Need a BAA, DPA, or security review?
For hospitals, OD schools, multi-location practices, and organisations with formal health-data review, MyopiaTracker can support an Enterprise compliance workflow before identifiable patient data is entered.
Important: Standard Trial and Pro plans do not include a signed HIPAA Business Associate Agreement with iCare Enterprises, LLC and do not include country-specific data residency. If your organisation requires a BAA, DPA, DPIA, local hosting review, transfer impact assessment, or institutional approval, complete Enterprise review before entering identifiable patient data.
Compliance documents clinics commonly request
BAA review
For U.S. HIPAA-regulated workflows where protected health information may be stored or processed in MyopiaTracker.
- Available only by Enterprise or separate written agreement
- Not active until countersigned
- Requires organisation and workflow review
DPA and transfer review
For privacy teams reviewing controller/processor roles, international transfers, and sub-processors.
- United States-based standard cloud processing
- Firebase, Stripe, and optional AI processors
- SCC or other transfer review if required
Security questionnaire
For IT or compliance teams that need technical and operational answers before approval.
- Encryption at rest and in transit
- Authentication and access boundaries
- Incident response and support contacts
Current standard data location
| Area | Standard Trial / Pro handling | Enterprise discussion |
|---|---|---|
| Clinical cloud records | Google Firebase / Firestore configured in the United States | Regional hosting or additional controls may be reviewed only by separate written agreement |
| Authentication | Firebase Authentication, generally United States processing | Institutional identity and access requirements can be reviewed |
| Billing | Stripe processes billing details; MyopiaTracker does not store card numbers | Procurement and invoicing terms can be discussed |
| AI Insights | Optional and user-initiated; direct patient identifiers should not be submitted | AI use can be disabled or restricted by workflow policy |
| Registry | Optional; requires clinician and guardian consent before contribution | Institutional/IRB/ethics review can be supported where needed |
Fast intake checklist
To keep review efficient, include these details in your first email.
Organisation profile
Practice or institution name, country/region, number of clinicians, and whether this is a clinic, school, hospital, or network.
Contract need
Tell us whether you need a BAA, DPA, SCCs, security questionnaire, procurement form, or all of the above.
Data workflow
Describe whether you plan to store identifiable patient names/chart IDs or use internal IDs only.
Special requirements
Flag data residency, AI restrictions, registry restrictions, parent consent workflow, or institutional approval needs.
Ready for compliance review?
Send one email with the checklist above. We’ll respond with the appropriate next step for Enterprise review.
Email Enterprise Compliance →