What the BAA covers.
The Wendesk Business Associate Addendum is a written contract that sets the safeguards Wendesk maintains over Protected Health Information (PHI) as a Business Associate under the HIPAA Privacy and Security Rules. Material commitments:
- PHI auto-redaction before any AI inference call — tenant data is scrubbed of identifiers before it leaves our trust boundary toward third-party model providers.
- Audit log retention 6 years for healthcare tenants (vs 1–7 years for other plan tiers).
- AES-256-GCM at rest with AWS KMS Customer Managed Keys; per-tenant data encryption keys; TLS 1.3 in transit.
- Sub-processor PHI controls — every sub-processor handling PHI signs a back-to-back BAA; tenants get 30 days advance notice before any new sub-processor is engaged.
- Breach notification within 60 days of discovery to the Covered Entity (45 CFR § 164.410); forensic detail supplied to the Covered Entity for their HHS / individual notifications.
BAA available on Pro and Enterprise tiers. Email [email protected] with your workspace ID and we counter-sign within 5 working days. Free of charge.
Read this first. This page describes our BAA program. The full executed BAA is provided privately under NDA after a Pro+ contract is in place. Email [email protected] with subject "BAA Request" to receive: (a) the unsigned BAA template for review, (b) the security questionnaire (SIG Lite + CAIQ), (c) coordination with your covered-entity counsel for execution.
What's covered when you sign.#
When the BAA is executed, Wendesk commits to the following safeguards over PHI as a Business Associate under the HIPAA Privacy and Security Rules. These are summarized here for transparency; the binding contract clauses live in the executed BAA itself.
- PHI auto-redaction before any AI inference call — tenant data is scrubbed of identifiers before it leaves our trust boundary toward third-party model providers.
- Audit log retention 6 years for healthcare tenants (vs 1–7 years for other plan tiers).
- Encryption posture: AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit at every hop.
- Breach notification within 60 days to the HHS Secretary; immediate notification for breaches affecting ≥500 records (per HIPAA Breach Notification Rule).
- Sub-processor restrictions — only sub-processors that themselves sign a BAA receive PHI access.
- Dedicated database isolation for healthcare Enterprise tenants (per ADR-0003).
How to request.#
Email [email protected] with subject "BAA Request" and include: your business name; the workspace slug or signup intent; the role of the person executing the BAA (CEO, COO, Compliance Officer); and your covered-entity status (provider, health plan, healthcare clearinghouse). We return the unsigned template, security questionnaire, and counter-sign within 5 business days of receiving the executed copy.
Plan eligibility: BAA is available on Pro and Enterprise plans. Free Lite, Base, Starter, and Growth tiers do not include BAA execution because the per-tenant isolation primitives required for HIPAA compliance are gated above. Talk to [email protected] if you need to negotiate an exception under a CustomPlan.
1. What the BAA Covers#
The Wendesk BAA is a written contract that sets the safeguards Wendesk maintains over Protected Health Information (PHI) as a Business Associate under the HIPAA Privacy and Security Rules.
Material commitments made by Wendesk as Business Associate:
- PHI auto-redaction before any AI inference call — tenant data is scrubbed of identifiers (names, dates of birth, geographic data, phone numbers, email addresses, SSN, MRN, and the other 16 HIPAA identifiers) before it leaves our trust boundary toward third-party model providers. Use the on-platform self-hosted Llama route for prompts that legitimately require PHI context.
- Audit log retention 6 years for healthcare tenants, covering all access, modification, disclosure, and administrative events on PHI. Logs are cryptographically signed and tamper-evident.
- Encryption posture: AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit at every hop — storage, inter-service calls, backup, and archival.
- Breach notification within 60 days to the HHS Secretary; immediate internal escalation for any suspected breach; notification to affected individuals without unreasonable delay.
- Sub-processor restrictions — every sub-processor that receives PHI is itself bound by a Business Associate Agreement. The current list is published at
/sub-processorswith the BAA-eligible subset flagged. - Dedicated database isolation for healthcare Enterprise tenants (per ADR-0003
DEDICATED_DBstrategy), ensuring PHI never co-mingles with data of non-healthcare tenants. - Minimum necessary standard — Wendesk personnel access PHI only to the minimum extent necessary to carry out service obligations (support, incident response, legal compliance).
- Workforce training and access controls — all Wendesk personnel with potential PHI access receive HIPAA privacy and security training. Access is role-based, least-privilege, and reviewed quarterly.
Encryption
All tenant data is protected with AES-256-GCM with AWS KMS-managed Customer Managed Keys; per-tenant DEK; TLS 1.3 in transit. Each tenant is issued a dedicated data encryption key (DEK) wrapped by a Customer Managed Key (CMK) in AWS KMS; integration credentials and AI BYOK keys are encrypted with the same envelope and never logged.
2. How to Request#
Email [email protected] with:
- Your business name and workspace slug (or signup intent if not yet activated).
- The role of the person executing the BAA (CEO, COO, Compliance Officer, Privacy Officer, or equivalent).
- Your covered-entity status: provider, health plan, or healthcare clearinghouse.
- A brief description of the PHI categories you intend to process via Wendesk.
We return a counter-signed BAA within 5 working days.
Plan eligibility: BAA is available on Pro and Enterprise plans only. Free Lite, Base, Starter, and Growth tiers do not include BAA execution because the per-tenant isolation primitives required for HIPAA compliance (dedicated database isolation, 6-year audit retention, enhanced breach-notification workflows) are gated above those plan thresholds. Talk to [email protected] if you need to negotiate an exception under a CustomPlan.
3. Breach Notification#
For HIPAA-specific obligations:
| Event | Timeline |
|---|---|
| Discovery of a breach | Internal escalation: within 1 hour |
| Notification to HHS Secretary (small breach) | Within 60 days of end of calendar year |
| Notification to HHS Secretary (breach ≥ 500 records) | Without unreasonable delay; within 60 days of discovery |
| Notification to affected individuals | Without unreasonable delay; within 60 days of discovery |
| Notification to prominent media (breach ≥ 500 residents in a state) | Without unreasonable delay; within 60 days of discovery |
The cross-regime breach-notification matrix (DPDP 72h, GDPR 72h, HIPAA 60d) is published in the central matrix below for cross-reference.
Breach notification.
| Regime | To regulator | To affected person |
|---|---|---|
| DPDP (India) | 72 hours to the Data Protection Board | Without undue delay; via in-app banner + email |
| GDPR (EU/EEA) | Without undue delay; within 72 hours to the lead supervisory authority | Without undue delay where high risk to rights and freedoms |
| HIPAA (US healthcare) | As Business Associate, Wendesk notifies the Covered Entity without unreasonable delay and within 60 days of discovery (45 CFR §164.410); the Covered Entity then notifies HHS, individuals, and (≥500 records in a state) media per §164.404 | Customer-facing notice runs from the Covered Entity; Wendesk supplies forensic detail under the BAA |
4. Sub-Processor PHI Controls#
Only sub-processors that have executed a Business Associate Agreement receive access to PHI. Wendesk maintains a documented list of BAA-eligible sub-processors and reviews it quarterly. The current list of all sub-processors is below; BAA-eligibility for PHI workloads is annotated separately on the /sub-processors page.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | Compute, RDS PostgreSQL, S3, KMS, Bedrock | AWS Mumbai (ap-south-1) |
| MongoDB Atlas | Database | Tenant business data (CRM, content, integrations) | AWS Mumbai (ap-south-1) |
| ClickHouse Cloud | Analytics database | High-volume activity logs (non-PII) | AWS Mumbai (ap-south-1) |
| Razorpay | Payments | Card tokenisation, UPI, net-banking, subscription billing | India |
| MSG91 | SMS gateway | OTP and transactional SMS | India |
| Twilio | Voice / messaging | WhatsApp Business API, voice fallback, programmable SMS | USA / Ireland (per region) |
| OpenAI | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Anthropic | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Google AI | AI inference | Gemini completions when routed via quota router | USA / Ireland |
| AWS Bedrock | AI inference | Default LLM provider for India tenants (Claude, Llama, Titan) | AWS Mumbai (ap-south-1) |
| Sarvam AI | AI inference | Indic-language LLM and TTS for vernacular features | India |
| Firebase | Authentication | Phone OTP delivery and Google OAuth for L7 marketplace customers | USA / multi-region |
| Cloudflare | CDN, DNS, WAF | DDoS mitigation, edge cache, custom-domain SSL for white-label tenants | Global edge |
| Typesense | Search | Full-text search index for marketplace and CRM (no PII indexed) | AWS Mumbai (ap-south-1) |
New PHI-touching sub-processors trigger a 30-day notice to healthcare tenants before data flows begin, in addition to the standard sub-processor change notification.
5. Security Rule Compliance#
Wendesk's technical safeguards for healthcare tenants include:
- Access controls: Unique user identification; automatic logoff after inactivity; emergency access procedures documented and tested annually.
- Audit controls: Hardware, software, and procedural mechanisms that record and examine activity in information systems containing PHI.
- Integrity: Electronic mechanisms to corroborate that PHI has not been altered or destroyed in an unauthorized manner (cryptographic checksums + tamper-evident logs).
- Transmission security: AES-256-GCM encryption for all PHI at rest; TLS 1.3 for all PHI in transit; no unencrypted PHI in logs, error messages, or cache.
6. Effective Date and Term#
This BAA supplement is effective upon counter-signature by Wendesk. It remains in force for the duration of the principal Terms of Service and survives termination for the period required to complete destruction or return of PHI.