation and maintenance of technical, physical, and administrative safeguards meeting or exceeding HIPAA Security Rule standards.

โœ“ Included

Breach Notification

Notification to your designated Privacy Officer of any confirmed or suspected breach of PHI within 60 calendar days of discovery, per 45 CFR ยง164.410.

โœ“ Included

Subcontractor BAAs

All sub-processors with PHI access are bound by BAAs equivalent to or more stringent than Complern's standard BAA terms.

โœ“ Included

Individual Rights Support

Complern will cooperate in fulfilling patient rights requests โ€” access, amendment, and accounting of disclosures โ€” as they relate to data held by Complern.

โœ“ Included

Termination & Return of PHI

Upon contract termination, Complern will return or securely destroy all PHI held within 90 days, with written certification of destruction provided on request.

Process

Our planned BAA process

Complern's BAA process is currently being finalised with legal counsel. Here is how it will work when ready โ€” reach out now if you are evaluating us for a deployment involving PHI.

1

Request via contact form or account rep

Submit a BAA request through our contact page or notify your Complern account representative. Include your organisation name and legal entity name.

2

Review the standard BAA

Our legal team sends a DocuSign envelope with Complern's standard BAA. Most hospital legal teams find our terms acceptable without modification. Typical review time: 3โ€“5 business days.

3

Negotiate custom terms if needed

If your legal team requires modifications, we work through a single redline cycle. Enterprise customers with custom agreements can attach their own BAA as an exhibit for our CPO to countersign.

4

Electronic countersignature

Once legal review is complete on both sides, Complern's authorised signatory countersigns. Both parties receive an executed copy. The BAA will be linked to your subscription.

5

PHI processing begins

With a fully executed BAA on file, Complern can begin processing identifiable workforce training data. Your Compliance Officer receives a copy for your policy evidence files.

Evaluating Complern for a PHI deployment?

Let's discuss your timeline and compliance requirements. We'll be transparent about where our BAA documentation currently stands.

Discuss BAA Requirements