Pharity

Legal

Legal

Business Associate Agreement

Required for every clinic + pharmacy that handles PHI through Pharity.

BAAs are executed via BoldSign during onboarding

The binding BAA between Pharity and your organization is the document signed via BoldSign as part of clinic or pharmacy onboarding. This page describes the standard BAA terms and links to your executed copy from your admin panel.

What the BAA covers

Pharity is a HIPAA Business Associate to every clinic and pharmacy on the platform. The mutual BAA between Pharity and your organization (the Covered Entity) governs how Protected Health Information (PHI) is created, received, maintained, or transmitted on your behalf.

Standard terms

  • Pharity uses PHI only as permitted by HIPAA and the executed agreement, to operate the platform on your behalf, not for any other purpose
  • Pharity implements administrative, physical, and technical safeguards per HIPAA Security Rule §164.308–.312
  • All PHI is encrypted at rest (AES-256 via DigitalOcean Managed Postgres) and in transit (TLS 1.3)
  • Append-only audit log via Postgres trigger, UPDATE and DELETE on audit_logs are rejected at the database level
  • Audit records retained six years under the executed BAA, matching the documentation-retention period of 45 CFR §164.316(b)(2)(i) — HIPAA sets no retention period for the audit log itself, so this is Pharity's commitment rather than a regulatory floor
  • Pharity notifies you of any breach of unsecured PHI per HIPAA §164.410 within 60 days (typically much sooner)
  • Pharity will not subcontract PHI handling to any vendor without a written BAA in place (subprocessor list maintained at /legal/privacy)
  • On termination, Pharity returns or destroys PHI per the executed BAA's terms

Subprocessors and their required BAAs

Pharity does not handle PHI in production until a signed BAA is in place with each subprocessor below. None of these agreements are executed yet, so this list is the requirement we must satisfy before launch, not a description of agreements already signed.

  • DigitalOcean, hosting + Managed Postgres (Standard Support tier, BAA required)
  • AWS, SES for email delivery (BAA via AWS Artifact, required)
  • Twilio, SMS delivery (BAA required)
  • BoldSign, e-signature workflow (BAA required)
  • Sentry, error monitoring (HIPAA tier, BAA required)
  • Daily.co or Zoom for Healthcare, telehealth video (BAA required when telehealth ships)

What Pharity does NOT do

  • Sell, monetize, or aggregate PHI for any purpose
  • Share PHI with any party that hasn't signed a BAA
  • Use PHI for product analytics or marketing
  • Store PHI in payment-processor metadata (Stripe; payment-processing exemption applies)

Find your executed BAA

Once activated, your executed BAA lives in your admin panel under Settings → Compliance (coming with C4). Before that ships, request a copy from admin@pharity.com.

Need a custom BAA?

Pharity's standard BAA mirrors the HHS sample BAA. We accommodate redlines from clinic counsel within reason, email legal@pharity.com and we'll route it.