When it happens
Digital BAA signing is part of rollout—typically before your first secure email, fax, or form submission. You receive an executed copy for your compliance file.
Security overview
Healthcare buyers need more than a logo lock. Here is how we approach encryption, agreements, logging, and operational transparency.
Business Associate Agreement
Your vendor relationship should be documented before PHI moves—not negotiated after an audit letter arrives. Every Easy MD Forms subscription includes a signed Business Associate Agreement executed during onboarding.
Digital BAA signing is part of rollout—typically before your first secure email, fax, or form submission. You receive an executed copy for your compliance file.
One agreement spans HIPAA email, cloud fax, patient forms, secure files, and team chat. You are not stacking separate BAAs for each module.
Request our security and compliance packet for vendor due diligence—architecture summary, subprocessors, and control overview alongside the executed BAA.
All plans include a signed BAA · Public pricing · Built for physician offices
Security controls
Technical and operational safeguards mapped to what clinics ask during vendor due diligence—not marketing fluff.
Every plan includes a signed BAA before you send your first message—so your compliance file is audit-ready, not assembled after a close call.
TLS protects data in transit between clients and our services. PHI stays on purpose-built channels—not consumer Gmail or personal SMS workflows.
AES-256 aligned storage practices for protected content at rest, with key management appropriate to healthcare workloads.
Role-based access and session timeouts help limit PHI exposure to staff who need it—principle of least privilege for day-to-day operations.
Activity logging helps answer “who touched this PHI?” Unified logs across email, fax, and forms reduce scramble compared to patchwork tools.
Staff admin accounts support two-factor sign-in. Customer portal users verify with a one-time code emailed after password sign-in. We recommend MFA for every account with PHI or configuration access.
Backups and recovery procedures aligned to healthcare uptime expectations—documented for vendor reviews on request.
Documented incident response and breach notification process with customers, including coordination when a reportable event is discovered.
Production domains should publish SPF, DKIM, and DMARC to reduce spoofing and improve deliverability. Your hosting team can verify records with standard DNS tools.
Infrastructure transparency
Healthcare organizations deserve clear answers during vendor review—not vague assurances.
Documented architecture overview and subprocessor list available on request for vendor due diligence.
Infrastructure designed for resilience with documented backup and recovery procedures—not a single undocumented point of failure.
Infrastructure monitoring for availability and security-relevant events, with alerting when operational thresholds are crossed.
Security and compliance packet available on request—architecture summary, subprocessors, and control overview for your privacy officer.
Compliance standards
Controls on use and disclosure of PHI. BAA execution for covered services before production use.
Administrative, physical, and technical safeguards implemented and documented for systems that handle PHI.
Breach notification requirements and expanded Business Associate obligations under the Omnibus Rule.
Risk assessment and safeguard documentation informed by NIST guidance for HIPAA Security Rule implementation.
Purpose-built email, fax, forms, chat, and files—separate from consumer apps that lack BAAs and audit trails.
Plain-language answers for practice managers and privacy officers evaluating vendors—not security jargon alone.
Security documentation
Documentation and guides to support your vendor security review—request formal packets through our team.
Architecture overview and control summary for your vendor review.
Request packet →HIPAA email, BAA basics, OCR audits, and vendor comparisons.
Browse guides →What a Business Associate Agreement covers and when you need one.
Read the guide →Book a consult to walk through your practice size, stack, and rollout.
Book a consult →Third-party attestation
Plenty of vendors display SOC 2 and HITRUST badges. We display what we've actually earned. Request our security and compliance packet for control documentation, sub-processor details, and an honest picture of where we stand.
Third-party scanners help confirm headers and performance on the marketing site (results vary by CDN settings):
Protect your practice
Get HIPAA-compliant email, fax, and forms with transparent pricing—starting with a free consult or risk check.
✓ BAA included · ✓ Public pricing · ✓ Built for clinics
We are away right now. Send a message and we will follow up by email.
End this chat and email a transcript to you?
Thank you for reaching out. A copy of this conversation has been emailed to you.
How was your support experience?
Thanks for your feedback.