> ## Documentation Index
> Fetch the complete documentation index at: https://docs.z360.biz/llms.txt
> Use this file to discover all available pages before exploring further.

# Your responsibilities

> What Z360 is responsible for, what your practice is responsible for, and how email works.

HIPAA compliance on Z360 is shared. Z360 protects patient information inside covered services. Your practice controls what information goes where, who can see it, and everything outside the covered services.

| Z360 is responsible for | Your practice is responsible for |
| - | - |
| Protecting covered services with encryption, access controls, and other safeguards | Keeping patient information inside covered services |
| Holding a BAA with companies that process patient information for covered services | Everything related to email |
| Turning off or labeling features outside the BAA | Not using excluded features with patient information |
| Notifying you of security incidents affecting covered patient information | Deciding whether to notify patients, regulators, or the media after an incident |
| Giving at least 10 days' notice before adding or replacing a subprocessor that handles patient information | Managing team access and removing access when people leave |
| Confirming BAA activation and deleting data from live systems after a valid request | Getting any consent required to record calls and approving the recording disclosure |
| Never using your patient information to train AI | Training your team on how to handle patient information |

## Email

Email isn't covered by your BAA with Z360. Your mailbox, email provider, and everything sent or received by email are your practice's responsibility.

You can request a Gmail or Outlook connection only in writing from the BAA signer at your practice. Email remains outside Z360's BAA. Your practice is responsible for the mailbox, the email provider's BAA and safeguards, and the destination's risk. You can ask Z360 to turn the connection off. Free personal email accounts are not offered a BAA by their providers.

For health-related communication, point patients to covered channels such as calls and texts.

## A quick checklist for your practice

* Keep patient information in [covered services](/hipaa-organizations/coverage) only.
* Treat email as outside your BAA with Z360.
* Turn on two-factor authentication for everyone on your team.
* Review team access regularly and remove it when someone leaves.
* Get patient consent to record calls where your state requires it.
* Approve the recording disclosure used before covered calls are recorded.
* Make written requests through the BAA signer for any practice-owned mailbox, EHR, CRM, or custom connection.
* Tell us right away if you think patient information went somewhere it shouldn't.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.