ProxForm
Checking… Not connected Build a form
HIPAA The conduit position, in one place

ProxForm under HIPAA

We do not market ProxForm as a HIPAA-compliant product, because the question doesn't apply the way most SaaS vendors answer it. ProxForm never receives, stores, or processes Protected Health Information — so under the conduit exception we are not a Business Associate. This page lays out the position your compliance officer needs.

Not legal advice. Use this as a starting point for a conversation with your HIPAA Privacy/Security Officer or counsel.

The four pillars under HIPAA

0
PHI on our infrastructure

Patient Health Information never touches Artivicolab servers. There are no Artivicolab servers in the PHI path.

0
Persistent access

We have no ability to read, retain, or replay PHI even momentarily. The data is encrypted browser-to-browser; we cannot decrypt it.

0
BAA required

Under the conduit exception, no Business Associate Agreement is needed between the covered entity and Artivicolab. We can issue one on request, but the legal default is "not a BA."

100%
On the covered entity

The clinic remains the covered entity for the PHI it collects through ProxForm — the same way a clinic using a paper clipboard is the covered entity for what's on the paper.

Why ProxForm is not a Business Associate

HIPAA's definition of "business associate" at 45 CFR 160.103 includes entities that "create, receive, maintain, or transmit" PHI on behalf of a covered entity. HHS guidance carves out a conduit exception for entities that only transmit PHI without persistent access — examples cited include the US Postal Service, private couriers, and telecom carriers. ProxForm fits that pattern.

Closest precedent: a clinic using a fax machine, a paper courier, or a USB stick to move forms between desks. The hardware vendor is not a Business Associate.

HIPAA Security Rule technical-safeguards mapping

Even though ProxForm is not a Business Associate, the architecture satisfies — or exceeds — every technical safeguard in the HIPAA Security Rule that a covered entity would need to evidence for the ProxForm portion of their workflow.

What stays on the covered entity (clinic)

HIPAA's administrative and physical safeguards live with the covered entity — not with software vendors. ProxForm does not replace them.

Cryptography & transport detail

What ProxForm is not under HIPAA

If your compliance officer wants a BAA anyway

Some compliance teams ask for a Business Associate Agreement reflexively, even where the conduit exception applies. We will sign one on request — drafted to reflect the actual relationship (we don't access PHI, we don't store it, we don't transmit it through our infrastructure). Contact us through the link in the footer.

Need something for your audit?

If your DPO or HIPAA Officer needs a written statement, a BAA copy, or a letter for the audit packet, use the Contact button in the footer.