Straight talk on HIPAA — and a Business Associate Agreement ready when you need one.

Compliance is a legal obligation your organization carries — not something a vendor can sell you a certificate for. Here's what we actually provide, and what to ask any IT vendor handling PHI.

"HIPAA certified" isn't a real credential. Here's what is.

No government body or private credentialing organization issues an official "HIPAA certification" to vendors. HIPAA compliance is a legal responsibility your organization holds — third-party providers support it through signed agreements and documented safeguards, not a badge.

Not a Real Thing

"HIPAA Certified" Marketing Claims

Phrases like "HIPAA certified software" or "certified HIPAA compliant" usually mean a vendor completed a self-assessment — not that any government agency reviewed and approved them.

What We Actually Offer

A Signed BAA & Documented Safeguards

A Business Associate Agreement on request, plus specific, documented controls for access, encryption, logging, and physical security — the things that actually support your compliance.

What we put in place as your Business Associate

When we provide managed IT, hardware, network infrastructure, or security systems to a healthcare client, we operate as a Business Associate under HIPAA — with obligations that follow, whether or not a BAA has been signed yet. Here's what that covers.

Why on-premise infrastructure helps

Much of our work keeps your systems on hardware you own, on-site — which changes the compliance conversation in your favor.

AspectOn-Premise, ArcAngel-ManagedCloud-Only Vendor
Physical ControlYou own the hardware and facility; we manage it locallyVendor controls the data center; you rely on their security
Data LocationStays on-site — no cloud transmissionTravels to vendor infrastructure
Audit AccessYou can inspect systems in personLimited to the vendor's own audit reports
Vendor Lock-InLower risk — you can migrate providersHigher effort to export and migrate data
Control CustomizationConfigured for your specific requirementsGenerally one-size-fits-all policy

Ask for the BAA before you ask anything else.

A BAA is required by law for any vendor handling PHI on your behalf — regardless of how much you trust them. We keep a BAA ready to sign, and we'd rather you ask for it up front than discover the gap later.

Request Our BAA
Our Part

Supporting Your Compliance

We implement and document the technical, physical, and administrative safeguards for the systems we manage, sign a BAA, and notify you promptly of any incident.

Your Part

Your Legal Obligation

HIPAA compliance is your organization's legal responsibility. You determine what PHI can be discussed where, train your staff, and notify HHS and affected individuals if required. We can advise, but we can't carry that obligation for you.

This page is intended for general information about how ArcAngel Technical Services supports HIPAA-covered clients and does not constitute legal advice. HIPAA compliance is a legal obligation specific to your organization — consult qualified legal counsel to confirm what applies to your circumstances. For more, see our FAQ.

Working with PHI? Let's talk about a BAA.

We'll walk through what our services cover, what a BAA includes, and how our on-premise approach fits your compliance program.

Request a BAA