Business Associate Agreement
Last updated: September 11, 2026
Three Gates processes protected health information on behalf of healthcare organizations, which makes us a business associate under HIPAA. Here is how that works with us.
We sign before anything moves
No PHI reaches the platform until a Business Associate Agreement is signed. That includes design partner engagements.
Your paper or ours
Most healthcare organizations have a standard BAA and prefer to use it. We will review and sign yours, or send you our template, which follows the sample provisions HHS publishes.
What we commit to
Using PHI only to provide the contracted service, for our own administration where HIPAA allows it, or when the law requires it. Keeping the safeguards the HIPAA Security Rule requires of a business associate. Passing the same obligations to any vendor that handles PHI for us. Reporting any impermissible use or disclosure, including a breach of unsecured PHI, without unreasonable delay and within ten business days of discovery, with the information you need to meet your own notification duties. Supporting access, amendment, and accounting requests if we ever hold PHI in a designated record set; today we do not. Making our records available to HHS if asked. Returning or destroying PHI when the engagement ends, or continuing to protect anything that cannot be returned.
What a BAA does not do
It does not make us a healthcare provider, and it does not create obligations to patients directly. Patients exercise their rights with their provider.
The signed agreement is what counts
This page describes it. If the two ever differ, the signed agreement governs.
Request the template or send us yours
Emaillegal@threegates.ai.