> ## Documentation Index
> Fetch the complete documentation index at: https://docs.z360.biz/llms.txt
> Use this file to discover all available pages before exploring further.

# Get and manage your BAA

> How to request, sign, and activate a BAA, and what changes in your organization once it's active.

Setting up a BAA takes five steps. Our team handles most of it, and we'll email you at each stage so you know where things stand.

<Warning>
  Don't store or send patient information through Z360 until your BAA is active. Your organization isn't covered until you receive our activation email.
</Warning>

<Steps>
  <Step title="Request a BAA">
    Email [help@z360.biz](mailto:help@z360.biz) or tell your Z360 contact that your practice will handle patient information. We'll confirm we've received your request.
  </Step>

  <Step title="Share your practice's details">
    We'll send you a short form asking for your practice's legal name, Z360 organization, contact details, authorized signer, and planned Z360 services.
  </Step>

  <Step title="Review and sign">
    We prepare your agreement and send it by e-signature to your authorized signer. The email includes a plain-language summary of what the agreement covers.
  </Step>

  <Step title="We countersign">
    Once your signer has signed, Z360 countersigns. You'll receive a copy of the signed agreement for your records.
  </Step>

  <Step title="BAA mode turns on">
    Our team turns on BAA mode for your organization and sends written confirmation. Do not send patient information through Z360 before that confirmation.
  </Step>
</Steps>

## Who can sign

The signer must be authorized to sign contracts for your practice, such as the owner, an officer, or a practice manager with signing authority.

## Before you sign

Some features are unavailable or labeled after BAA mode is on. If your team relies on integrations, connected apps, or web search, review those workflows before you sign. See [What's covered and what's not](/hipaa-organizations/coverage).

## Once your BAA is active

In a HIPAA organization, open **Settings → Team & Security → HIPAA** to review:

* **Status and effective date** for the current HIPAA mode.
* **Safeguards enabled** for your organization.
* **Coverage & limits**, including which features are covered or not covered by the BAA.

Features outside the BAA are clearly labeled:

* **Not HIPAA-supported:** the feature or voice relies on a service outside the BAA and is unavailable to your organization.
* **Not covered:** the feature stays available, but it isn't covered by your BAA and must not be used with patient information.
* **Enabled at your request:** a connection to a practice-owned destination that your BAA signer requested in writing. Your practice remains responsible for that destination.

Email, practice-owned EHR or CRM connections, and custom actions that send data to your own systems are outside the Z360 BAA. Ask the BAA signer at your practice to make any request about those connections in writing to [help@z360.biz](mailto:help@z360.biz). Your practice is responsible for the destination and can ask us to turn the connection off.

## Changes to your BAA and covered services

We email HIPAA organizations at least 10 days before adding, replacing, or materially changing a subprocessor or covered service. A material BAA change requires written acceptance. If you do not accept a material change, you can leave under the terms of your BAA, including the applicable 30-day transition period.

## Turning off BAA mode

Only the Z360 team can turn BAA mode on or off, and every change is recorded with who made it and when. To request that it be turned off, email [help@z360.biz](mailto:help@z360.biz). Turning it off ends coverage for your organization, so we'll confirm how you'd like your patient information handled first.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.