Calendly is everywhere in healthcare. Telehealth intake coordinators book it without thinking, founders integrate it into patient flows, and billing teams point patients to the link. Then compliance asks: does it sign a Business Associate Agreement? The answer is no. Calendly explicitly does not sign BAAs, which means it cannot legally handle protected health information under HIPAA. If your patients enter their date of birth, insurance details, or reason for visit into a Calendly form, you've created a compliance violation the moment you integrate their data with your EHR. This is not a known limitation that some customers work around. It's a hard architectural choice that Calendly has made. And for telehealth practices expanding into regulated markets—particularly Singapore, where healthcare data protection rules are strict—that choice disqualifies the entire platform. Why Calendly doesn't sign BAAs (and what that means) Calendly's refusal to sign Business Associate Agreements stems from a simple business model: the company treats scheduling data as its own asset, not as data held on behalf of customers. That model works for sales teams, SaaS onboarding, and fitness studios. It does not work for healthcare. Under HIPAA, any vendor that touches protected health information must sign a BAA that specifies: What data they can access and for how long How they handle data breaches and security incidents When and how they delete data after the relationship ends Their obligation to cooperate with HIPAA breach investigations Calendly's terms say that customer data (including scheduling details) is processed under their standard Data Processing Addendum (DPA), which is designed for non-sensitive use cases. A DPA is not a BAA. They are fundamentally different legal instruments. For a practice using Calendly, the risk is direct: if a patient's information is breached and regulators ask who is responsible, the answer is both you and Calendly. But Calendly has no HIPAA obligation, no breach notification requirement under HIPAA, and no audit liability. You carry all of it. Acuity Scheduling: BAA-ready, but payment processing adds friction Acuity Scheduling does sign BAAs. The platform was built for healthcare and wellness practitioners, and they have invested in compliance infrastructure. If you are a telehealth practice in the United States, Acuity will execute a BAA at no extra cost. Acuity's platform includes: Custom intake forms with conditional logic (show specific fields based on patient responses) Automated reminders via email and SMS with no-show rates typically 15–25% lower than Calendly Multi-provider scheduling with timezone mapping Payment processing integrated through Stripe or PayPal HIPAA-compliant file storage for documents (uploaded consent forms, medical history, etc.) The friction point: Acuity's payment processing is not native to the booking system. If a patient books a telehealth visit and you want to collect a deposit or co-pay at the time of booking, Acuity chains Stripe or PayPal through the confirmation email. That means the patient receives a booking confirmation, reads it, clicks a payment link, and then completes payment in a separate window. Conversion drops at each step. For high-volume clinics where payment at booking matters, this flow adds 3–5% to no-payment-collected rate. Acuity pricing is per-provider-per-month ($15–$99 USD depending on feature tier). At eight providers, you are spending $120–$792 monthly just on booking software. Orin: BAA-ready, integrated payments, and unified patient inbox Orin's booking system was built with healthcare workflows in mind. The platform signs BAAs and houses booking alongside your unified messaging inbox , so patient comms, appointment details, and payment status all appear in one place. Key differences from Acuity: Payment at booking: Patients confirm their appointment and complete payment in the same flow. If payment fails, the slot remains available (not held). Conversion on payment is typically 8–12% higher than email-link flows. Intake forms with conditional logic: Ask about insurance only if the patient indicates they have it. Show medication history questions only for established patients. Reduce form friction by 40%+ compared to static intake. Unified inbox: A patient emails, texts, or uses WhatsApp to ask about their appointment. That message lands in the same inbox as their booking, payment status, and visit notes. Your coordinator sees context without switching tabs. Cancellation policy automation: Define refund rules by appointment type and notice period. If a patient cancels 48 hours before, they forfeit 50%. Less than 24 hours, they lose the full deposit. Rules execute automatically; no manual refund processing. Multi-timezone scheduling: If your telehealth practice spans Singapore, Malaysia, and Indonesia, you define time zones per provider. Patient bookings reflect their local time; providers see appointments in their own timezone.