HIPAA Compliant - BAA Available

CData Connect AI supports HIPAA-regulated workloads

CData Connect AI can be configured to support workloads involving protected health information (PHI). CData requires a Business Associate Agreement (BAA) for eligible use cases involving PHI.

SOC 2 Type II ISO/IEC 27001:2022 BAA Available

Background

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a U.S. federal law that establishes privacy and security standards for protected health information (PHI). If your organization is a covered entity or business associate subject to HIPAA, CData Connect AI can be configured to support PHI within your data workflows.

When a covered entity or business associate has executed a BAA with CData, Connect AI is available for eligible HIPAA-regulated use cases and CData operates as a business associate.

Requirements and limitations

For eligible HIPAA-regulated use cases, CData offers a BAA.

Please note the following limitations:

  • Do not use Connect AI to communicate with patients (or their personal representatives), plan members, or family members.
  • Do not submit PHI as free-text input to AI prompts.
  • Do not use support impersonation features when PHI may be involved.
  • Do not use legacy OData endpoints for PHI workflows.
  • Do not submit PHI through live chat, support chatbot, public email, or personal email.

The above limitations are not eligible use cases for PHI. CData does not support HIPAA compliance for such use cases.

If you enable query logging at verbosity level 3 or above, those logs may contain PHI and the BAA will apply to those logs.

Not a system of record Connect AI does not maintain a designated record set and should not be used as the system of record for PHI.
Third-party applications CData's BAA does not extend to your organization's third-party applications, integrations, or marketplace providers. You are responsible for determining whether a BAA is required with any third-party application before use.
Customer responsibility You remain responsible for configuring and using Connect AI in a manner consistent with your HIPAA obligations.

Need a BAA for Connect AI?

Contact your CData sales rep.

Request a BAA

Security or privacy questions? Our team is here to help.