Free Tool: HIPAA/BAA Readiness Checklist
The HIPAA/BAA readiness checklist is a free, browser-side self-assessment on the developer tools hub. Mark each of the five tenant-owned steps you already have covered, and the panel scores your readiness in plain language and links each open item to the docs page that configures it — no account required. Everything on the page is advisory: HIPAA posture is tenant-owned — you attest whether Protected Health Information (PHI) is in scope and configure the controls, and the checklist only reports the coverage you self-attest.What the checklist walks
The checklist covers the five steps that make up a HIPAA-ready posture on Orbit:- PHI-scope attestation — declare whether PHI enters your traffic.
The attestation starts (or relaxes) the BAA lifecycle —
not_requiredis the default until you attest otherwise, and flipping PHI into scope moves the lifecycle to pending so the execute step opens without a separate call (the BAA flow). - BAA execution — a workspace owner signs the Business Associate
Agreement: template preview, typed-name e-signature, a stored executed
PDF, and a one-year term with re-execution opening 60 days before
expiry. Only
executedsatisfies the HIPAA-enable and PHI-send gates (the BAA flow). - HIPAA mode toggle — the workspace owner turns HIPAA mode on per organization: opt-in, off by default, BAA-gated, with disable requiring re-authentication. The toggle activates (or relaxes) the enhanced control set (HIPAA compliance controls, and the end-to-end sequence in the HIPAA posture guide).
- Role-based PHI access — message-content and PHI audit-log reads are restricted to designated roles: owners and admins read content, developers and viewers do not touch the PHI access log, billing roles read neither. Map each surface to the people in your workspace before go-live (HIPAA compliance controls, sequenced in the HIPAA onboarding guide).
- Minimum-necessary audit — every PHI read is logged with a reason code so you can prove minimum-necessary access, and the rolling audit row lines up with the PHI-channel matrix that keeps PHI out of channels it should never use (HIPAA compliance controls, with the downloadable evidence in audit log export).
The steps are a summary layer over the deep guides — HIPAA compliance
controls and the BAA flow are the
authoritative references, and the tool links them from each item.
Tenant-owned framing
When to use it
Run the checklist as the pre-go-live self-attestation before you touch the BAA gate on a live workspace: it names the five items your compliance owner must already have covered — PHI scope attested, BAA executed, HIPAA mode toggled, PHI access restricted to the right roles, and the minimum-necessary audit row readable — so the first production send does not stall at the send-time gate with422 HIPAA_BAA_REQUIRED. Re-run it
after the BAA renewal reminder, a role change, or a new channel launch; a
fresh self-check takes under a minute.
Relation to the four-gate BAA state machine
The checklist mirrors the BAA state machine documented on the BAA page:not_required (the default), pending (PHI in
scope, not yet signed), executed (signed and inside the one-year term —
the only state that satisfies the gates), and expired (term elapsed,
gates close again until re-execution; the window opens 60 days early). The
step order on the tool follows the same lifecycle: attestation opens it,
execution satisfies it, and the remaining steps configure the controls the
organization runs while the agreement is live. See the BAA
flow for the full state table and gate verdicts.
See also
- Business Associate Agreement (BAA) flow — attestation states, e-sign, one-year term, re-execution window
- HIPAA compliance controls — the opt-in toggle, the roles-versus-surface matrix, the PHI audit row
- HIPAA posture guide — assemble the whole posture end to end for an auditor or buyer
- HIPAA onboarding — the ordered sequence from BAA to audit-ready
- Audit log export — queued, tamper-evident export of the audit trail for evidence requests