Skip to content
← All posts
Compliance · PracticeWide

The BAA question every practice should ask its lead tools

If a vendor touches patient phone numbers, names, or messages, you need a Business Associate Agreement. The big platforms will sign one — on the right plan, sometimes as a pricey add-on. The tools your agency bundles usually won't. Here's how to audit your stack.

A Business Associate Agreement (BAA) is the contract that lets a vendor legally handle protected health information (PHI) on your behalf. For a medical practice, it isn’t optional paperwork — it’s the line between a compliant vendor relationship and a reportable exposure.

Phone numbers and names are PHI

There’s a common misconception that PHI only means charts and diagnoses. In a practice context, a phone number tied to a person seeking treatment is identifiable health information. The moment a lead or call-tracking tool stores “this person called about a hair transplant,” it’s handling PHI.

The majors will sign — read the fine print

The picture has improved: as of mid-2026, the major platforms a practice is likely to be pitched will sign a BAA. But how they sign is where the details bite:

  • Call trackers typically offer it only on a dedicated healthcare plan — and those plans redact PII by default and restrict integrations that would send PHI to third parties. Responsible, but it constrains exactly the data flows your attribution reporting depends on.
  • Agency CRMs may gate compliance behind a paid add-on on top of a top-tier plan — in one prominent case, $297/month on top of a $497/month plan, with documentation stating the add-on can’t be cancelled, refunded, or downgraded once enabled.
  • Messaging and reputation platforms generally sign without drama, but they only cover the slice of the patient journey they touch. The booking tool, the spreadsheet, and the email inbox around them are still your liability.

Where the real exposure lives

The riskiest tools aren’t the name brands — they’re the pieces your web agency bundles: the form-to-email chatbot, the generic autoresponder, the shared spreadsheet of “leads this month.” Those move patient enquiries through infrastructure that will never sign a BAA, and the HIPAA liability sits with your practice, not with whoever sold you the stack.

There’s also a structural problem: every additional vendor that touches PHI is another BAA to negotiate, another security posture to audit, and another place a breach can start. Four tools means four agreements — or, more commonly, one agreement and three exposures nobody has noticed yet.

What “compliant by design” actually requires

A platform that handles practice leads responsibly should, at minimum:

  • Encrypt PHI at rest — phone numbers, names, and message contents stored encrypted, not in plain text.
  • Keep an append-only audit log — every access and change recorded, nothing silently editable.
  • Sign a BAA on every plan — not as an upsell, and stand behind it with real controls, not just a signature.
  • Minimize what it stores — for example, transcribing calls instead of warehousing raw audio.

PracticeWide was built for practices from the first commit: PHI encrypted at rest, an append-only audit trail, and a BAA included on every plan — one agreement covering the call, the message, the booking, and the payment, because they all live in one system. Audit your current stack with a single question per vendor: “Will you put your BAA terms in writing for the plan I’m actually on?” The answers are usually illuminating.

See how we handle security.

The $0 30-day loss audit

The next step is a count, not a contract.

For thirty days, the audit runs quietly on the calls, texts, and website enquiries you already get. Nothing you run changes. At the end: a one-page count of what got no answer and what it was likely worth in booked procedures. $0, no commitment, and a Business Associate Agreement signed before it touches anything.