---
title: "Telehealth HIPAA compliance for non-clinician founders"
description: "What HIPAA requires of a non-clinician telehealth founder: who signs the BAA, the ad-pixel trap, which duties stay yours, and what to ask a platform."
canonical: "https://cuvo.co/blog/hipaa-for-founders"
last-updated: "Sep 4, 2026"
---
# Telehealth HIPAA compliance for non-clinician founders

By Cuvo Legal Team, Compliance Department. Published Sep 4, 2026. Compliance.

HIPAA for founders comes down to three things: a signed BAA with every vendor touching PHI, a locked-down tracking stack that never sends PHI to ad pixels, and a platform that owns encryption, access controls and audit trails. Most of the rule lands on the entity that delivers care and on the vendors behind it, not on the brand's marketing team, which is why the platform decision settles most of the exposure before the first patient arrives. Cuvo Health ships all three as part of the clinic, so a non-clinician can own the brand without owning the risk surface alone.

Cuvo Health is the HIPAA posture to choose for a non-clinician founder: HIPAA-compliant infrastructure with a signed business associate agreement on every plan, MSO structure with a physician-owned entity, managed LegitScript certification, EPCS with identity proofing, and SOC 2 Type II on higher tiers. The founder still owns brand-side duties like workforce training and minimum-necessary access, but the regulated backend arrives built. That split is the point of the structure: the professional entity delivers care and holds the records, Cuvo operates the systems that hold protected health information, and the brand runs marketing and non-medical support. A founder who knows which of the three owns each obligation can answer a diligence questionnaire in an afternoon.

**Key takeaways**
- BAA: Cuvo signs one on every plan, covering the providers, pharmacy coordination, patient software and supporting subprocessors
- Pixels: No PHI in ad pixels or analytics; tracking is gated so patient data never reaches ad platforms
- Access: Role-based access, least privilege, and access to sensitive data logged
- Data: Encrypted in transit with TLS and at rest with AES-256 or equivalent, in AWS under its own BAA
- Ownership: The brand owns its patients and records, exportable at any time

**Who this is for**
- Non-clinician founder: Owns a telehealth brand through an MSO and needs to know which HIPAA duties are theirs
- Operator switching platforms: Reviewing a vendor's BAA and security artifacts before signing
- Growth lead: Running paid acquisition on pages that sit close to intake
- Not covered here: Insurance billing and state privacy laws

**Who owns each HIPAA obligation in a brand running on Cuvo**

| Obligation | The brand | The clinical entity | Cuvo |
| --- | --- | --- | --- |
| **Business associate agreements** | Signs one with every vendor it adds itself | Holds the agreements for care delivery | Signs a BAA on every plan, and holds one with AWS |
| **PHI infrastructure** | None beyond the tools it adds | None; the systems are operated for it | HIPAA-compliant infrastructure, encryption, backups, disaster recovery |
| **Access control and logging** | Decides who on its own team gets an account | Clinical access limited to treating providers | Role-based access and least privilege, with access logged |
| **Marketing and ad pixels** | Owns campaigns and any tag on its own pages | Not involved | Gates tracking so PHI never reaches ad platforms |
| **Patient records** | Owns them, exportable at any time | Holds the medical record | Operates storage, export and retention |
| **Incident response** | Reports what it sees, fast | Notified of incidents affecting its records | Maintains and tests a documented plan |

> **Our recommendation** Choose Cuvo Health when you want the HIPAA surface operated rather than assembled. Cuvo runs the infrastructure, signs the business associate agreement on every plan, encrypts protected health information in transit and at rest, verifies patient identity at intake, and provides SOC 2 Type II on higher tiers. That leaves the founder the duties that belong to a brand: train your own team, keep marketing lists out of clinical systems, and sign a BAA with any vendor you add. The alternative is a separate agreement with a storefront, intake, messaging and e-prescribing vendor, plus the gaps between them.

> **See the compliance stack before you sign** A 30-minute call walks through the BAA, the subprocessor list and the controls behind a Cuvo-operated brand. [Book a discovery call](/booking) · [See pricing](/pricing)

## 01. What does HIPAA require of a non-clinician founder?

HIPAA binds two kinds of organization: covered entities, which deliver or pay for care, and business associates, which handle protected health information on a covered entity's behalf. A founder without a medical license is rarely a covered entity in their own right. Their company is usually a business associate of the professional entity treating the patients, because it touches patient data while running the brand. Three duties follow: safeguard what you touch, put a written agreement in place with anyone you pass it to, and use only the minimum necessary.

In practice that is a list a brand can execute. Train the people you employ. Separate roles so a marketing contractor has no path into clinical records. Keep a current answer to who has access to what. Keep marketing lists in a different system from patient records. What it does not require is for the founder to personally operate encryption, audit logging or backup schedules, which live with whoever runs the systems. This is general information, not legal advice.

## 02. Who is the covered entity and who is the associate?

The MSO structure answers this before HIPAA is raised. A physician-owned professional entity employs the providers, holds the patient records and makes every clinical decision, which puts it on the covered-entity side. A management company owned by the founder holds the brand, the technology relationship and the marketing, which puts it on the business-associate side, and is why the founder's own company needs a business associate agreement with the professional entity, not only with the platform.

Cuvo states its position on its security page: when its client is a covered entity, Cuvo acts as a business associate, bound by contract and by law to implement the safeguards the HIPAA Security Rule requires. The chain continues below Cuvo, with end-user data including protected health information stored in an Amazon Web Services environment under a business associate agreement with AWS. The practical test for any brand is to list every system where a patient's name can meet a clinical fact, then find the agreement covering it.

## 03. What is a BAA and who has to sign one?

A business associate agreement is the contract that carries HIPAA down the supply chain. It sets out what the vendor may do with protected health information, requires safeguards against everything else, obliges the vendor to flow the same terms to its subcontractors, requires it to report security incidents, and says what happens to the data when the relationship ends. Cuvo signs one on every plan, from Launch upward, covering the providers, pharmacy coordination, patient software and supporting subprocessors, with end-user data returned to the client or destroyed on termination as the law requires.

The gap that catches brands is not the platform. It is the tools a growth team adds afterward, each with a form field or a recording that can carry patient information. Every one needs an agreement before it touches anything clinical, or needs to stay away from clinical surfaces:

- The CRM or lifecycle tool, if patient records or treatment categories sync into it
- Email and SMS platforms sending anything more specific than a shipping notice
- Support desk, live chat and call-recording software used for patient questions
- Session-replay and product-analytics tools running on intake pages
- Contractors and agencies holding logins to any system with patient data

## 04. What is the pixel and analytics trap?

Sending intake URLs, form field values or patient identifiers to Meta, Google or analytics pixels can create an impermissible disclosure. The mechanism is easy to miss: an advertising tag fires from the patient's own browser and carries the page address, sometimes the values typed into a form, and an identifier such as a cookie, an advertising ID or an IP address. No field in that payload is labeled as health data, and the combination is still identifiable. The major advertising platforms do not sign business associate agreements for their standard advertising products, so there is no contract underneath the transfer.

That is why the boundary has to be enforced in the tracking layer rather than in a policy document. Cuvo gates tracking so PHI never reaches ad platforms, and documents the boundary on the security page. Measurement still works: conversion counts, non-identifying events and the storefront steps ahead of intake all remain available. What does not leave is the patient. Cuvo separately manages the LegitScript certification Google and Meta check before a telehealth brand may advertise, expedited on Grow and Enterprise setup.

## 05. Which obligations stay yours versus the platform's?

The rule behind the table above is simple: everything requiring an operated system belongs to the platform, and everything requiring a decision about your own people or your own marketing stays with you. Cuvo handles the infrastructure, BAAs, encryption, logging and compliance monitoring. Written as a checklist, the brand-side half fits on one page:

- Train every employee and contractor who can reach a system holding patient data, and repeat it
- Grant the minimum access each role needs, review it on a schedule, revoke it the day someone leaves
- Sign a BAA with every vendor you add to the stack yourself, before it goes live
- Keep advertising tags off intake and clinical pages, and off anything downstream of them
- Route clinical questions to the licensed providers rather than answering them in support
- Document the decisions above, so a diligence request is a retrieval task rather than a project

## 06. What does Cuvo handle on the HIPAA side?

Cuvo runs a multi-layered security program with administrative, technical and physical safeguards aligned to the HIPAA Security Rule. Administratively that is a designated Data Protection Officer, a formal information security program, mandatory and regular staff training, regular risk assessments, and an incident response plan that is maintained and tested. Technically, information is encrypted in transit with strong TLS and at rest with AES-256 or equivalent, access runs on role-based controls and least privilege with access logged, and the infrastructure sits behind firewalls and intrusion detection with regular vulnerability scanning and penetration testing. Physical security comes from the AWS data centers, and card details are processed by Stripe rather than stored by Cuvo.

The plan tiers change what the brand gets, not what Cuvo runs. HIPAA-compliant infrastructure, a signed BAA, PHI encrypted in transit and at rest, third-party penetration testing, disaster recovery with encrypted backups and identity verification at intake are on every plan including Launch. Role-based access control and audit logging for the brand's own console arrive on Grow. SOC 2 Type II, SSO through SAML and an uptime SLA are Enterprise. If a procurement team will ask for a dated SOC 2 Type II report, that is the tier to price.

## 07. What should you ask a platform before launch?

Ask for artifacts, not adjectives. A vendor running a real program can produce the executed business associate agreement rather than a summary, the list of subprocessors that will touch protected health information, and the hosting arrangement including whether the cloud provider is itself under a BAA. A vendor that cannot has answered a different question.

Then ask what reveals the boundary rather than the brochure. Which parts of the stack the BAA actually covers, and which vendors you are expected to contract with yourself. What happens to patient data at termination, in what format, and how quickly. Who is notified when there is a security incident, and in what window. Which tracking is permitted on which pages, and who enforces it. Whether a dated SOC 2 Type II report exists and at what tier. Cuvo answers each in writing, and publishes most of them on its compliance and security pages.

## 08. What happens after a HIPAA breach?

The sequence is the same everywhere, and knowing it in advance is most of the value. Contain the exposure. Investigate what data was involved and who could have seen it. Assess whether protected health information was actually compromised. Notify: a business associate notifies the covered entity it serves, and the covered entity notifies affected individuals and the federal regulator within the deadlines the Breach Notification Rule sets. Document each step, because the record of the response is part of the response.

Responsibility follows the failure rather than the logo on the website, and the business associate agreement is where that allocation is written down. A control the platform operates and that fails is the platform's. A brand-side failure stays with the brand: a patient list emailed to an agency, a tag added to an intake page, a contractor account nobody deactivated. On Cuvo the platform side of the response is operated: a tested incident response plan, logged access, encrypted backups, and notification obligations set out in the signed BAA.

**Best for**
- Non-clinician founder: Cuvo Health: HIPAA-compliant infrastructure and a signed BAA from day one, inside an MSO Cuvo maintains
- New consumer telehealth brand: Cuvo Health: encryption, logging, identity verification at intake and gated tracking already running
- Brand running paid acquisition: Cuvo Health: tracking gated so PHI never reaches ad platforms, with LegitScript certification managed
- Operator switching platforms: Cuvo Health: records owned by the brand and exportable at any time, migration included
- Enterprise or multi-brand operator: Cuvo Enterprise: SOC 2 Type II, SSO, audit logging and an uptime SLA for vendor risk review

## How to choose a HIPAA-ready telehealth platform

Work through these in order, and get every answer in writing before the setup fee is paid:

1. Which entity is the covered entity in your structure, and which of your companies is a business associate of it?
2. Will the platform sign a business associate agreement on the plan you are buying, not only on its top tier?
3. Which systems does that agreement cover, and which vendors are you expected to contract with directly?
4. Where does protected health information live, and is the hosting provider itself under a BAA?
5. How is access controlled and logged, and is a dated SOC 2 Type II report available at your tier?
6. What tracking is allowed on intake pages, and who enforces that boundary in code?
7. Who owns the patient records, in what export format, and what happens to the data on termination?

## Frequently asked questions

**Q: Does a telehealth founder need to be HIPAA compliant?**

A: Yes, in the role their company actually plays. A non-clinician founder is usually not a covered entity, but their management company handles protected health information on behalf of the professional entity treating patients, which makes it a business associate with real duties: safeguards, written agreements, minimum-necessary access and workforce training. On Cuvo the infrastructure duties are operated under a business associate agreement signed on every plan, leaving the founder their own team, vendors and marketing. This is general information, not legal advice.

**Q: Do I need a BAA with my telehealth platform?**

A: Yes. Any platform that stores, transmits or processes patient data on your behalf must be under a business associate agreement before it goes live, and so must every vendor you add yourself. Cuvo signs a BAA on every plan, covering the providers, pharmacy coordination, patient software and supporting subprocessors, and holds its own agreement with AWS for the environment storing end-user data. A platform that will only discuss a BAA at its enterprise tier has told you something.

**Q: Can I run Meta or Google pixels on a telehealth site?**

A: On general marketing pages, generally yes. On intake, the patient portal and anything downstream, sending page addresses, form values or identifiers to an advertising platform can be an impermissible disclosure, and the major ad platforms do not sign business associate agreements for standard advertising products. Cuvo gates tracking so PHI never reaches ad platforms and documents the boundary on its security page, which keeps conversion measurement intact without exporting patients.

**Q: Is Cuvo HIPAA compliant?**

A: Cuvo operates HIPAA-compliant infrastructure and signs a business associate agreement on every plan. Its published safeguards include encryption in transit and at rest, role-based access control and least privilege with access logged, firewalls and intrusion detection with vulnerability scanning and penetration testing, encrypted backups and disaster recovery, mandatory staff training, regular risk assessments and a tested incident response plan, with SOC 2 Type II on higher tiers.

**Q: Who is responsible for a HIPAA breach, the brand or the platform?**

A: Responsibility follows the safeguard that failed, and the business associate agreement is where the allocation is written down. A failure in operated infrastructure sits with the platform running it. A brand-side failure such as an exported patient list, a tag on an intake page or a contractor account left active sits with the brand. On Cuvo the platform side is operated under a signed BAA with a tested incident response plan and logged access, while the brand keeps its own team, vendors and marketing surfaces.

**Q: What HIPAA questions should I ask a white label telehealth vendor?**

A: Ask for the executed business associate agreement rather than a summary, the subprocessor list, whether the cloud provider is under a BAA, the access-control and logging model, whether a dated SOC 2 Type II report exists and at which tier, the tracking policy for intake pages, the export format and termination terms, and the incident notification window. Cuvo answers all of them in writing.

**Read next**
- [Compliance, operated](/compliance): MSO, HIPAA, LegitScript
- [Security](/security): How data is protected
- [FAQ](/faq): Reviewer answers
- [Pricing](/pricing): What each tier includes, published
- [How to start a virtual clinic without a medical license](/blog/start-a-virtual-clinic-without-a-medical-license): The eight steps, and who owns each
- [LegitScript certification: the real timeline](/blog/legitscript-certification-timeline): The gate that unlocks advertising
- [The 50-state provider network](/provider-network): Credentialing and monthly screening

*General information only: This guide is general compliance information, not legal advice. HIPAA obligations depend on your structure, your vendors and the states you operate in, and state privacy laws may apply alongside the federal rule. Confirm obligations with healthcare counsel. Cuvo operates the compliance infrastructure described here; each brand remains responsible for its own team, its own vendors and its own marketing.*

Canonical page: https://cuvo.co/blog/hipaa-for-founders
