Skip to content

docs: qualify BAA copy to decided position; broaden PHI to PHI/PII#51

Merged
abrichr merged 2 commits into
mainfrom
baa-phi-copy-update
Jul 21, 2026
Merged

docs: qualify BAA copy to decided position; broaden PHI to PHI/PII#51
abrichr merged 2 commits into
mainfrom
baa-phi-copy-update

Conversation

@abrichr

@abrichr abrichr commented Jul 21, 2026

Copy link
Copy Markdown
Member

Brings the on-prem compliance docs in line with the counsel-decided BAA/PHIPA posture and broadens the general sensitive-data term from PHI to PHI/PII (OpenAdapt serves healthcare and lending/regulated work).

BAA copy (legal-attestation-sensitive; scoped, not overclaimed)

docs/guides/deploy-on-prem.md "Compliance posture" section: replaced the flat "We do not sign a BAA" with the qualified position. In the self-hosted deployment PHI stays inside your environment and does not enter OpenAdapt's infrastructure, so the software runs as an on-premise vendor rather than a business associate for that shape and a BAA is not the operative instrument for it; the deploying org's privacy officer and counsel make the determination. Where procurement requires written terms, a US HIPAA BAA (or, for an Ontario clinic, a PHIPA service-provider agreement) can be signed following review. Hosted processing of PHI in our infrastructure (BAA + HIPAA risk analysis) is not offered today.

The other pre-existing BAA lines (security-review.md, deployment-matrix.md "do not infer BAA/HIPAA/PHIPA status from architecture docs") were already accurate and were left as-is.

PHI -> PHI/PII

General product/security/deployment copy across 15 docs broadened to PHI/PII (scrubbing, at-rest, boundary, lane-safety guidance, etc.).

Kept as PHI (correct legal/health-specific term or literal token): the HIPAA/BAA/PHIPA compliance clause, the "a real EMR can display PHI" illustration, the PHI audit REM-3 remediation identifiers, the merged-PR title in whats-new.md, the PlaintextPHIWarning code identifier, already-compound PII/PHI, and the narrow non-PHI validation-environment / entry-URL qualification fields.

Guards

  • scripts/validate_docs.py: Validation passed
  • mkdocs build --strict: success
  • pytest tests/: 64 passed (pinned substrate-evidence copy untouched)

No em dashes introduced. Source of the decided position: internal counsel decision memo (.private/baa_phipa_decision_2026_07_14.md).

🤖 Generated with Claude Code

https://claude.ai/code/session_01NyCHrzA1psrKMFfroYbzaM

abrichr and others added 2 commits July 21, 2026 04:37
Bring the on-prem compliance copy in line with the counsel-decided posture
and broaden the general sensitive-data term from PHI to PHI/PII (OpenAdapt
serves healthcare and lending/regulated work, not healthcare alone).

BAA copy (deploy-on-prem.md compliance section): replace the flat "We do
not sign a BAA" with the qualified position. In the self-hosted deployment
PHI stays inside the customer environment and does not enter OpenAdapt's
infrastructure, so the software runs as an on-premise vendor rather than a
business associate for that shape and a BAA is not the operative instrument
for it; the deployment's privacy officer and counsel make the determination.
Where procurement requires written terms, a US HIPAA BAA (or, for an Ontario
clinic, a PHIPA service-provider agreement) can be signed following review.
Hosted processing of PHI in our infrastructure (BAA + HIPAA risk analysis)
is not offered today.

PHI -> PHI/PII in general product/security/deployment copy. Kept PHI where
it is the correct legal/health-specific term or a literal token: the
HIPAA/BAA/PHIPA compliance clause, the EMR illustration, the "PHI audit
REM-3" identifiers, the merged-PR title in whats-new, the PlaintextPHIWarning
code identifier, already-compound PII/PHI phrasing, and the narrow non-PHI
validation-environment/entry-URL qualification fields.

validate_docs.py, mkdocs build --strict, and pytest tests/ all pass; the
pinned substrate-evidence copy is untouched.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NyCHrzA1psrKMFfroYbzaM
@abrichr
abrichr force-pushed the baa-phi-copy-update branch from 7941251 to b7b0d66 Compare July 21, 2026 08:38
@abrichr
abrichr merged commit a023a61 into main Jul 21, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant