Skip to content

Guide5 min read

How to check if an automation tool will sign a HIPAA BAA

Not every automation tool will sign a HIPAA business associate agreement. Here is how to check any vendor before you build.

A clinic asks us to send appointment reminders by text. Simple enough. Then someone asks the question that stops the project: is this HIPAA compliant?

The honest answer is that it depends less on the software than on a contract most people have never read. Here is how to get it right, and how to check any vendor in about ten minutes.

First, your reminder probably is protected health information

A common assumption is that a message only counts as protected health information if it contains a diagnosis. That is not how it works.

If a text message connects an identifiable person to a healthcare provider, it is generally treated as protected health information. “Your results are ready” sent from a named clinic does that. So does “Reminder: your follow-up is Thursday.” The message does not need to mention a condition. The link between the person and the provider is the sensitive part.

Once you accept that, the rule follows: every vendor whose systems touch that message needs a signed Business Associate Agreement with you.

What a BAA actually is

A Business Associate Agreement is a contract in which a vendor accepts legal responsibility for protecting the health information it handles on your behalf. It is not a feature. It is not a security certification. It is not a badge on a pricing page.

This distinction matters because plenty of vendors hold SOC 2 and ISO 27001 certifications, encrypt everything properly, and still will not sign a BAA. Those certifications describe how they run their business. A BAA is them accepting liability for your patients’ data. Many vendors are happy to do the first and unwilling to do the second.

If there is no signed BAA, the tool is not usable for protected health information, regardless of how secure it is.

This catches people out, because these are the tools most businesses reach for first.

Some widely used workflow platforms state in their own documentation that they do not sign BAAs. These are excellent products for other work. They are not an option for workflows that carry protected health information unless the vendor confirms otherwise in writing.

Vendor positions change, so check the current position for every tool you plan to use.

What does work

There are three practical routes.

Self-hosted n8n on AWS or Azure. n8n is a source-available automation platform you can run on your own infrastructure. Both AWS and Azure sign BAAs covering their hosting services, so when you self-host, the compliance boundary sits with a cloud provider that has accepted it. You get comparable capability with a compliance path you control.

Microsoft Power Automate. If the organisation already runs Microsoft 365, a BAA is typically already in place through that agreement and extends to Power Automate. For a business that is already Microsoft-based, this is often the shortest route.

Purpose-built healthcare vendors. For messaging specifically, several providers serve healthcare directly and will sign a BAA as standard. They cost more than a generic texting tool. That premium is the compliance.

One more worth knowing: some large communication platforms will sign a BAA, but only on specific higher tiers. The entry-level plan does not include it. Check which tier you are actually buying.

How to check any vendor in ten minutes

We learned this the hard way. On one project we found a marketing article and an AI summary both stating that a particular messaging vendor signed BAAs. We took it to the client. Then we read the vendor’s own acceptable use policy, which explicitly prohibited transmitting electronic protected health information through their service. Their support team confirmed it directly. The marketing article was simply wrong.

So here is the check, in order of reliability:

1. Read the acceptable use policy, not the marketing page. This is where vendors state what you may not do with their product. If it prohibits health information, nothing on the pricing page overrides that.

2. Search the vendor’s own site for “BAA” or “business associate”. A vendor that signs them says so plainly, usually with a request form. Silence is an answer.

3. Ask support in writing. Not a phone call. Email, so you have the response on record. Ask directly: “Will you sign a Business Associate Agreement for our account?”

4. Confirm which plan includes it. BAAs are frequently restricted to higher tiers. Confirm it applies to the plan you intend to buy.

5. Ignore third-party listicles and AI summaries entirely. This is where we went wrong. Comparison articles are often outdated, occasionally incorrect, and never binding. The vendor’s own contract is the only source that counts.

Map every vendor in the chain, not just the obvious one

A single automated reminder might involve four or five vendors: the system holding patient records, the automation platform, the messaging provider, the hosting service, and possibly an AI service generating the message text.

Every one of them that touches the data needs a BAA. Buyers usually check the messaging tool and forget the automation platform sitting in the middle, which is often the one that fails.

Draw the chain out before you buy anything. List each vendor. Confirm each one individually.

When compliance changes the architecture

Sometimes the answer is not swapping one tool for another. It is designing so that fewer systems ever see the sensitive data.

If a message only needs to say “You have an update, please log in to view it,” then the message itself carries far less. The detail stays inside a system that is already covered. This is not a loophole — you still need a BAA with anything handling the underlying records — but it reduces how many vendors sit inside your compliance boundary, which reduces both cost and risk.

Data minimisation is a genuine architectural tool, not just a policy phrase.

Takeaways

  • A reminder does not need to mention a diagnosis to be protected health information. Linking a person to a provider is enough.
  • A BAA is a contract accepting liability. It is not a certification, and security badges do not replace it.
  • Some popular workflow tools do not sign BAAs. Self-hosted n8n on AWS or Azure, Microsoft Power Automate, or a healthcare-specific vendor are practical routes to check.
  • Read the acceptable use policy, not the marketing page. It is where the real restriction lives.
  • Get the answer in writing from the vendor, and confirm it applies to your specific plan.
  • Map every vendor in the chain. The automation platform in the middle is the one people forget.
  • Vendor terms change. Re-verify before you sign, not after.

If you are planning a healthcare automation project, check the vendor chain before you commit. It is far easier than discovering the problem after launch.

This article is general information, not legal advice. Confirm your obligations with qualified counsel.

This article is general information, not legal or professional advice. Vendor terms and platform rules change, so confirm the current position with the vendor before you act on it. Last reviewed September 2026.

The project behind this article

More insights

How-to6 min read

Why your TikTok API posts publish as private

TikTok forces unaudited apps to post privately. Here is why it happens, and the second API that lets owned accounts post publicly.

TikTok APISocial Media AutomationAPI Integration

Tell us what is slowing your business down.