No government body issues a software certificate for HIPAA. What we offer is a signed BAA, safeguards behind it, and evidence of both on request.
Two kinds of organizations
Every Z360 organization runs in one of two modes.- Standard organization. The default. The full product is available, and no HIPAA boundaries apply. Standard organizations shouldn’t store or send patient information through Z360.
- HIPAA organization. Your practice has signed a BAA with Z360, and our team has turned on BAA mode for your organization. Covered services protect patient information. Features outside the BAA are turned off or clearly labeled. Your settings show exactly where the line sits.
Why a BAA matters
Your practice is a Covered Entity under HIPAA. When you use Z360 to communicate with or about patients, Z360 becomes your Business Associate: a company that handles patient information on your behalf. The law requires a written BAA between us before patient information flows through Z360.HIPAA is a shared responsibility
Z360 protects patient information inside our covered services and binds every company we rely on to the same standard. Your practice decides what information goes where, manages who on your team has access, and is responsible for anything outside the covered services, including email. Signing a BAA doesn’t make every use of Z360 compliant on its own. It works when both sides do their part.In this section
Get and manage your BAA
Request, sign, and activate your agreement, and learn what changes in your settings.
What's covered and what's not
Review the services protected under your BAA and the features outside it.
Your responsibilities
Understand what Z360 does, what your practice does, and how email works.
How we handle your data
Review security, AI and training, retention, deletion, and incidents.
Subprocessors
See the companies that process data for Z360 and their HIPAA coverage.
FAQ
Get quick answers to common questions from healthcare practices.
