OnePath logoOnePathConnect
For BusinessFor Developers
PlatformDocsChangelogUse CasesCompanyLive Demo
StatusSign InGet API Access
Legal

Business Associate Agreement

Required for all OnePath Connect production integrations. Executed in 1–2 business days.

What is a Business Associate Agreement?

Under HIPAA, a Business Associate Agreement ("BAA") is a legally required contract between a Covered Entity (or Business Associate) and a vendor that will receive, process, or transmit Protected Health Information ("PHI") on the Covered Entity's behalf.

When you use OnePath Connect to submit or retrieve PHI, OnePath functions as your Business Associate under 45 CFR §160.103. Federal law requires a BAA be executed and in place before any PHI is exchanged. Operating without a BAA would constitute a HIPAA violation for both parties.

Who Needs a BAA with OnePath?

You need a BAA if you are a:

  • HIPAA Covered Entity — a healthcare provider that transmits health information electronically, a health plan, or a healthcare clearinghouse
  • Business Associate — an organization that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity and that will pass PHI to OnePath Connect for processing

Sandbox Access Without PHI

Sandbox access is available without a BAA. You must not submit real PHI in the sandbox. All sandbox data must be de-identified per 45 CFR §164.514 or entirely synthetic.

What's Covered

What OnePath's BAA covers

The OnePath standard BAA satisfies the requirements of 45 CFR §164.504(e) and the HITECH Act.

  • OnePath's permitted uses and disclosures of PHI on your behalf
  • OnePath's obligations to safeguard PHI using HIPAA-required safeguards
  • Breach notification timelines and procedures
  • PHI return or destruction upon termination of the partnership
  • Subcontractor Business Associate obligations (our infrastructure providers)
  • Your rights to audit OnePath's compliance
  • Provisions required by the HITECH Act and Omnibus Rule

Process

How to execute a BAA with OnePath

1

Request a BAA

Submit a partner access request through our website or contact partners@onepath.health. Indicate you require a BAA and provide your organization's legal name and contact.

2

Review (1–2 business days)

Our legal and compliance team sends you the OnePath standard BAA for review. We can discuss material concerns with your legal team. We do not accept fully custom BAA language in most cases.

3

Execute electronically

BAAs are executed via DocuSign or equivalent e-signature platform. We require a signature from an individual authorized to bind your organization legally.

4

Receive API credentials

Once the executed BAA is on file, your partner application is provisioned and we issue production API credentials. Sandbox access is available immediately during BAA review.

FAQ

Common questions

Can I use OnePath Connect if I'm not a Covered Entity?

If your organization processes PHI as a Business Associate on behalf of a Covered Entity, you still need a BAA. If you are not handling PHI in any form, standard API terms may apply. Contact us to discuss your situation.

Does OnePath accept third-party or custom BAA templates?

We use our own standard BAA that accurately reflects the technical architecture of OnePath Connect. We can discuss material concerns. Fully custom BAAs significantly extend the contracting timeline.

How long does the BAA process take?

Typically 1–3 business days from submission to execution, assuming no material redlines. We send via DocuSign and can usually turn it around the same day we receive countersignature.

Can I start building while the BAA is being reviewed?

Yes. Sandbox API access is available immediately upon partner application approval. Develop and test using de-identified or synthetic data while the BAA review is underway.

Ready to execute your BAA?

Submit a partner access request and we'll have your BAA to you within one business day.

Request Partner Access Email Us Directly
OnePath logoOnePathConnect

HIPAA-compliant health intelligence API for any organization working with health data.

Status

Product

DocsPlatformChangelogStatusUse Cases

Developers

Getting StartedAPI ReferenceSDKsWebhooksError Reference

Company

AboutSecurityContactLinkedIn

Legal

Privacy PolicyTerms of ServiceHIPAA ComplianceBAA InformationSecurity Disclosure

© 2026 OnePath Health, Inc. All rights reserved.

HIPAA-compliant · FHIR R4 native · SOC 2 in progress