HIPAA and Business Associate Agreements
Last updated August 2026. SlayTab is not a HIPAA business associate and does not accept protected health information.
SlayTab does not currently sign Business Associate Agreements, and must not be used to store or process protected health information (PHI).
A Business Associate Agreement is a contract required by the US Health Insurance Portability and Accountability Act when a vendor handles PHI on behalf of a covered entity. Signing one is a binding commitment to a specific set of safeguards. We would rather tell you plainly that we do not meet them yet than sign and leave you exposed.
Why not
A compliant BAA would require all of the following. Today, SlayTab does not have them:
- Downstream BAAs with every sub-processor that could touch PHI. The AI assistant sends content to a model provider under a standard commercial agreement, not one covering PHI.
- Encryption of PHI at rest under our control, beyond what the hosting platform provides.
- Audit logging of access to individual records, retained for six years.
- Formal access controls, workforce training and a documented risk analysis.
- Breach notification procedures meeting the HIPAA Breach Notification Rule specifically.
What this means for you
- Do not upload medical records, clinical notes, patient identifiers, insurance claims or anything else that constitutes PHI. This is also stated in the Acceptable Use Policy.
- If you are a covered entity or a business associate, SlayTab is suitable for your general working documents and links — not for anything patient-identifiable.
- Using SlayTab for PHI without a BAA in place would put you in breach of HIPAA, not just us. That is the risk we are trying to spare you.
Other regimes
The same reasoning applies to other regulated categories. SlayTab is not certified for PCI-DSS cardholder data, and is not designed for classified or government-restricted material. General business use under the Indian DPDP Act and the GDPR is supported — see the Data Processing Agreement.
If you need one
We would like to support healthcare customers properly, and the gaps above are engineering work rather than anything fundamental. If a BAA is a requirement for you, write to legal@slaytab.com describing what you need. We will tell you honestly whether and when we could get there, rather than sign something we cannot honour.