TigerConnect is a healthcare communication and workflow platform that provides secure messaging, clinical collaboration, physician scheduling, patient engagement, and integrations with electronic health record systems.
Is TigerConnect HIPAA compliant? Yes, based on our research, TigerConnect is HIPAA compliant.
What changed this year?
In April 2026, TigerConnect published an updated business associate agreement. The current agreement continues to cover TigerConnect’s handling of PHI under its services agreement and does not appear to narrow the company’s HIPAA coverage.
The updated BAA also expressly addresses device and database encryption, records protected under 42 CFR Part 2, de-identified information, subcontractor obligations, and a contractual limitation of liability. TigerConnect continues to describe its Clinical Collaboration Platform as HIPAA compliant.
Will TigerConnect sign a business associate agreement (BAA)?
Yes, TigerConnect offers a BAA, as mentioned above.
The BAA supplements the customer’s services agreement. It identifies the customer as either a covered entity or business associate and TigerConnect as either a business associate or subcontractor, depending on the relationship.
What does the TigerConnect BAA cover?
The TigerConnect BAA governs the PHI TigerConnect creates, receives, maintains, or transmits while providing services to a customer.
The agreement states, “TigerConnect may only Use or disclose PHI as specified in this BAA and as necessary to perform the services set forth in the Services Agreement between the parties.”
The BAA covers:
- Permitted uses and disclosures of PHI
- Administrative, physical, and technical safeguards
- Encryption of devices, databases, backups, and archives containing PHI
- Reporting breaches and security incidents
- Subcontractors that handle PHI
- Patient access and amendment requests
- Accounting of disclosures
- Access by the HHS Secretary
- Minimum necessary requirements
- Data aggregation for healthcare operations
- Records protected under 42 CFR Part 2
- Return, destruction, or continued protection of PHI after termination
TigerConnect also agrees to “Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI,” and to ensure that subcontractors handling PHI accept restrictions consistent with those imposed on TigerConnect.
What does the TigerConnect BAA exclude?
The BAA applies only to PHI handled in connection with services covered by the customer’s services agreement. It does not automatically extend to information or services outside that contractual relationship.
The agreement also excludes properly de-identified information from its scope, stating that the BAA “applies solely to PHI and does not apply to De-Identified Information,” provided the information was de-identified in compliance with applicable law and the recipient cannot re-identify the individual.
TigerConnect may create de-identified information from customer PHI and retain ownership claims over the resulting information, provided it does not attempt to re-identify it or disclose a re-identification key.
Upon termination, TigerConnect generally must return or destroy PHI. However, the BAA says TigerConnect is not required to erase PHI-containing metadata or information stored on disaster-recovery tapes or backup media when deletion is not feasible. The company must continue protecting that information and restrict further use or disclosure.
The BAA also limits TigerConnect’s total cumulative liability connected with the agreement to $5 million. Healthcare organizations should review this provision alongside the services agreement and their own risk-management requirements.
Conclusion
TigerConnect offers a BAA and is HIPAA compliant when the platform is covered by the applicable services agreement, properly configured, and used in accordance with HIPAA and the organization’s policies.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a BAA?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information.
HIPAA is designed to protect the privacy and security of individuals’ health information and ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities and business associates.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates that perform certain functions or activities involving PHI for or on behalf of covered entities.
