We've been seeing more vendors, customers, and prospects asking about HIPAA compliant email services. Since Paubox is a Business Associate to thousands of customers, we’ve been wondering if they are able to use Squarespace in a HIPAA compliant manner. We know the HIPAA industry is vast, so we can empathize with just how many people need to use cloud services in this sector. Today we will determine if Squarespace offers HIPAA compliant service or not.
Squarespace is a SaaS company that provides website building and hosting services. The company is headquartered in New York City. If you have your website hosted by Squarespace and wish to integrate it with a HIPAA compliant email marketing service, this will be important information.
What is a Business Associate?
A Business Associate is a person or company that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) for a Covered Entity. In a nutshell, the role of a Business Associate is to help Covered Entities comply with the HIPAA Privacy Rule Read full article: What does it mean to be a Business Associate?
Business Associate Agreement provisions
If a Business Associate provides services to a Covered Entity, then a Business Associate Agreement (BAA) must be in place. A BAA is a written contract between a Covered Entity and a Business Associate and is required by law for HIPAA compliance. At a minimum, a Business Associate Agreement contains 10 provisions. Read full article: Business Associate Agreement Provisions
Squarespace and the Business Associate AgreementWe checked the Squarespace site for mention of their ability to sign a Business Associate Agreement (BAA). We quickly found the information we were looking for on a page called " Squarespace and HIPAA." On that page, we see the following language:
Squarespace Scheduling is designed to allow you to comply with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. Other parts of the Squarespace platform, including contact form features like the Form Block, can't be used as part of a HIPAA compliant solution. To collect secure patient information online for areas outside of Scheduling, we recommend linking to an external, compliant service.
In a nutshell, only a limited portion of Squarespace can be configured to be HIPAA compliant.
Does Squarespace offer HIPAA Compliant Service?
The Business Associate Agreement (BAA) is a key component to HIPAA compliance between a Covered Entity and a Business Associate. Conclusion: Squarespace does a Business Associate Agreement with its customers, but only for a single service, Squarespace Scheduling. Squarespace can be configured to a HIPAA compliant provider, but only for a single product: Squarespace Scheduling