PHI & the BAA
By default, HANK services are not authorized for protected health information (PHI). Send synthetic or de-identified data only. Without a signed Business Associate Agreement, the content you submit is not treated as PHI, and Hank may use it in de-identified or aggregated form to improve the Service.
We do not block your requests when your organization has no agreement. You keep full use of every service. The console and each service show this warning instead: "Your organization is not covered by a Business Associate Agreement for this product. Do not send protected health information. Sign the agreement at https://console.hank.ai/console/baa to enable coverage." You are responsible for the content you send.
Enable PHI for your organization
- Subscribe to a PHI-eligible plan (shown on Billing).
- An organization owner or admin signs the Business Associate Agreement at BAA. The signature binds your organization, and works from a desktop or a phone.
Once both are true, PHI is enabled: the console shows your coverage status,
/api/whoami returns baa_covered, and every API and MCP response carries
the X-Hank-BAA-Covered header (1 = covered, 0 = not covered).
What the BAA does
- Permits your organization to submit PHI to HANK services.
- Binds Hank to HIPAA safeguards: encryption, access controls, breach notification, and use limited to your directed purpose.
- Excludes covered PHI from service-improvement (training) use.
- Limits liability as stated in the agreement text at BAA.
A BAA is not zero data retention. Retention follows the agreement and your directed purpose. Separately, organizations with a signed BAA can turn on per-service zero data retention at Data retention for services that support it.
Coverage follows your subscription tier
The BAA stays on record once signed, but PHI authorization is active ONLY while your subscription is on a PHI-eligible tier:
- If your subscription ends, is suspended, or moves below the qualifying tier, PHI authorization suspends immediately and automatically. The console shows a coverage warning, and we email your organization administrators. Do not send PHI while coverage is suspended.
- When you restore a qualifying subscription, coverage resumes automatically (if your signed BAA version is current) and we email your administrators.
Re-signing after updates
When the BAA text changes materially, we publish a new version. Your organization must sign the new version before PHI is authorized again. The BAA page always shows the current version and your signature status.