---
title: Does iorad Require a BAA?
description: Learn how iorad relates to HIPAA & BAAs, when a business associate agreement may be needed, and how teams can reduce PHI exposure when creating tutorials.
image: https://learning.iorad.com/hubfs/features_and_pricing.png
---

[![iorad](https://learning.iorad.com/hubfs/Iored%20Theme%202021/Images/iorad%20logo%20DONT%20DELETE.png)](https://www.iorad.com/)

- Product
  
  #### Individual
  
  [Tutorial Privacy Control who views your tutorials](https://www.iorad.com/pricing/feature/tutorial-privacy) [Mask Data Control who views your tutorials](https://www.iorad.com/pricing/feature/mask-data) [Basic Audio Text-to-speech & custom voiceovers](https://www.iorad.com/pricing/feature/basic-audio)
  
  #### Team
  
  [Branding Add custom branding](https://www.iorad.com/pricing/feature/custom-branding) [Premium Audio Neural voiceovers and CC](https://www.iorad.com/pricing/feature/premium-audio) [Collaboration Co-edit and publish tutorials](https://www.iorad.com/pricing/feature/team-collab) [Analytics See tutorial performance](https://www.iorad.com/pricing/feature/analytics)
  
  #### Enterprise
  
  [Translations Automatic language translation](https://www.iorad.com/pricing/feature/translations) [Team Accounts Allocate separate accounts](https://www.iorad.com/pricing/feature/team-collab) [Encrypt & Anti-Track Strict compliance & additional data protection](https://www.iorad.com/pricing/feature/encrypt-and-anti-track)
  
  [All plans & Features →](https://www.iorad.com/features)
- Resources
  
  #### Support
  
  [Help Center](https://www.iorad.com/resources/help-center) [Learning Hub](https://learning.iorad.com) [Schedule Demo](https://www.iorad.com/demo)
  
  #### Customers
  
  [Testimonials](https://www.iorad.com/testimonials) [Case Studies](https://learning.iorad.com/customer-stories?_ga=2.48225895.1718347252.1788801042-1263284910.1780521832)
  
  #### Marketplace
  
  [Partnerships](https://www.iorad.com/partner-programs) [Integrations](https://www.iorad.com/connectIntegrations) [Services](https://www.iorad.com/services)
  
  #### Company
  
  [Privacy Policy](https://www.iorad.com/privacypolicy) [About Us](https://www.iorad.com/meet-the-team)
- Use Cases
  
  [EDU](https://www.iorad.com/use-cases/education) [Customer Training](https://www.iorad.com/use-cases/customer-training) [Sales Enablement](https://www.iorad.com/use-cases/sales-enablement) [Learning & Development](https://www.iorad.com/use-cases/learning-and-development)
  
  [HR](https://www.iorad.com/use-cases/human-resources) [Product Management](https://www.iorad.com/use-cases/product-management) [I.T.](https://www.iorad.com/use-cases/information-technology) [Operations](https://www.iorad.com/use-cases/operations)
  
  [All Use Cases →](https://www.iorad.com/use-cases)
- [Pricing](https://www.iorad.com/pricing)

[Try it Free](https://www.iorad.com/signup) [Sign In](https://www.iorad.com/login)

# Does iorad Require a BAA?

[Learning Hub](https://learning.iorad.com/) → [Thought Leadership](https://learning.iorad.com/thought-leadership) →  Does iorad Require a BAA?

![iorad ](https://learning.iorad.com/hubfs/features_and_pricing.png)

iorad does not require a Business Associate Agreement. HIPAA requires covered entities to sign BAAs with vendors that create, receive, maintain, or transmit Protected Health Information on their behalf. iorad is a user-generated content platform. When someone records a tutorial, iorad captures on-screen clicks and steps, not patient data, insurance records, or any protected health information.

The tool never processes or stores PHI on behalf of its users. That distinction puts iorad outside HIPAA's BAA requirement for most healthcare organizations using it to build software training. This article explains the scope, limitations, and how healthcare teams minimize PHI exposure in tutorials.

**Why iorad falls outside HIPAA's scope**

HIPAA requires covered entities to sign BAAs with vendors that create, receive, maintain, or transmit Protected Health Information (PHI) on their behalf. iorad doesn't do any of those things.

iorad is a user-generated content platform. When someone records a tutorial, iorad captures screenshots of what's on screen. It doesn't connect to your systems, extract data, read data fields, or interpret anything in the underlying application. The output is a visual, step-by-step representation — not a data record.

Because iorad never receives or processes PHI, it doesn't qualify as a Business Associate under HIPAA. A BAA is not applicable.

**Your responsibility as a content creator**

While iorad doesn't process PHI, sensitive information can still appear in a tutorial if a creator records in a live production environment without taking precautions. That responsibility sits with your team.

Two controls cover most of the risk.

**Record in non-production environments when possible.**  
Use a test, staging, sandbox, or demo environment with fictional or sanitized data whenever one is available. If your organization has demo accounts or masked datasets, use them. Production environments should be the exception, not the default, and any exception should be documented and approved internally.

**Require a second-person review before publishing.**  
No tutorial should be published, shared externally, or distributed until someone other than the creator has reviewed it. The reviewer should confirm that no PHI, credentials, internal URLs, or other sensitive information appears in screenshots, annotations, transcript text, or downloadable assets.

iorad also gives creators a built-in tool for situations where sensitive data does appear on screen: the blur feature. Any sensitive area can be blurred during capture, and once saved, the blurred version is the only version stored on iorad's servers. No unblurred copy is retained.

**What reviewers should check**

Before approving a tutorial for publish or share, reviewers should confirm that none of the following are visible:

- Real patient or customer names
- Account numbers, financial balances, or transaction history
- Email addresses, phone numbers, or mailing addresses
- Dates of birth, SSNs, tax IDs, or similar identifiers
- Credentials, API keys, tokens, or session details
- Browser tabs, bookmarks, internal URLs, or side panels that expose internal information
- Internal-only confidential business data

If any of these are found, the tutorial should be rejected and corrected before release.

**Keeping records**

For teams that need to demonstrate compliance controls internally, it's worth retaining evidence for each tutorial: the environment used, who created it, who reviewed it, and any exceptions or remediation notes. This gives your InfoSec or compliance team an audit trail without placing any burden on iorad.

A per-tutorial worksheet covering each of these checkpoints is available as a companion to this article. Teams can adopt it as-is or adapt it to fit existing evidence-retention policies.

**Summary**

iorad does not collect, store, or process PHI. It's a screenshot-based content tool, and the data that appears in any tutorial is entirely determined by the person recording it. Because of this, HIPAA's BAA requirement doesn't apply to iorad. The compliance piece is an internal workflow question: record in safe environments, review before publishing, and blur anything sensitive.

![Company Logo](https://learning.iorad.com/hubfs/iorad%20icon.png)

#### Support

- [Help Center](https://www.iorad.com/resources/help-center)
- [Learning Hub](https://learning.iorad.com/)
- [Schedule Demo](https://www.iorad.com/demo)
- [Releases](https://www.iorad.com/release)
- [FAQ](https://www.iorad.com/faq)

#### Pricing

- [Business](https://www.iorad.com/pricing/business)
- [Education](https://www.iorad.com/pricing/education)
- [Non-Profit](https://www.iorad.com/pricing/non-profits)

#### Company

- [About](https://iorad.com/about)
- [Leadership](https://www.iorad.com/leadership)
- [History](https://www.iorad.com/history)
- [Culture](https://www.iorad.com/culture)
- [Careers](https://www.iorad.com/careers)

#### Explore iorad

- [What is iorad](https://www.iorad.com/tutorialbuilder)
- [Features](https://www.iorad.com/features)
- [Compare iorad](https://www.iorad.com/compare)
- [How to use iorad](https://learning.iorad.com/use-cases)
- [Testimonials](https://www.iorad.com/testimonials)

#### Connect

- [Partners](https://www.iorad.com/partner-programs)
- [Integrations](https://www.iorad.com/connectIntegrations)
- [Helping Hands](https://www.iorad.com/helping-hands)
- [Services](https://www.iorad.com/services)
- [Adoption Curve](https://learning.iorad.com/the-adoption-curve)

#### Fine Print

- [Terms of use](https://www.iorad.com/termsconditions)
- [Privacy Policy](https://www.iorad.com/privacypolicy)
- [Cookie Policy](https://www.iorad.com/cookiepolicy)
- [Accessibility](https://www.iorad.com/accessibility)
- [System Status](https://status.iorad.com/)

© Copyright 2026 – iorad Inc. All rights reserved.

[![LinkedIn](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/LinkedIn.png)](https://www.linkedin.com/company/iorad) [![Facebook](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/Facebook.png)](https://www.facebook.com/iorad) [![Instagram](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/Instagram.png)](https://www.instagram.com/iorad) [![YouTube](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/YouTube.png)](https://www.youtube.com/@iorad) [![Twitter](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/Twitter.png)](https://twitter.com/iorad)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Raymond Chuma-Onwuoku",
    "url" : "https://learning.iorad.com/author/raymond-chuma-onwuoku"
  },
  "dateModified" : "2026-06-17T19:47:39.557Z",
  "datePublished" : "2026-05-08T14:56:05.000Z",
  "headline" : "Does iorad Require a BAA?",
  "image" : [ "https://learning.iorad.com/hubfs/features_and_pricing.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://learning.iorad.com/thought-leadership/does-iorad-require-a-baa",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://learning.iorad.com/hubfs/iorad_logo_colour_2021%20(1).png"
    },
    "name" : "iorad"
  }
}
```