NOVRASCALE
PlatformPricing
Client LoginBook a Free Call
NOVRASCALE

Legal

Business Associate Agreement Policy

Last updated: June 20, 2026

NovraScale LLC does not sign Business Associate Agreements (BAAs) and is not a Business Associate under HIPAA. This page explains why, and where the line falls between the work NovraScale does and the systems healthcare clients keep on their own HIPAA-compliant infrastructure.

1. The short version

A BAA is required whenever a vendor creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a Covered Entity. NovraScale does none of those things. The websites and lead-capture systems we build for healthcare clients are designed deliberately so that no PHI ever lands in any system we operate or host.

2. What NovraScale handles

For a healthcare client, NovraScale typically operates these surfaces. None of them are designed to accept or store PHI:

  • The public marketing website (homepage, about, services, location pages)
  • A non-clinical contact form limited to name, email, phone, and a short free-text message — no medical history, no symptom intake, no insurance details
  • Local SEO setup, Google Business Profile, and review-generation outreach (which collects star ratings and short text reviews, not health information)
  • A non-clinical CRM that tracks marketing leads through the inquiry → first-contact → consultation stages — again, no PHI fields
  • Hosting, security patches, SSL renewals, and uptime monitoring for the marketing site

If a visitor accidentally pastes something that would qualify as PHI into a free-text marketing field, our standard practice is to redact and notify the client. We do not retain the original.

3. What your HIPAA-compliant systems handle

Everything clinical routes through systems you (the Covered Entity) own and operate, under your own BAAs with those vendors. Typical examples:

  • Patient intake forms that ask about symptoms, medication, or insurance — hosted in your EHR or a HIPAA-compliant intake platform (e.g. Jane, SimplePractice, IntakeQ, Healthie)
  • Appointment scheduling that ties a patient identity to a clinical visit type — your EHR or a BAA-covered scheduler
  • Patient communication — email, SMS, or portal messaging — through a BAA-covered platform (e.g. Spruce, OhMD, your EHR’s portal)
  • Insurance verification, billing, claims, telehealth video
  • Anything that creates, receives, maintains, or transmits PHI

The marketing site we run links out to those systems — for example, the “Book an Appointment” button on your homepage opens your HIPAA-compliant scheduler. The handoff is intentional: PHI starts the moment a real patient identity meets clinical data, and that moment happens on your infrastructure, not ours.

4. Why we draw the line here

A BAA is not a checkbox — it is a binding agreement that puts real penalties in play and requires the signing vendor to operate under the HIPAA Security Rule. The honest answer for most marketing engagements is that signing one isn’t necessary because the vendor never touches PHI. Pretending otherwise would mean either operating under requirements we don’t meet, or quietly accepting risk neither side has priced in. Neither is acceptable.

5. What this means for healthcare prospects

If you’re a healthcare practice evaluating NovraScale and your compliance officer asks whether we sign a BAA, the answer is no — and the reason is the structural one above, not a reluctance to engage with HIPAA. We work with healthcare practices regularly and design every engagement to keep PHI cleanly on your side of the line.

If your situation requires PHI to land on the marketing site (for example, a clinical assessment running on the public domain rather than a patient portal), we are not the right vendor. We’ll tell you that on the discovery call.

6. Compliance-adjacent reading

If you want background on how this plays out in practice, the HIPAA website violations guide covers the common mistakes practice marketing sites make, and the Google Analytics HIPAA violation explainer covers a specific tracking trap we avoid by default. Both walk through the same line this page draws — what is and isn’t PHI on a marketing surface.

7. Questions

Compliance questions or requests for clarification: legal@novrascale.com.

This page describes NovraScale’s stance on Business Associate Agreements and is provided for informational purposes only. It is not legal advice. Healthcare practices should consult their own counsel or compliance officer about HIPAA obligations specific to their organization.

© 2026 NovraScale LLC