Resources · Healthcare
Decide BAA and vendor access before anyone gets the dump.
PHI, role, what the party will see, BAA status, access type. A path you can print. Not legal advice. Not an EHR.
“Legal is looking at the BAA” is not an access model
Teams grant staging databases, support exports, and Copilot indexes while the agreement is still in review. A party that will see PHI is not onboarded with a handshake. This tree forces the order: classify, paper, then minimum necessary. Dedicated HealthTech delivery still lives at Maxiom Labs. Feature-level mapping is the HIPAA minimum-necessary mapper.
Who this is for
- Healthcare product, engineering, and vendor-management leads asked to open a repo or an environment this week.
- InfoSec partners who need a one-pager before production credentials leave the building.
- Teams pairing software delivery with Maxiom Labs and needing the BAA conversation in writing first.
What you get
- A path: classify first, wait for BAA, flow-down for subcontractors, keep PHI out of AI tools, or NDA-only.
- Plain-language next steps, not a fake HIPAA certification.
- Pointers to HIPAA software development and compliance engineering when the control has to live in the product.
Frequently asked questions
What is the BAA / vendor access decision tree?
A six-step path for regulated and healthcare teams deciding whether a vendor, engineer, or AI tool may see PHI, and whether a BAA must exist before access. Export a one-pager. It is not legal advice.
Is this legal advice or a HIPAA designation?
Neither. Counsel and your privacy officer own the determination. This is an engineering and vendor-onboarding aid so you stop granting production dumps while legal “is looking at it.”
Do I upload patient data?
No. Describe categories and access. Never paste records, exports, or production logs. Client data stays in your environment.
Who is this for?
Healthcare product, engineering, InfoSec, and vendor-management leads. Also useful when Maxiom (or any engineer) is the party being asked for repo or environment access.
How does this relate to the HIPAA mapper?
The minimum-necessary mapper is feature-level: data classes versus logs, prompts, analytics, vendors. This tree is the access-path question: BAA first, classify first, or NDA-only. Use both. Neither is an EHR.
What about Maxiom Labs?
Clinical product engineering and dedicated HealthTech live at Maxiom Labs. This tree will point there when the work is the product, not a vendor checkbox. HIPAA-aligned delivery on this site is HIPAA software development.
Can Copilot or an MCP server be in the path?
Yes, and that is often the failure. Indexes, prompts, and tool-servers are disclosure surfaces. A BAA on a different vendor does not cover this tool. Pair with the MCP exposure checklist when agents are the access path.
Why a work email?
Same gate as the other Resources tools. Unlock, walk the tree, export. No patient file leaves the browser because none is collected.
What if we are a subcontractor?
PHI access usually needs a written flow-down that matches the upstream BAA. “Our customer said it was fine” is not the chain. The tree will say so.
Launch
Launch the decision tree
Sign in with a work email, then run the tool in this page. Client code stays in your environment.
Work email to continue
Unlock BAA / vendor access decision tree
Same gate as the AI Code Risk Checklist. Unlock once per browser session to use or export. Client code stays in your environment: this tool never asks for a repository.
- Questionnaire only: no source upload
- Print or save a one-pager from the browser
- Unlocks the other Resources tools in this session
