We are currently in process of implementing external recognition as a healthcare client and our legal reps are concerned about PHI - submitters name and email as well as any PHI that may be scrubbed. If you are a healthcare client, how did you handle this? Did you do a BAA or just accepted it as a low risk option? Any info you can share would be great!