You cannot copy content of this website, your IP is being recorded.

Difference Between Agency BAA and a Platform BAA

What is the difference between agency BAA and a platform vendor BAA?

An Agency BAA and a Platform Vendor BAA are both legal contracts required by HIPAA, but they cover completely different entities and responsibilities within your dental practice’s marketing ecosystem. The core difference is that an Agency BAA covers the human marketing team managing your data, while a Platform Vendor BAA covers the software infrastructure where that data is stored or processed.

Agency BAA (The People)

An Agency BAA is signed between your dental practice and your external marketing agency, consultant, or web developer.

  • Who it covers: The agency’s employees, account managers, and contractors.
  • What it promises: The agency promises that their staff will handle your patients’ Protected Health Information (PHI) securely, train their employees on HIPAA, and report any data breaches they cause.
  • Why it matters: Even if your website software is 100% compliant, an agency employee could violate HIPAA by downloading an unencrypted patient contact list to their personal laptop. The Agency BAA protects you from liability in that scenario. 

Platform Vendor BAA (The Software)

A Platform Vendor BAA is signed between your dental practice (or your agency) and the software company providing the analytics, hosting, or form tool.

  • Who it covers: The software company (e.g., Freshpaint, PatientGain, Matomo Cloud, HIPAA-compliant CRMs) and their servers.
  • What it promises: The vendor promises that their servers are encrypted, their databases are secure, and their software architecture prevents unauthorized access to the tracked data. 
  • Why it matters: If a hacker breaches the analytics database containing your dental patient leads, the Platform Vendor BAA establishes that the software company is responsible for securing that infrastructure.

Why You Need Both

Signing one does not cover the other. 

  • If you only sign a Platform Vendor BAA, your data is secure in the cloud, but your marketing agency is legally handling that data without a license—putting you at risk. 
  • If you only sign an Agency BAA, your agency is legally bound to privacy, but the software they use (like standard Google Analytics) will still illegally send patient data to an unsecure third party.

However, if I use PatientGain services, do they cover both?

Yes. If you use PatientGain, their Business Associate Agreement (BAA) covers both the software platform and the human services under a single, unified contract. Because PatientGain operates as an all-in-one, fully managed marketing and software suite, they eliminate the need to manage separate legal agreements for your tools and your marketing team. 

What is Covered Under a PatientGain BAA

  • The Software Stack (Platform Vendor BAA): Their standard BAA natively covers their entire digital ecosystem. This includes their proprietary, secure analytics dashboard, HIPAA-compliant CRM, web forms, automated appointment scheduling, and encrypted communication apps (like two-way patient texting). All of this data is stored on secure, healthcare-grade cloud infrastructure (AWS and Google Cloud) configured to HIPAA standards. 
  • The Account Managers & Support (Agency BAA): Because they provide “Done-For-You” managed marketing services (such as medical SEO content updates and PPC ad management), their human support staff and account managers are legally bound by the same BAA. PatientGain background-checks its staff and subjects them to regular HIPAA and security training to ensure compliance when they handle your practice’s account. 

The Only Exception to Keep in Mind

While PatientGain covers its own internal platform and human team, they cannot cover external platforms that refuse to sign a BAA. For example, if you require standard Google Analytics (GA4) or Meta advertising pixels to remain on your site, PatientGain will use techniques like data masking or data obfuscation to filter out patient identifiers. However, they do not absorb the legal liability for Google or Meta’s independent platforms. 

Practices typically use PatientGain’s native, secure tracking dashboard to measure campaign attribution and traffic sources instead of relying on standard unsecure tracking codes.