What the BAA covers.
The Wendesk Business Associate Addendum is a written contract that sets the safeguards Wendesk maintains over Protected Health Information (PHI) as a Business Associate under the HIPAA Privacy and Security Rules. Material commitments:
- PHI auto-redaction before any AI inference call — tenant data is scrubbed of identifiers before it leaves our trust boundary toward third-party model providers.
- Audit log retention 6 years for healthcare tenants (vs 1–7 years for other plan tiers).
- AES-256-GCM at rest with AWS KMS Customer Managed Keys; per-tenant data encryption keys; TLS 1.3 in transit.
- Sub-processor PHI controls — every sub-processor handling PHI signs a back-to-back BAA; tenants get 30 days advance notice before any new sub-processor is engaged.
- Breach notification within 60 days of discovery to the Covered Entity (45 CFR § 164.410); forensic detail supplied to the Covered Entity for their HHS / individual notifications.
BAA available on Pro and Enterprise tiers. Email [email protected] with your workspace ID and we counter-sign within 5 working days. Free of charge.
पहले यह पढ़ें। यह पृष्ठ हमारे BAA कार्यक्रम का वर्णन करता है। पूर्ण executed BAA Pro+ अनुबंध होने के बाद NDA के तहत निजी रूप से प्रदान किया जाता है। विषय "BAA Request" के साथ [email protected] पर ईमेल करें और प्राप्त करें: (a) समीक्षा के लिए unsigned BAA template, (b) security questionnaire (SIG Lite + CAIQ), (c) execution के लिए आपके covered-entity counsel के साथ समन्वय।
हस्ताक्षर करने पर क्या covered होता है।#
जब BAA executed होता है, तो Wendesk HIPAA Privacy और Security Rules के तहत Business Associate के रूप में PHI पर निम्नलिखित safeguards प्रदान करने की प्रतिबद्धता लेता है। इन्हें यहाँ transparency के लिए संक्षेप में प्रस्तुत किया गया है; बाध्यकारी अनुबंध के खंड executed BAA में हैं।
- PHI auto-redaction — किसी भी AI inference call से पहले tenant data से identifiers scrub किए जाते हैं, इससे पहले कि वह third-party model providers की ओर हमारे trust boundary को छोड़े।
- Audit log retention 6 वर्ष healthcare tenants के लिए (अन्य plan tiers के लिए 1–7 वर्ष की तुलना में)।
- Encryption posture: AES-256-GCM, AWS KMS-managed Customer Managed Keys के साथ; TLS 1.3 in transit — हर hop पर।
- Breach notification 60 दिनों के भीतर HHS Secretary को; ≥500 records प्रभावित करने वाले breaches के लिए तत्काल notification (HIPAA Breach Notification Rule के अनुसार)।
- Sub-processor restrictions — केवल वे sub-processors जो स्वयं BAA sign करते हैं, PHI access प्राप्त करते हैं।
- Dedicated database isolation healthcare Enterprise tenants के लिए (ADR-0003 के अनुसार)।
Request कैसे करें।#
विषय "BAA Request" के साथ [email protected] पर ईमेल करें और शामिल करें: आपका business name; workspace slug या signup intent; BAA execute करने वाले व्यक्ति की role (CEO, COO, Compliance Officer); और आपकी covered-entity status (provider, health plan, healthcare clearinghouse)। हम executed copy प्राप्त होने के 5 कार्य दिवसों के भीतर unsigned template, security questionnaire वापस करते हैं और counter-sign करते हैं।
Plan eligibility: BAA Pro और Enterprise plans पर उपलब्ध है। Free Lite, Base, Starter, और Growth tiers में BAA execution शामिल नहीं है क्योंकि HIPAA compliance के लिए आवश्यक per-tenant isolation primitives उन plan thresholds से ऊपर gated हैं। यदि आपको CustomPlan के तहत अपवाद negotiate करना है तो [email protected] से बात करें।
1. BAA क्या Cover करता है#
Wendesk BAA एक written contract है जो HIPAA Privacy और Security Rules के तहत Business Associate के रूप में Wendesk द्वारा Protected Health Information (PHI) पर maintained safeguards को set करता है।
Wendesk के Business Associate के रूप में material commitments:
- PHI auto-redaction — किसी भी AI inference call से पहले tenant data से identifiers scrub किए जाते हैं (नाम, जन्म तिथि, geographic data, phone numbers, email addresses, SSN, MRN, और अन्य 16 HIPAA identifiers)। PHI context की वैध आवश्यकता वाले prompts के लिए on-platform self-hosted Llama route का उपयोग करें।
- Audit log retention 6 वर्ष healthcare tenants के लिए, PHI पर सभी access, modification, disclosure, और administrative events को cover करते हुए। Logs cryptographically signed और tamper-evident हैं।
- Encryption posture: AES-256-GCM, AWS KMS-managed Customer Managed Keys के साथ; TLS 1.3 in transit — हर hop पर — storage, inter-service calls, backup, और archival।
- Breach notification 60 दिनों के भीतर HHS Secretary को; किसी भी suspected breach के लिए तत्काल internal escalation; बिना अनुचित विलंब के प्रभावित individuals को notification।
- Sub-processor restrictions — हर sub-processor जो PHI receive करता है, वह स्वयं Business Associate Agreement से bound है। वर्तमान सूची
/sub-processorsपर BAA-eligible subset के साथ प्रकाशित है। - Dedicated database isolation healthcare Enterprise tenants के लिए (ADR-0003
DEDICATED_DBstrategy), यह सुनिश्चित करते हुए कि PHI non-healthcare tenants के data के साथ कभी नहीं मिलती। - Minimum necessary standard — Wendesk personnel PHI को केवल service obligations (support, incident response, legal compliance) पूरा करने के लिए आवश्यक minimum extent तक access करते हैं।
- Workforce training और access controls — PHI access की संभावना वाले सभी Wendesk personnel HIPAA privacy और security training प्राप्त करते हैं। Access role-based, least-privilege है और quarterly समीक्षा की जाती है।
एन्क्रिप्शन
सभी tenant डेटा AES-256-GCM with AWS KMS-managed Customer Managed Keys; per-tenant DEK से सुरक्षित है; ट्रांज़िट में TLS 1.3। प्रत्येक tenant को AWS KMS में एक Customer Managed Key (CMK) द्वारा wrapped एक dedicated data encryption key (DEK) जारी किया जाता है।
2. Request कैसे करें#
[email protected] पर ईमेल करें इसके साथ:
- आपका business name और workspace slug (यदि अभी activate नहीं हुआ तो signup intent)।
- BAA execute करने वाले व्यक्ति की role (CEO, COO, Compliance Officer, Privacy Officer, या समकक्ष)।
- आपकी covered-entity status: provider, health plan, या healthcare clearinghouse।
- PHI categories का brief description जो आप Wendesk के माध्यम से process करना चाहते हैं।
हम 5 working days के भीतर counter-signed BAA return करते हैं।
Plan eligibility: BAA केवल Pro और Enterprise plans पर उपलब्ध है। Free Lite, Base, Starter, और Growth tiers में BAA execution शामिल नहीं है क्योंकि HIPAA compliance के लिए आवश्यक per-tenant isolation primitives (dedicated database isolation, 6-year audit retention, enhanced breach-notification workflows) उन plan thresholds से ऊपर gated हैं। CustomPlan के तहत अपवाद negotiate करने के लिए [email protected] से बात करें।
3. Breach Notification#
HIPAA-specific obligations:
| Event | Timeline |
|---|---|
| Breach की discovery | Internal escalation: 1 घंटे के भीतर |
| HHS Secretary को notification (small breach) | Calendar year के अंत के 60 दिनों के भीतर |
| HHS Secretary को notification (breach ≥ 500 records) | बिना अनुचित विलंब के; discovery के 60 दिनों के भीतर |
| प्रभावित individuals को notification | बिना अनुचित विलंब के; discovery के 60 दिनों के भीतर |
| Prominent media को notification (राज्य में ≥ 500 residents breach) | बिना अनुचित विलंब के; discovery के 60 दिनों के भीतर |
Cross-regime breach-notification matrix (DPDP 72h, GDPR 72h, HIPAA 60d) cross-reference के लिए नीचे दिया गया है।
उल्लंघन अधिसूचना।
| व्यवस्था | नियामक को | प्रभावित व्यक्ति को |
|---|---|---|
| DPDP (India) | 72 hours to the Data Protection Board | Without undue delay; via in-app banner + email |
| GDPR (EU/EEA) | Without undue delay; within 72 hours to the lead supervisory authority | Without undue delay where high risk to rights and freedoms |
| HIPAA (US healthcare) | As Business Associate, Wendesk notifies the Covered Entity without unreasonable delay and within 60 days of discovery (45 CFR §164.410); the Covered Entity then notifies HHS, individuals, and (≥500 records in a state) media per §164.404 | Customer-facing notice runs from the Covered Entity; Wendesk supplies forensic detail under the BAA |
4. Sub-Processor PHI Controls#
केवल Business Associate Agreement execute करने वाले sub-processors को PHI access मिलती है। Wendesk BAA-eligible sub-processors की documented list maintain करता है और quarterly समीक्षा करता है। सभी sub-processors की वर्तमान सूची नीचे है; PHI workloads के लिए BAA-eligibility /sub-processors पृष्ठ पर अलग से annotated है।
| उप-प्रोसेसर | श्रेणी | उद्देश्य | स्थान |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | Compute, RDS PostgreSQL, S3, KMS, Bedrock | AWS Mumbai (ap-south-1) |
| MongoDB Atlas | Database | Tenant business data (CRM, content, integrations) | AWS Mumbai (ap-south-1) |
| ClickHouse Cloud | Analytics database | High-volume activity logs (non-PII) | AWS Mumbai (ap-south-1) |
| Razorpay | Payments | Card tokenisation, UPI, net-banking, subscription billing | India |
| MSG91 | SMS gateway | OTP and transactional SMS | India |
| Twilio | Voice / messaging | WhatsApp Business API, voice fallback, programmable SMS | USA / Ireland (per region) |
| OpenAI | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Anthropic | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Google AI | AI inference | Gemini completions when routed via quota router | USA / Ireland |
| AWS Bedrock | AI inference | Default LLM provider for India tenants (Claude, Llama, Titan) | AWS Mumbai (ap-south-1) |
| Sarvam AI | AI inference | Indic-language LLM and TTS for vernacular features | India |
| Firebase | Authentication | Phone OTP delivery and Google OAuth for L7 marketplace customers | USA / multi-region |
| Cloudflare | CDN, DNS, WAF | DDoS mitigation, edge cache, custom-domain SSL for white-label tenants | Global edge |
| Typesense | Search | Full-text search index for marketplace and CRM (no PII indexed) | AWS Mumbai (ap-south-1) |
New PHI-touching sub-processors data flows शुरू होने से पहले healthcare tenants को 30-day notice trigger करते हैं, standard sub-processor change notification के अतिरिक्त।
5. Security Rule Compliance#
Healthcare tenants के लिए Wendesk के technical safeguards:
- Access controls: Unique user identification; inactivity के बाद automatic logoff; emergency access procedures annually documented और tested।
- Audit controls: PHI वाले information systems में activity record और examine करने के hardware, software, और procedural mechanisms।
- Integrity: PHI को unauthorized तरीके से alter या destroy नहीं किया गया — यह corroborate करने के electronic mechanisms (cryptographic checksums + tamper-evident logs)।
- Transmission security: सभी PHI at rest के लिए AES-256-GCM encryption; सभी PHI in transit के लिए TLS 1.3; logs, error messages, या cache में कोई unencrypted PHI नहीं।
6. प्रभावी तिथि और अवधि#
यह BAA supplement Wendesk द्वारा counter-signature पर effective है। यह principal Terms of Service की अवधि के दौरान in force रहता है और PHI के destruction या return के लिए आवश्यक period के लिए termination के बाद भी जारी रहता है।