Business Associate Agreement FAQ
How the BAA works at Nem, in plain language.
Last updated June 28, 2026
What is a BAA and why do I need one?+
HIPAA requires a Business Associate Agreement between your clinic (the covered entity) and any vendor that handles Protected Health Information on your behalf, including Nem. It defines how Nem may use PHI, how it is protected, and what happens if something goes wrong. Without it, neither party may lawfully exchange patient data.
When does the BAA apply and take effect?+
Before any real patient data enters your account. Your organization owner reviews and accepts the agreement inside Nem; until then, your workspace runs on demo or synthetic data only. Acceptance is recorded with the version, timestamp, and accepting user.
Who in my clinic can accept it?+
Only your organization owner, or a role you explicitly grant organization-settings management. Staff accounts use the platform normally but cannot accept legal agreements on the organization’s behalf. This keeps a single accountable signer for PHI handling.
What happens when the BAA is updated?+
You are notified in-app and by email and given a review window. The prior version stays in force until your owner accepts the new one, so material changes never apply silently. Every version is archived and available for download.
Which subprocessors sit behind Nem?+
Retell AI (voice) and Google Workspace (business email and documents) already operate under executed BAAs with Nem, signed in July 2026. The remaining PHI-touching infrastructure (Vercel and Neon) signs a BAA before your live data is onboarded, and AWS is executed at account setup. PHI-free services (Resend and PostHog) never receive patient data. The current list, with BAA status, is public on our Trust Center.
What if we do not renew or accept a new version?+
Your data is not deleted for this reason. If a review window lapses without acceptance, the platform is designed to pause two specific actions: bulk imports of patient data and adding new people to your clinic. Everything else keeps working without interruption, including reading and exporting records, documenting patient care, the voice agent booking appointments, and accepting the update itself. Deletion only ever follows our published retention policy, not a lapsed agreement.
How do I request the BAA?+
Email info@nemsol.org or ask during onboarding. Nem provides a standard BAA that references the safeguards described on our Security page and Trust Center; qualified counsel should review it for your organization before you rely on it.
Looking for the vendor list and security posture? See our Trust Center or request the agreement at info@nemsol.org.

