Patient documents that are never transmitted
Most online file tools cannot lawfully touch protected health information, because using one means disclosing PHI to a vendor. The usual workaround is a Business Associate Agreement. The better answer is not to disclose it: these tools run inside your browser, so no third party receives the document.
HIPAA, and what a Business Associate Agreement is actually for
A BAA exists to govern a vendor that receives PHI on your behalf. Software that processes a file entirely on your own device is not receiving it — the same way a BAA is not required for the PDF reader already installed on your computer. Note the boundary carefully: this reasoning covers our in-browser tools only, and stops at anything that touches our servers.
The everyday jobs
Where we can’t help
- This is not legal advice and not a compliance certification. Your privacy officer decides what your organisation may use, and they should read this page before you rely on it.
- The reasoning covers our in-browser tools only. Anything that runs on our servers — the AI features, server-side Office conversion, OCR — is a disclosure and is out of scope. Those tools say so on their own pages.
- We do not offer a BAA today. If your policy requires one regardless of architecture, we are not yet the right fit.
Your toolkit
The 12 tools this work actually reaches for, out of 80.
The strongest privacy control is not transmitting the file. That is the default here.
Start redactingAlso written for