Skip to main content

RevDesk’s HIPAA posture

If your business handles Protected Health Information (PHI), you sign one Business Associate Agreement, and it is with RevDesk. We’ve already executed BAAs with the subprocessors in our stack that require them. You don’t need to chase individual provider BAAs; we handle that upstream. Once your BAA is on file, we set hipaa_enabled on your workspace. That flag activates real runtime controls (described below), not just a contractual posture.

Our subprocessor BAA status

We use several third-party services to deliver RevDesk. Here’s where each one stands today. This is informational only; you don’t act on this list. If you need documentation of any individual subprocessor BAA for your own compliance audit, email compliance@revdesk.com and we’ll provide it.

How to request a BAA from RevDesk

  1. Email support@revdesk.com with subject “HIPAA BAA Request”.
  2. Include:
    • Your legal entity name
    • The workspace or team that will handle PHI
    • Your primary compliance contact (name + email)
  3. What happens next:
    • We respond within 2 business days with our standard BAA.
    • For customers who can sign as-is: same-day workspace activation once the BAA is countersigned.
    • For customers needing legal markup: we route through our counsel; typical close in 5–10 business days.
  4. After signing: We record execution on your workspace (baaSignedAt) and flip hipaa_enabled = true. The runtime controls below take effect immediately.
If you’re a partner with consistent healthcare volume, ask us about platform-wide HIPAA, a single agreement that covers your entire downstream customer base. Details on the HIPAA add-on page.

What hipaa_enabled does

A workspace with hipaa_enabled: true enforces the following at runtime:
  1. Voice AI provider HIPAA mode: every AI assistant we create on your behalf is provisioned with the upstream provider’s HIPAA setting enabled, routing inference through BAA-covered paths only.
  2. Recording disclosure locked on: you cannot save a custom assistant greeting that omits the “this call is recorded” disclosure. Our default greetings include it in 40+ languages.
  3. Recording retention capped: recordingRetentionDays cannot exceed 30, and recordingEnabled cannot be turned off.
  4. LLM routing prefers BAA-covered model providers; fallback to non-BAA providers is blocked.
  5. Integration installs gated: third-party apps that handle PHI but don’t have a subprocessor BAA on file (e.g., certain CRM and messaging integrations) are blocked from being installed on the workspace. The full list is shown in the integrations directory with a HIPAA notice.
  6. Audit log: every compliance-relevant mutation (flag flips, BAA recording, retention changes, blocked installs) is recorded.
Flipping the flag is reversible, and we don’t mass-delete historical data. The flag itself can only be enabled when baaSignedAt is set, which requires a fully executed BAA on our side.

Security baseline RevDesk always provides

Regardless of whether hipaa_enabled is set:
  • TLS 1.3 in transit, AES-256 at rest.
  • Encrypted credential storage (REVDESK_ENCRYPTION_KEY).
  • Row-level access control: every API query runs through buildOwnershipFilter which scopes results to the authenticated principal’s org/team visibility.
  • Audit log on every mutation via tRPC middleware.
  • Breach notification procedures per § 164.410.
Missing something your compliance officer needs? Email compliance@revdesk.com.