Legal
Last updated: June 20, 2026
NovraScale LLC does not sign Business Associate Agreements (BAAs) and is not a Business Associate under HIPAA. This page explains why, and where the line falls between the work NovraScale does and the systems healthcare clients keep on their own HIPAA-compliant infrastructure.
A BAA is required whenever a vendor creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a Covered Entity. NovraScale does none of those things. The websites and lead-capture systems we build for healthcare clients are designed deliberately so that no PHI ever lands in any system we operate or host.
For a healthcare client, NovraScale typically operates these surfaces. None of them are designed to accept or store PHI:
If a visitor accidentally pastes something that would qualify as PHI into a free-text marketing field, our standard practice is to redact and notify the client. We do not retain the original.
Everything clinical routes through systems you (the Covered Entity) own and operate, under your own BAAs with those vendors. Typical examples:
The marketing site we run links out to those systems — for example, the “Book an Appointment” button on your homepage opens your HIPAA-compliant scheduler. The handoff is intentional: PHI starts the moment a real patient identity meets clinical data, and that moment happens on your infrastructure, not ours.
A BAA is not a checkbox — it is a binding agreement that puts real penalties in play and requires the signing vendor to operate under the HIPAA Security Rule. The honest answer for most marketing engagements is that signing one isn’t necessary because the vendor never touches PHI. Pretending otherwise would mean either operating under requirements we don’t meet, or quietly accepting risk neither side has priced in. Neither is acceptable.
If you’re a healthcare practice evaluating NovraScale and your compliance officer asks whether we sign a BAA, the answer is no — and the reason is the structural one above, not a reluctance to engage with HIPAA. We work with healthcare practices regularly and design every engagement to keep PHI cleanly on your side of the line.
If your situation requires PHI to land on the marketing site (for example, a clinical assessment running on the public domain rather than a patient portal), we are not the right vendor. We’ll tell you that on the discovery call.
If you want background on how this plays out in practice, the HIPAA website violations guide covers the common mistakes practice marketing sites make, and the Google Analytics HIPAA violation explainer covers a specific tracking trap we avoid by default. Both walk through the same line this page draws — what is and isn’t PHI on a marketing surface.
Compliance questions or requests for clarification: legal@novrascale.com.
This page describes NovraScale’s stance on Business Associate Agreements and is provided for informational purposes only. It is not legal advice. Healthcare practices should consult their own counsel or compliance officer about HIPAA obligations specific to their organization.