Your Compliance Documents, On Demand
Download the legal and compliance documentation your organization needs to onboard EDiFi with confidence. BAA, HIPAA overview, and data agreements, all available immediately.
Four Documents. One Request.
Fill out a brief form and we'll send the documents directly to your inbox. No sales call required to access compliance materials.
Our standard HIPAA Business Associate Agreement, reviewed by healthcare compliance attorneys. Establishes the legal framework for how we handle your protected health information as a business associate under HIPAA.
A detailed technical overview of EDiFi's security architecture: encryption standards, access controls, audit logging, infrastructure providers, and incident response procedures. Written for IT teams and security reviewers.
A plain language summary of how EDiFi supports HIPAA technical, administrative, and physical safeguard requirements. Designed for practice administrators, compliance officers, and DSO procurement teams who need a one page reference.
Our standard Data Processing Agreement (DPA) covering data controller and processor responsibilities, sub-processor chains, data residency, retention schedules, and cross border transfer protections for enterprise and DSO customers.
What Our BAA Covers
Our BAA is reviewed annually by healthcare compliance attorneys and updated to reflect current HIPAA regulatory guidance. It is included at no additional cost with every EDiFi subscription.
- PHI permitted uses and disclosure restrictions
- Breach notification within 72 hours of discovery
- Subcontractor and sub-processor chain of trust
- Access to your PHI upon request within 30 days
- Data return or destruction upon contract termination
- Annual compliance review and agreement update cycle
- Mutual indemnification for compliance failures
How BAA Signing Works
Questions about the BAA or specific compliance requirements? Contact our compliance team →
Need Something Specific?
If your organization requires custom compliance documentation, SOC 2 bridge letters, or a security questionnaire response, contact our team directly.