← Help Center

Privacy & HIPAA behavior

How Sorraia's per-site HIPAA mode works — signing your BAA, what changes when a site is HIPAA-enabled (including why AI chat is turned off), and how your data is handled.

What HIPAA mode is

HIPAA mode is a setting you turn on per site, not for your whole account. That means you can run a HIPAA-enabled intake form on one site while keeping your other sites unchanged.

You manage everything from the HIPAA settings page (the /hipaa route in your dashboard). It's only available on plans that support HIPAA, and only once your Sorraia deployment is on HIPAA-eligible hosting — if it isn't yet, the page shows a banner explaining that and keeps signing disabled until it is.

Signing your BAA

Before you can turn HIPAA on for any site, you sign one Business Associate Agreement (BAA). A single BAA covers every HIPAA-enabled site on your account, so you only do this once.

On the HIPAA settings page you can read the agreement, type your full legal name, tick the box to agree on behalf of your organization, and choose Sign BAA. The Free plan can't sign — you'll be prompted to upgrade to Starter or higher first. Once signed, the page shows who signed it, when, and the version.

Turning HIPAA on for a site

After your BAA is signed, use the link to Sites to flip the HIPAA toggle on individual sites. The site has to be a verified production site for the toggle to apply.

Billing is per enabled site — you're charged the per-site HIPAA rate for each site you turn it on for, and turning it back off (or archiving the site) removes that charge. The HIPAA settings page shows a running count of how many of your verified sites currently have it enabled.

What changes on a HIPAA-enabled site

Enabling HIPAA on a site changes how a few features behave, so sensitive information is handled carefully:

  • AI chat is turned off on that site. Chat transcripts count as personal information, so the chat widget won't run, won't accept messages, and can't be created there — this is deliberate and can't be overridden per site.
  • Form fields you mark as containing health information are split out of the normal submission and stored encrypted, separate from the rest of the submission's data.
  • Calendar booking custom fields are protected the same way when the site is HIPAA-enabled.
  • Outbound webhooks only fire to hostnames you've approved. Add them under Webhook destinations on the HIPAA settings page — until you approve at least one host, webhooks from HIPAA sites won't fire, and typos or stale URLs are blocked rather than sent.

How your data is handled

Protected fields are encrypted at rest, and the actions in this flow are recorded in an audit trail. If you later stop using HIPAA on a site, you can start a 90-day wind-down from the HIPAA settings page: your protected data stays available for export during that window, after which it is sanitized.

Sorraia relies on a small set of third-party sub-processors to run the service (hosting, email, payments, and so on). You can see the current list, what each one handles, and where it's located on the Sub-processors page at /sub-processors — including a note that our AI page-analysis feature never receives form submissions or health information.

This article describes how the product behaves; it isn't legal or compliance advice. For questions specific to your obligations, talk to your own advisor, and reach us at [email protected] for anything about the flow itself.