The U.S. Department of Health and Human Services explains that a cloud provider that creates, receives, maintains, or transmits ePHI for a covered entity or business associate is itself a business associate, even when the data is encrypted and the provider lacks the decryption key.
That is why MedStack does not treat HIPAA as a single software toggle. The deployment process identifies the parties, the permitted purpose, the minimum data needed, the systems and subcontractors involved, the contract path, and the safeguards required for the practice’s use case.
Practices remain responsible for their own legal and compliance obligations. MedStack’s role and responsibilities are documented in the services agreement, BAA when required, and the approved implementation scope.