Coffee is designed to support HIPAA-compliant workflows. If your organization needs to store, process, or transmit protected health information (PHI), we can execute a Business Associate Agreement (BAA) with you.
Who can sign a BAA
BAAs are available to any Coffee customer, regardless of plan. Contact us to get started before you enter any PHI into your workspace.
How to request a BAA
Email [email protected] with the subject line "BAA request."
Include your workspace name and the legal entity that will sign the agreement.
Add a brief description of your intended PHI use case.
If you need us to review custom BAA language instead of using our standard agreement, include it in this email.
We'll send our standard BAA for review and signature. Most requests are turned around within a few business days.
Before you store PHI in Coffee
Your BAA must be signed before any PHI is created, received, maintained, or transmitted in your workspace. This includes meeting recordings, transcripts, notes, messages, attachments, and any custom fields used to track patient information.
If you're already using Coffee and may have handled PHI without a signed BAA, contact us before continuing that workflow. We'll review your setup and confirm the right path forward.
What else is in place
Beyond the BAA, HIPAA workflows are protected by the same safeguards behind our SOC 2 Type II certification:
Encryption in transit and at rest
Role-based access controls with least-privilege access
MFA required across in-scope systems
Audit logging and monitoring
BAAs in place with subprocessors that may handle PHI
Prompt access removal when employees leave
See How does Coffee keep my data safe? for the full picture.
Common questions
Is Coffee "HIPAA compliant"?
HIPAA is a legal framework, not a certification — no vendor is "HIPAA certified" by a government body. What matters is that Coffee supports HIPAA-aligned workflows through its technical controls and is willing to sign a BAA. Coffee does both.
Are subcontractors covered?
Yes. We maintain BAAs with subprocessors that may handle PHI as part of providing the service.
