10/11/2026 Official Document
HIPAA Business Associate Agreement (BAA) Summary
HIPAA Business Associate Agreement (BAA) Standard
Standard: Health Insurance Portability and Accountability Act of 1996 (HIPAA)
Applicability: Healthcare Clinics, Hospitals, Telehealth Providers & BPO Medical Billing
Effective Date: October 8, 2026
LookAtMe provides a legally binding Business Associate Agreement (BAA) for Covered Entities and Business Associates processing Protected Health Information (PHI).
1. Safeguards Implemented by LookAtMe
- Workstation PHI Redaction: Windows Agent dynamically redacts Social Security Numbers (SSN), Medical Record Numbers (MRN), and diagnostic ICD-10 strings from clipboard telemetry and screenshot OCR.
- Access Controls (§ 164.312(a)): Strict single-step JWT role-based access control ensuring healthcare staff only access necessary patient data.
- Audit Controls (§ 164.312(b)): Immutable audit logging recording all administrative view, export, and mutation events.
- Data in Transit & At Rest (§ 164.312(e)): FIPS 140-2 validated AES-256 encryption across all storage tiers and TLS 1.3 wire tunnels.
2. Breach Notification Commitment (§ 164.410)
In the event of a confirmed security incident impacting unsecured PHI, LookAtMe notifies Covered Entities within 24 hours of formal discovery, providing forensic telemetry and remediation steps.
Request Executed BAA: compliance@lookatme.com