Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Business Associate Agreement (BAA)

A Business Associate Agreement (BAA) is a contract required under US HIPAA between a covered entity, such as a healthcare provider or health plan, and a business associate that handles protected health information on its behalf. It binds the business associate to safeguard that data and to follow the relevant HIPAA rules. The same obligation flows down to subcontractors through further BAAs.

In practice

The BAA is the trigger, but the Security Rule is the work. Signing commits you to administrative, physical, and technical safeguards and to a documented risk analysis, which is the requirement most often missing when a company assumes a policy set covered it.

The obligation chains downward. If you use subcontractors that touch the same health data, you need BAAs with them too, so the agreement is rarely a single document at the top of the stack.

// how traztech helps

traztech delivers HIPAA Security Rule readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A BAA usually arrives as a contract to sign rather than a standard to study. A health system or payer asks you to execute one, and the HIPAA obligations follow from that signature whether or not you were thinking about HIPAA before. The safeguards behind it are what HIPAA Security Rule readiness puts in place.

The trap is signing the BAA without the Security Rule work behind it. A BAA commits you to safeguards, a risk analysis, and breach handling, so executing one you cannot actually meet creates contractual exposure on top of the regulatory kind. Our HIPAA in Canada post covers how this reaches Canadian vendors.

Business Associate Agreement (BAA): common questions

When do we need to sign a BAA?

When you create, receive, maintain, or transmit protected health information on behalf of a covered entity. If your software touches patient data for a US healthcare customer, you are likely a business associate and a BAA is expected.

Does a BAA from our cloud provider make us compliant?

No. A BAA from a cloud platform covers their layer only. Your application, access controls, logging, and staff training sit outside it and are exactly what a customer will assess.

Free PDFs, no card

Get the checklists that go with this

SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.