10/11/2026 Official Document

HIPAA Business Associate Agreement (BAA) Summary

HIPAA Business Associate Agreement (BAA) Standard

Standard: Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Applicability: Healthcare Clinics, Hospitals, Telehealth Providers & BPO Medical Billing
Effective Date: October 8, 2026

LookAtMe provides a legally binding Business Associate Agreement (BAA) for Covered Entities and Business Associates processing Protected Health Information (PHI).


1. Safeguards Implemented by LookAtMe

  • Workstation PHI Redaction: Windows Agent dynamically redacts Social Security Numbers (SSN), Medical Record Numbers (MRN), and diagnostic ICD-10 strings from clipboard telemetry and screenshot OCR.
  • Access Controls (§ 164.312(a)): Strict single-step JWT role-based access control ensuring healthcare staff only access necessary patient data.
  • Audit Controls (§ 164.312(b)): Immutable audit logging recording all administrative view, export, and mutation events.
  • Data in Transit & At Rest (§ 164.312(e)): FIPS 140-2 validated AES-256 encryption across all storage tiers and TLS 1.3 wire tunnels.

2. Breach Notification Commitment (§ 164.410)

In the event of a confirmed security incident impacting unsecured PHI, LookAtMe notifies Covered Entities within 24 hours of formal discovery, providing forensic telemetry and remediation steps.

Request Executed BAA: compliance@lookatme.com

Copyright 2026 LOOKATME ENTERPRISE SUITE Intelligence