Will Athena sign a Business Associate Agreement (BAA)?
Yes. Athena Security will sign a Business Associate Agreement and has executed BAAs with healthcare customers in the past. We understand that hospitals and health systems must comply with HIPAA, and we're committed to supporting that obligation wherever our technology or services could touch protected health information (PHI).
It's worth noting that Athena's PHI footprint is intentionally minimal. We never collect or store medical records. The only data combination that constitutes PHI in our platform is a room number paired with personally identifiable information (such as a visitor destination in a hospital setting) — and even that is configurable.
Beyond signing the BAA itself, Athena supports HIPAA compliance through:
- Data minimization by design — our systems are built to screen for threats and manage visitors, not to collect health information. We never store medical records, diagnoses, or treatment data. Our only potential PHI exposure is a room number associated with PII.
- Zero-knowledge architecture — even Athena can't read your data — all PII and PHI is encrypted on the tablet at the point of capture, and the private encryption key remains on the tablet, never in the cloud. Cloud-based reports display only a first name and last initial; the remaining data is cryptographically unreadable to anyone without the key — including Athena employees. Your data stays under the hospital's control at all times, even when it transits our infrastructure.
- Customer-controlled data retention — you decide which data points are kept and which are never sent to the cloud. If your compliance posture requires it, PHI-constituting fields (like room numbers) can be excluded from cloud transmission entirely, keeping Athena outside the scope of PHI handling altogether.
- Local-only badge printing option — the hospital decides what happens when a visitor badge is printed: the record can be sent to the cloud for storage, or processed and deleted entirely on the local tablet so the data never touches the cloud. This gives your compliance team full control over where — or whether — visitor data ever leaves the building.
- Automatic PHI detection and redaction — across both our Weapons Detection System (WDS) and Visitor Management System (VMS), every data field is scanned for PHI that may have been accidentally entered into the wrong field. When detected, the data is immediately masked and permanently erased — only asterisks (******) and the violation type remain visible. An alert is sent to the console with a full audit trail, including the station and user involved. The workflow continues uninterrupted for the user, so there is no feedback that would allow anyone to probe or circumvent the detection logic.
- Security safeguards — encryption of data in transit and at rest, role-based access controls, and audit logging across our platform.
- Breach notification commitments — clear procedures and timelines for notifying your organization in the unlikely event of a security incident, consistent with the HIPAA Breach Notification Rule.
- Subcontractor flow-down — any subcontractors who could access covered data are held to equivalent BAA obligations.
- Flexibility on paper — we can execute your organization's standard BAA template or provide ours, whichever your legal and compliance teams prefer.
We're happy to have our team walk through the agreement and our security architecture with your privacy officer or compliance department during procurement.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article