BAA status

Confirm directly before sending ePHI

This website does not state that a Business Associate Agreement is automatically included with free or paid AliasCloak use. A covered entity or business associate should obtain written confirmation and execute any required agreement before using the service to create, receive, maintain, or transmit ePHI on its behalf.

When might a BAA be required?

HHS explains that a cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate is generally a business associate, even when the provider stores only encrypted ePHI and does not hold the decryption key. The parties should evaluate the actual service and relationship.

Questions to resolve in writing

  • Is AliasCloak acting on behalf of a covered entity or another business associate?
  • Will ePHI be created, received, maintained, or transmitted through the service?
  • Which AliasCloak entity would sign the agreement?
  • What permitted uses and disclosures apply?
  • What safeguards, incident reporting, subcontractor, return, and destruction terms apply?
  • Does the agreement cover free generated mailboxes, paid custom aliases, or a separate offering?
  • What customer responsibilities apply to keys, endpoints, access, retention, and records?

Encryption does not eliminate the question

End-to-end encryption can reduce who can read message content, but HHS guidance says that maintaining encrypted ePHI can still create a business-associate relationship. Do not treat a zero-knowledge or private-key design as an automatic exemption.

Recommended public wording

AliasCloak provides privacy-focused encrypted messaging and file delivery. Before using AliasCloak for protected health information, your organization must confirm whether a Business Associate Agreement and additional administrative, technical, and physical safeguards are required for its specific workflow.

What customers remain responsible for

  • Risk analysis and risk management
  • Authorized workforce access
  • Private-key and endpoint protection
  • Minimum-necessary use and recipient verification
  • Record retention and patient-access obligations
  • Incident response and breach assessment
  • Appropriate downstream storage after delivery
Do not send ePHI based on marketing language alone

Obtain the actual agreement, review the actual data flow, and have qualified privacy or legal personnel assess the intended use.

Official sources

Use primary guidance when building a healthcare communication workflow.