← Back to Home

HIPAA Responsibilities and BAA Process

Operational boundary notice · Updated August 9, 2026
No BAA is executed through this website. The public reference agreement, Request Access form, payment, and account invitation do not establish a Business Associate Agreement or authorize PHI use. Only the pharmacy-specific DocuSign envelope completed by both parties is an executed BAA.

BAA signing and activation process

  1. Request Access: the pharmacy submits business and authorized-signer information without PHI.
  2. Verification: RxRecon Pro verifies the pharmacy legal entity, approved location, administrator, and signer.
  3. DocuSign: RxRecon Pro sends a pharmacy-specific BAA and Schedule A to the authorized pharmacy signer. The pharmacy signs first, and RxRecon Pro LLC countersigns.
  4. Evidence gate: RxRecon Pro records the completed envelope ID, completion date, signer email, and agreement version. Checkout cannot be issued, and provisioning and invitation cannot occur, without that execution evidence.
  5. Activation: after payment and required safeguards are confirmed, RxRecon Pro provides written activation for the approved location. PHI use is prohibited before activation.

RxRecon Pro safeguards and limits

The application is designed to parse supported source reports locally, retain direct patient and prescriber identifiers and the re-association map in browser memory, reject raw-file payloads and unexpected fields, and send only a versioned allowlisted analytical projection with run-scoped opaque tokens to protected compute. RxRecon Pro applies access controls, tenant and pharmacy-identity checks, minimum-necessary processing, security monitoring, and the duties stated in each executed BAA.

These controls reduce exposure; they do not guarantee that every client-controlled value is free of identifiers, prevent every security incident, or make the pharmacy's devices, browser, extensions, network, source systems, workforce, printing, downloads, screenshots, clipboard, backups, or physical environment compliant. Browser-local information may remain PHI under the pharmacy's control. RxRecon Pro cannot control or assume responsibility for safeguards outside its systems.

Pharmacy responsibilities

The pharmacy remains independently responsible for its HIPAA risk analysis and risk management; lawful authority and minimum-necessary use; accurate source records; secure and patched devices, browsers, networks, source systems, and backups; unique authorized users; strong credentials and screen locks; workforce training and sanctions; physical privacy; retention and required notices; prompt access removal; and independent professional verification of all output before action.

The pharmacy must not share credentials or place PHI in filenames, free-text fields, the Request Access form, Stripe, ordinary email, support messages, or any channel not expressly approved in writing for PHI. It must notify ADMIN@RXRECONPRO.COM without unreasonable delay and no later than twenty-four (24) hours after discovering suspected credential compromise, unauthorized service access, or an impermissible submission involving the service. Do not include PHI in the initial email.

Shared compliance boundary

HIPAA compliance depends on the conduct, systems, documentation, and safeguards of both parties; it is not a one-time product certification or an absolute guarantee. RxRecon Pro remains responsible for duties imposed directly on it by HIPAA and the executed BAA. The pharmacy remains responsible for duties imposed on it as a covered entity and for its systems, workforce, instructions, and use of the service. Neither party's duties excuse the other's noncompliance.

Evaluation and prohibited use

Until the BAA is fully executed and RxRecon Pro confirms production activation in writing, use only synthetic or appropriately de-identified data. The service is not a system of record, backup, clinical decision-maker, claims system, or substitute for the pharmacy's legal, privacy, security, or professional obligations.