Every Covered Entity and upstream Business Associate signs a BAA with ClaimworksIQ before PHI moves. This page says what that agreement commits us to, and the signed document is available on request.
Under HIPAA, a Covered Entity (a healthcare provider, health plan, or healthcare clearinghouse) must execute a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits Protected Health Information ("PHI") on its behalf. When attorneys handle PHI obtained in litigation under HIPAA's permitted-disclosure provisions, they typically extend equivalent contractual protections to their vendors. ClaimworksIQ is a Business Associate to its attorney and physician customers, and we operate under those rules.
Our BAA permits ClaimworksIQ to use and disclose PHI only as necessary to:
Any use outside that scope requires either your written authorization or an exception expressly permitted by HIPAA.
The agreement is explicit about what we will never do with PHI:
The BAA binds us to administrative, physical, and technical safeguards consistent with the HIPAA Security Rule (45 CFR Part 164, Subpart C). In practice that includes:
The full controls inventory is on our security page.
Where ClaimworksIQ engages a subcontractor that may access PHI, for example cloud infrastructure or AI inference providers, that subcontractor is required to sign a downstream BAA with equivalent protections before any PHI flows. We maintain an internal list of PHI-touching subcontractors and provide a current categorical summary to customers under NDA on request.
If ClaimworksIQ discovers a breach of unsecured PHI as defined under HIPAA, we will notify the affected customer without unreasonable delay, and in no case later than the timelines required by 45 CFR § 164.410 (within 60 days of discovery, and typically much sooner). Notice will include the information required by HIPAA to enable the Covered Entity to fulfill its own notification obligations: the nature of the incident, the PHI involved, the parties affected, mitigation taken, and contacts for follow-up.
Routine, unsuccessful security events (port scans, blocked authentication attempts) are tracked internally and summarized on request rather than reported individually.
The BAA preserves the rights HIPAA grants to individuals: access to their PHI (§ 164.524), amendment requests (§ 164.526), and accounting of disclosures (§ 164.528). Patients direct those requests to the Covered Entity that holds the relationship with them; ClaimworksIQ supports the Covered Entity in responding, within reasonable timeframes, by producing the information in our systems.
We will make our internal practices, books, and records relating to PHI available to the Secretary of Health and Human Services for purposes of determining HIPAA compliance, and will cooperate with reasonable customer audit requests, subject to confidentiality protections.
When your agreement with ClaimworksIQ ends, you have a defined export window to retrieve Customer Data via our in-product tools. After that window, PHI is returned or destroyed in accordance with the BAA and our retention configuration. Where return or destruction is infeasible (for example, lawful backup retention), the BAA's protections continue to apply until that limitation no longer applies.
The BAA is coextensive with the underlying service agreement. Provisions that by their nature should survive termination (confidentiality, indemnification, audit cooperation, breach notification for incidents occurring during the term, return-or-destruction of PHI) survive termination.
Request a signed BAA by emailing security@claimworksiq.com with your firm or practice name and a signatory contact. For enterprise customers, the BAA is incorporated as an exhibit to the master services agreement.