HIPAA Overview
The Health Insurance Portability and Accountability Act (HIPAA) establishes standards for protecting sensitive patient health information. If you are a covered entity or business associate handling PHI, you must ensure your vendors also comply with HIPAA requirements.Bota’s HIPAA Compliance
Business Associate Agreement (BAA)
Bota offers a Business Associate Agreement to customers who need to process PHI through our platform. The BAA establishes:- Bota’s obligations as your business associate
- Permitted uses and disclosures of PHI
- Safeguards we implement to protect PHI
- Breach notification procedures
- Audit and compliance requirements
Request a BAA
Contact [email protected] to execute a Business Associate Agreement
Administrative Safeguards
| Safeguard | Implementation |
|---|---|
| Security Officer | Designated security officer responsible for HIPAA compliance |
| Workforce Training | All employees complete HIPAA training annually |
| Access Management | Role-based access controls, principle of least privilege |
| Incident Response | Documented procedures for security incident handling |
| Risk Assessment | Annual risk assessments and remediation planning |
Physical Safeguards
| Safeguard | Implementation |
|---|---|
| Data Center Security | AWS data centers with SOC 2 certification |
| Access Controls | Badge access, biometric authentication, 24/7 monitoring |
| Workstation Security | Encrypted devices, remote wipe capability |
| Device Disposal | Secure destruction of media containing PHI |
Technical Safeguards
| Safeguard | Implementation |
|---|---|
| Encryption in Transit | TLS 1.2+ for all API communication |
| Encryption at Rest | AES-256 encryption for all stored data |
| Access Controls | Unique user identification, automatic session timeout |
| Audit Logging | Comprehensive logging of all PHI access and modifications |
| Integrity Controls | Checksums and validation for data integrity |
| Transmission Security | Secure API endpoints, webhook signature verification |
Your Responsibilities
As a covered entity or business associate, you are responsible for:Before Using Bota
1
Execute a BAA
Contact [email protected] to sign a Business Associate Agreement before processing any PHI
2
Assess Your Use Case
Determine what PHI will be processed and ensure Bota is appropriate for your needs
3
Configure Retention
Set appropriate data retention policies for your project (we recommend aligning with your organization’s retention requirements)
During Operation
| Responsibility | Description |
|---|---|
| Patient Consent | Obtain appropriate consent before recording patient interactions |
| Minimum Necessary | Only include PHI that is necessary for your use case |
| Access Controls | Limit API key access to authorized personnel |
| Audit Your Logs | Regularly review access logs for your Bota project |
| Incident Reporting | Report any suspected breaches immediately |
Consent Best Practices
When using Bota to record patient-provider conversations:- Inform the patient that the conversation will be recorded
- Explain the purpose — clinical documentation, quality improvement, etc.
- Obtain explicit consent — verbal or written, as required by your policies
- Document consent — store consent status with the recording via API metadata
- Honor opt-outs — do not record patients who decline
PHI in Bota
What Constitutes PHI
Protected Health Information includes any individually identifiable health information, such as:- Patient names and contact information
- Medical record numbers
- Diagnosis and treatment information
- Dates of service
- Audio recordings of clinical encounters
- Transcriptions containing health information
Where PHI May Exist in Bota
| Component | PHI Potential | Notes |
|---|---|---|
| Audio Recordings | High | Primary source of PHI |
| Transcriptions | High | Contains spoken PHI |
| Summaries | High | May contain clinical information |
| EndUser Records | Medium | Depends on external_id usage |
| Metadata | Low-Medium | Depends on what you store |
De-identification
If you want to reduce PHI exposure, consider:- Using internal patient IDs as
external_idrather than names - Storing metadata references rather than PHI directly
- Implementing automated redaction in your downstream systems
Data Handling
Storage Location
All PHI is stored in AWS data centers in the United States. For customers requiring specific geographic storage, contact us about regional deployment options.Data Retention
Configure retention policies appropriate for your compliance requirements:HIPAA requires retention of medical records for 6 years from date of creation or last effective date. State laws may require longer retention.
Data Deletion
You can delete PHI at any time via the API:- All recordings for the EndUser
- All transcriptions and summaries
- All associated metadata
Breach Notification
Our Obligations
If we discover a breach of unsecured PHI, we will:- Notify you within 24 hours of discovery
- Provide details of the breach (what data, how many affected, timeline)
- Describe our remediation actions
- Cooperate with your investigation and notification requirements
Your Obligations
You are responsible for:- Notifying affected patients as required by HIPAA
- Reporting to HHS Office for Civil Rights
- Documenting the breach and response
- Implementing corrective actions
Audit and Compliance
Audit Logs
Bota maintains comprehensive audit logs for all PHI access:- API requests (who, what, when)
- Data modifications
- Access by Bota personnel (rare, only for support with your permission)
Compliance Certifications
| Certification | Status |
|---|---|
| SOC 2 Type II | Certified |
| HIPAA | Compliant (with BAA) |
| GDPR | Compliant |
Third-Party Audits
We engage independent auditors annually to assess our security controls. Audit reports are available to customers under NDA.Frequently Asked Questions
Do I need a BAA to use Bota?
Do I need a BAA to use Bota?
You need a BAA only if you will process PHI through Bota. If you’re using Bota for non-healthcare purposes (e.g., sales calls), a BAA is not required.
Can Bota employees access my PHI?
Can Bota employees access my PHI?
Bota employees do not access customer PHI in normal operations. Access is only possible with your explicit permission for troubleshooting specific issues, and all access is logged and audited.
Is the transcription AI HIPAA compliant?
Is the transcription AI HIPAA compliant?
Our transcription pipeline is covered under the BAA. Audio is processed in isolated environments and deleted after transcription completes. We do not use PHI to train AI models.
What about Bota devices?
What about Bota devices?
Bota Pin and Bota Note devices store audio locally with encryption. Data is only transmitted when synced via the mobile app over encrypted connections.
Can I use Bota for telehealth?
Can I use Bota for telehealth?
Bota is designed for in-person conversation capture. For telehealth recording, consult with your compliance team about applicable regulations beyond HIPAA.
Contact
For HIPAA compliance questions or to request a BAA: Email: [email protected] Subject: HIPAA / BAA InquiryLast updated: January 15, 2025

