United States: Business Associate Agreements. Canada: Information Manager and Agent Agreements.
Effective Date: August 11, 2024 Last Updated: August 2, 2026 Version: 2.1 Replaces: BirthBridge HIPAA Business Associate Agreement (BAA) Program Overview
1. Who this page is for
If you are a regulated health professional, a clinic, a midwifery practice, a hospital, a health authority, or an organization subject to health privacy law, and you want to use BirthBridge to communicate or coordinate care, you probably need a written agreement with us before you do.
This page explains what agreements we offer, which one applies to you, what is covered, and how to request one.
If you are a doula, childbirth educator, postpartum professional, or an independently practising lactation consultant who is not part of a regulated practice, you most likely do not need one of these agreements, and our standard Terms and Conditions and Health Information Policy already govern how we handle your clients' information. You are welcome to request an agreement anyway if your certifying body or your own counsel asks for one.
2. BirthBridge's role
BirthBridge is a technology platform that connects families with birth professionals and provides messaging, file sharing, scheduling, booking, and payment coordination.
BirthBridge does not provide video calling. Where you mark an appointment as virtual, you supply your own meeting link. That call takes place on a service you chose, outside BirthBridge, and it is outside the scope of any agreement with us. See Section 4.
We do not provide health care. We do not diagnose, treat, or advise. We do not control how a professional delivers care, and we do not direct clinical decisions.
When you use our platform to handle information about your clients or patients, we act as a service provider to you. You remain the custodian, the covered entity, or the responsible organization. The agreement between us sets out what we may do with the information, what safeguards we apply, and what we owe you if something goes wrong.
3. Which agreement applies to you
| Where you practise | Your status | Agreement we offer |
|---|---|---|
| United States, and you are a HIPAA covered entity or a business associate | Covered entity or business associate | Business Associate Agreement (BAA) under 45 CFR 164.504(e) |
| Ontario | Health information custodian under PHIPA | Agent agreement under PHIPA s. 10(3), plus our HINP undertakings where applicable |
| Alberta | Custodian under the Health Information Act | Information Manager Agreement under HIA s. 66 |
| British Columbia | Organization under PIPA, or a designated participant under the E-Health Act | Service provider agreement under PIPA |
| Saskatchewan | Trustee under HIPA | Information management service provider agreement under HIPA s. 18(2) |
| Manitoba | Trustee under PHIA | Information manager agreement under PHIA s. 25 |
| Nova Scotia, Newfoundland and Labrador, Prince Edward Island | Custodian | Information manager agreement under the applicable Act |
| New Brunswick | Custodian under PHIPAA | Agent agreement |
| Quebec | Enterprise under Law 25, or a body under the health and social services information legislation | Written mandate under Law 25, plus our privacy impact assessment summary for the cross-border transfer |
| Anywhere, as a general data processing agreement | Any | Data Processing Agreement (DPA) |
If your situation is not on this list, or you operate in more than one jurisdiction, contact us and we will work out the right instrument. Multi-province practices usually receive a single master agreement with province-specific schedules rather than several separate agreements.
4. What is in scope
An agreement covers the platform features through which you handle client or patient information. Being specific about this is useful to both of us, so:
In scope
- Platform messaging between you and your clients, and between you and other professionals on the platform.
- Files and images shared through platform messaging.
- Booking and appointment records, including any meeting link you enter.
- Scheduling and appointment information.
- Client contact records and booking records associated with your account.
- Support interactions in which you or your client shares information with our team.
Out of scope
- Your public profile, service descriptions, pricing, credentials, and photos. These are published by you for the purpose of being seen publicly.
- Reviews written by clients and published on your profile.
- Blog and educational content you publish through the platform.
- Marketing communications you or we send, which are governed by consent rather than by these agreements.
- Aggregate and de-identified analytics about platform usage that cannot reasonably identify an individual.
- Anything you do off the platform, including your own email, your own record system, and your own devices.
- Payment card data, which is handled by our payment processor under its own compliance framework and never reaches our systems in full.
- Video or telephone calls. BirthBridge provides no video calling. Any virtual appointment happens on a third-party service you selected, under your agreement with that service. We hold the link and the appointment record, and nothing about the call itself. If your use case requires video under a covered agreement, you need an agreement with that video vendor, not with us.
Precedence. Where a signed agreement covers information about health, that agreement prevails over our standard Terms and Conditions and Privacy Policy to the extent of any conflict, for the information it covers.
5. What we commit to
Across all of these agreements, subject to the specific terms of the one you sign:
Use and disclosure
- We use and disclose the information only to provide the platform to you, as your agreement permits, or as the law requires.
- We apply the minimum necessary principle.
- We do not use it for our own purposes, we do not sell it, we do not use it for advertising, and we do not use it to train machine learning or artificial intelligence models.
Safeguards
- Encryption of message content at rest using per-user key pairs, and TLS in transit.
- Role-based access control, limited to personnel who need access for their role.
- Logging of access to production systems and to personal information.
- A documented incident response process.
- Workforce training on the handling of health information for personnel whose role involves it.
- Review of threats, vulnerabilities, and risks to the information handled through the platform.
Where your agreement requires a specific training, audit, or assessment standard, raise it with us before signing so that the agreement reflects what we can evidence.
Subcontractors
- We require every subcontractor that handles covered information on our behalf to agree in writing to protections at least as strict as those in your agreement, including a Business Associate Agreement where United States protected health information is involved.
- We remain accountable to you for what our subcontractors do.
- We will give you a current list of subcontractors in scope on request, and reasonable notice before adding one.
Incidents
- United States: we report a breach of unsecured protected health information to you without unreasonable delay and no later than 60 days after discovery, and we report other security incidents and any unauthorized use or disclosure promptly.
- Canada: we notify you at the first reasonable opportunity of any unauthorized use, disclosure, loss, or unauthorized access, so that you can meet your own obligations to individuals and to your Commissioner. We keep a record of every incident for at least 24 months.
- In both cases we give you enough detail to assess the risk, we tell you what we are doing about it, and we cooperate with your investigation.
Access, correction, and audit
- We make information available to you so you can respond to a client's access, correction, amendment, or accounting request within your legal deadlines.
- We give you access to electronic records of access to and transfer of information handled through the platform.
- We provide reasonable cooperation with your audits and reviews, on notice, and we provide our security documentation.
End of the agreement
- On termination we return or securely destroy the covered information where feasible, and where it is not feasible we tell you and continue to protect it for as long as we hold it.
- We give you a reasonable window to export your data before deletion.
6. What you are responsible for
Signing an agreement with us does not make you compliant. It is one piece of your compliance, and the rest is yours.
You are responsible for:
- Determining whether BirthBridge is appropriate for your use case, and for your own privacy impact assessment where the law requires one. In Quebec, a privacy impact assessment is required before transferring personal information outside Quebec, and BirthBridge processes in the United States.
- Obtaining any consent or authorization your clients need to give before you use the platform for their information.
- Your own policies, safeguards, staff training, and record retention.
- Your own notification obligations to individuals and regulators if there is a breach.
- Configuring your own use of the platform appropriately, including who on your team has access.
- Complying with your regulatory college's standards, including advertising standards. Some Canadian colleges restrict the use of testimonials, which affects how reviews may be displayed on your profile. Tell us at hello@mybirthbridge.com if this applies to you.
- Keeping your clinical records in a system you control. Platform messaging is not a clinical record system and our retention schedule is not built to satisfy professional record retention requirements.
7. Where information is processed
BirthBridge processes and stores information in the United States.
For Canadian custodians and trustees this is a material fact in your assessment. Cross-border processing is permitted under Canadian privacy law, but you remain accountable for information you transfer, you must be satisfied it receives comparable protection, Alberta requires you to notify individuals that a service provider outside Canada is used, and Quebec requires a completed privacy impact assessment before the transfer.
We will provide what you need for your assessment, including our security documentation, subcontractor list, and processing locations. Contact hello@mybirthbridge.com.
We do not currently offer Canadian data residency. If that changes we will update this page.
8. Ontario: plain language description of services
Published to meet the obligation on a health information network provider under O. Reg. 329/04 s. 6(3), made under the Personal Health Information Protection Act, 2004, to make available to the public a plain language description of the services it provides to health information custodians, including a general description of the safeguards in place.
What the service does. BirthBridge provides a web platform that lets a health information custodian communicate with the individuals in their care, and with other professionals, using text messaging and file sharing, and lets them manage appointments and bookings. BirthBridge does not provide video calling; where a custodian marks an appointment as virtual, the custodian supplies a meeting link for a third-party service, and that call takes place outside BirthBridge.
What information passes through it. Contact details, appointment and booking details, and whatever content a custodian or an individual chooses to type into a message or share as a file. This may include personal health information.
How the information is protected.
- Message content is encrypted while stored, using an encryption key pair generated for each user, so message content is not held in readable plain text in our database.
- All traffic between a user's device and our servers is encrypted in transit using TLS.
- Access to production systems and to personal health information is limited to personnel whose role requires it, is controlled by role-based permissions, and is logged.
- BirthBridge personnel access message content only to deliver notifications, to investigate a report of abuse, fraud, or a safety concern, to respond to a support request, or where legally required.
- BirthBridge does not use personal health information for advertising, does not sell it, and does not use it to train machine learning or artificial intelligence models.
- Subcontractors that handle personal health information are bound by written agreements imposing equivalent protections.
- Information is stored and processed in the United States.
Limits of the protection. BirthBridge does not offer end-to-end encryption. BirthBridge holds the technical means to decrypt message content and does so in the limited circumstances described above. Use of the platform does not by itself make a custodian compliant with PHIPA.
Records of access and transfer. Custodians may request an electronic record of accesses to, and transfers of, personal health information handled through the platform, by contacting hello@mybirthbridge.com. Directions for making that request are available on request and are provided to every custodian at the start of an agreement.
Threat, vulnerability, and risk assessment. Ontario requires a network provider to perform an assessment of the services with respect to threats, vulnerabilities, and risks to the privacy of individuals and to the security and integrity of personal health information, and to make it available to custodians. Ontario custodians should contact us at hello@mybirthbridge.com to discuss this, and the written agreement between us, before using the platform for personal health information.
Notice of unauthorized use or disclosure. BirthBridge notifies each applicable custodian at the first reasonable opportunity of any unauthorized use or disclosure of personal health information handled through the platform.
Contact. hello@mybirthbridge.com, or BirthBridge, LLC, Texas, United States.
9. How to request an agreement
Email hello@mybirthbridge.com with:
- Your organization's legal name and mailing address.
- Where you practise, listing every state, province, or territory.
- Your regulatory status, for example "registered midwife, College of Midwives of Ontario" or "HIPAA covered entity, family medicine practice."
- Which platform features you plan to use.
- Approximately how many people on your team will have access.
- A contact for the signatory.
What happens next. We acknowledge within 2 business days and send the appropriate agreement for signature within 10 business days. Where we have a standard form for your jurisdiction we will use it, which keeps this fast. We will consider reasonable redlines, and material changes may take longer and may require legal review on both sides.
There is no charge for a standard agreement.
Preview the forms. Ask us for the applicable form before you commit and we will send it for review.
10. Security documentation
A description of our safeguards is available to counterparties on request at hello@mybirthbridge.com, along with our current subcontractor list and processing locations, so that your privacy officer or counsel can complete their assessment.
If your review requires a specific certification, audit report, or assurance standard, tell us what you need at the start and we will tell you what we can provide. Section 5 describes the safeguards in place, and Section 11 sets out the limits of what we represent.
11. Limitations
- No system is completely secure. We describe our safeguards accurately and we do not guarantee that information cannot be compromised.
- Using BirthBridge does not make you compliant with HIPAA, PHIPA, HIA, PIPEDA, Law 25, or any other law. Compliance depends on how you use the platform and on everything you do outside it.
- This page is not legal advice. Have your own counsel or privacy officer review whether BirthBridge fits your compliance framework.
- Nothing here creates an agreement. An agreement exists only when both parties sign one.
12. Contact
Compliance and agreements: hello@mybirthbridge.com Privacy contact: hello@mybirthbridge.com. Schedule B5 of our Privacy Policy sets out who holds the role of person in charge of the protection of personal information under Quebec's Law 25. Security: hello@mybirthbridge.com, and our Security and Vulnerability Disclosure policy.
BirthBridge, LLC
Texas, United States
Related documents