Do you sign a Business Associate Agreement (BAA) for our clinic?
No. MiOpsAI does not sign Business Associate Agreements (BAAs) today. Because we do not touch protected health information, no BAA is required for the workflows we support.
Under HIPAA, a Business Associate Agreement is required between a covered entity (your clinic) and a vendor when the vendor handles PHI on your behalf. Since MiOpsAI is explicitly architected to stay outside your EHR and outside any workflow that involves PHI, we do not meet the definition of a Business Associate for those workflows.
What this means in practice:
- PHI-handling vendors still need BAAs. Your EHR vendor (Athena, eClinicalWorks, etc.), your HIPAA-compliant email provider (Paubox, Google Workspace with BAA, Microsoft 365 with BAA), your fax provider, your billing platform, and your lab connections all need BAAs. Those relationships are unchanged.
- MiOpsAI vendors work like your marketing agency does. Marketing platforms (Mailchimp, HubSpot Marketing, social schedulers) generally do not sign BAAs either, and they operate on the same principle: keep PHI out.
- The line for your team to hold: Anything sent to a MiOpsAI-connected email address should be non-PHI marketing content (schedule questions, program inquiries, general FAQs). Anything clinical goes through your EHR patient portal or your HIPAA-compliant channel.
If you have a workflow where non-PHI and PHI blur together (say, an intake form that asks health history questions), we help you route those to the appropriate system during setup. The intake form sits on your EHR side or a HIPAA-covered form vendor; only the initial non-PHI contact goes through Marcus.
Some clinics use MiOpsAI for everything up to consultation booking, then hand off entirely to their HIPAA-compliant stack for clinical intake. See the Men's Healthcare page.
Ready to see MiOpsAI in action?
Request access and we’ll walk you through how the platform solves your specific workflow.
Request Access →