Skip to main content

Legal request

BAA Request

If your organization needs to use MARCUS with protected health information, you must complete a contracting and deployment review before submitting PHI. This includes a signed Business Associate Agreement and an approved PHI-capable configuration.

Submitting a request does not authorize PHI use. PHI use is authorized only after the applicable agreements are signed and the workspace is explicitly approved for PHI-enabled use.

Request a Business Associate Agreement for an approved PHI-enabled MARCUS deployment.

MARCUS is PHI-off by default. Public demos, trial workspaces, and uncontracted deployments are not approved for protected health information, patient identifiers, or patient-specific clinical facts. Do not upload, type, paste, or transmit PHI into MARCUS unless your organization has executed a Business Associate Agreement with surgicAI and your workspace has been approved for PHI-enabled use.

Who should request this?

  • Hospitals, health systems, clinics, physician groups, academic medical centers, residency programs, or healthcare institutions.
  • HIPAA covered entities or business associates.
  • Organizations planning to use MARCUS with PHI, ePHI, patient identifiers, or patient-specific clinical facts.
  • Organizations requiring vendor security review for clinical or institutional deployment.

What happens next?

  1. We review the organization, use case, data flow, and deployment needs.
  2. We confirm whether MARCUS can support the requested PHI use case.
  3. We exchange legal and security documents as needed.
  4. If approved, the parties execute a BAA and any related agreements.
  5. We configure or approve a PHI-enabled workspace.
  6. PHI use may begin only after written approval.

Request details to include

This page is a conservative intake checklist. It does not transmit form data from the browser. Send the relevant details to the contact below and do not include PHI, credentials, secrets, or patient-specific facts.

BAA Request intake fields
FieldTypeRequiredNotes
Full nameTextYes
Work emailEmailYes
OrganizationTextYes
Title / roleTextYes
Organization typeHospital, health system, academic medical center, clinic, residency program, business associate, or otherYes
Authority to request legal/security reviewYes / NoYes
Intended MARCUS use caseLong textYesDo not include PHI.
Will users submit PHI or patient-specific facts?Yes / No / UnsureYes
Expected data categoriesInstitutional documents, policies, handbooks, protocols, schedules, PHI, ePHI, audit logs, or otherYes
Expected usersNumberNo
Required deployment typeStandard cloud, private cloud/VPC, on-premises, or unsureYes
Required SSOSAML, OIDC, none, or unsureNo
Security review requirementsLong textNo
Preferred legal contactEmailNo
Requested start dateDateNo
Additional notesLong textNoDo not include PHI.

BAA requests

Send the request packet to legal@surgic.ai.