Business Associate Agreement
Overview
DashboardFox is designed with the security architecture and controls necessary to support HIPAA-regulated workloads. For healthcare customers who need to connect protected health information (PHI) to DashboardFox, we offer a Business Associate Agreement (BAA) on request.
Plan eligibility. The BAA is available to customers on the Enterprise plan (Dedicated Cloud) with the Compliance Tier, where PHI is processed on a dedicated server and dedicated database that serve your organization alone. It is not offered on Starter, Growth, or Scale plans, which run on shared infrastructure. Reviewers can start with our security review kit.
my.dashboardfox.app / my-eu.dashboardfox.app). Self-hosted and on-premise deployments of DashboardFox run entirely on your own infrastructure — 5000fish has no access to your data and is not a business associate for those deployments. Self-hosted customers do not need a BAA from 5000fish; your own HIPAA obligations for data on your infrastructure are governed by your internal policies and any agreements with your own infrastructure providers.
What is a BAA?
The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities — such as healthcare providers, health plans, and healthcare clearinghouses — to have a signed Business Associate Agreement in place with any vendor that creates, receives, maintains, or transmits protected health information (PHI) on their behalf.
A BAA is a legal contract that establishes the permitted uses and disclosures of PHI, sets out each party's responsibilities for safeguarding that data, and documents the vendor's commitment to HIPAA compliance. Without a signed BAA, a covered entity cannot lawfully use a third-party service to process PHI.
Who needs a BAA?
You need a BAA with DashboardFox if you are a HIPAA-covered entity or business associate and you intend to connect data sources containing PHI to your DashboardFox workspace. Common examples include:
- Healthcare providers reporting on patient records, appointments, or billing data
- Health plans or insurers analyzing claims or member data
- Healthcare SaaS companies embedding DashboardFox to report on data that includes PHI
- Business associates of covered entities whose reporting workflows involve PHI
If you are unsure whether your use case requires a BAA, consult your compliance or legal counsel. As a general rule: if the data you are connecting to DashboardFox could include individually identifiable health information, a BAA is required.
Who does not need a BAA?
A BAA is not required if your DashboardFox workspace does not process PHI. Healthcare-adjacent organizations that connect only de-identified, aggregated, or non-clinical data to DashboardFox do not need a BAA, provided they are confident the data does not meet HIPAA's definition of PHI.
Our approach to HIPAA
DashboardFox is built on an architecture designed to support HIPAA compliance:
- Isolated workspaces — every customer workspace runs in a dedicated, isolated PostgreSQL database. PHI in one workspace is fully segregated from all other customers.
- Encryption — data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access controls — role-based access, audit logging, and session management are built into the platform.
- Annual penetration testing — conducted to validate security controls.
- Cyber liability insurance — maintained by 5000fish, Inc.
Signing a BAA does not automatically make your DashboardFox deployment HIPAA-compliant — your organization remains responsible for configuring the platform appropriately, managing user access, and ensuring your connected data sources meet HIPAA requirements. We are a tool; HIPAA compliance is a shared responsibility.
How to request a BAA
Email [email protected] with the subject line "BAA Request" and include:
- Your organization name and DashboardFox account email
- A brief description of the PHI you intend to process within DashboardFox
We will review your request and respond within 2 business days. BAAs are available to customers on any paid plan.
To request a BAA or ask about HIPAA compliance:
[email protected]5000fish, Inc., 2201 Cooperative Way Drive, STE 600, Herndon, VA 20171, United States
