> ## Documentation Index
> Fetch the complete documentation index at: https://docs.z360.biz/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA on Z360

> How Z360 supports healthcare practices that handle patient information.

If your practice handles patient information, Z360 can act as your Business Associate under HIPAA and sign a Business Associate Agreement (BAA) with you. This section explains what the BAA covers, how to set it up, and what your practice needs to do on its side.

<Note>
  No government body issues a software certificate for HIPAA. What we offer is a signed BAA, safeguards behind it, and evidence of both on request.
</Note>

## Two kinds of organizations

Every Z360 organization runs in one of two modes.

* **Standard organization.** The default. The full product is available, and no HIPAA boundaries apply. Standard organizations shouldn't store or send patient information through Z360.
* **HIPAA organization.** Your practice has signed a BAA with Z360, and our team has turned on BAA mode for your organization. Covered services protect patient information. Features outside the BAA are turned off or clearly labeled. Your settings show exactly where the line sits.

BAA mode applies to your whole organization. Only the Z360 team can turn it on or off, and only after your agreement is signed.

If your practice also does non-patient work, use a separate standard organization for that work. Do not mix patient information with non-patient information in the same organization.

## Why a BAA matters

Your practice is a Covered Entity under HIPAA. When you use Z360 to communicate with or about patients, Z360 becomes your Business Associate: a company that handles patient information on your behalf. The law requires a written BAA between us before patient information flows through Z360.

## HIPAA is a shared responsibility

Z360 protects patient information inside our covered services and binds every company we rely on to the same standard. Your practice decides what information goes where, manages who on your team has access, and is responsible for anything outside the covered services, including email. Signing a BAA doesn't make every use of Z360 compliant on its own. It works when both sides do their part.

## In this section

<CardGroup cols={2}>
  <Card title="Get and manage your BAA" icon="file-signature" href="/hipaa-organizations/get-a-baa">
    Request, sign, and activate your agreement, and learn what changes in your settings.
  </Card>

  <Card title="What's covered and what's not" icon="shield-check" href="/hipaa-organizations/coverage">
    Review the services protected under your BAA and the features outside it.
  </Card>

  <Card title="Your responsibilities" icon="handshake" href="/hipaa-organizations/shared-responsibility">
    Understand what Z360 does, what your practice does, and how email works.
  </Card>

  <Card title="How we handle your data" icon="lock" href="/hipaa-organizations/data-handling">
    Review security, AI and training, retention, deletion, and incidents.
  </Card>

  <Card title="Subprocessors" icon="building" href="/hipaa-organizations/subprocessors">
    See the companies that process data for Z360 and their HIPAA coverage.
  </Card>

  <Card title="FAQ" icon="circle-question" href="/hipaa-organizations/faq">
    Get quick answers to common questions from healthcare practices.
  </Card>
</CardGroup>

Questions? Email [help@z360.biz](mailto:help@z360.biz).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.