Before
The HIPAA Business Associate Agreement requirement is clear: any vendor that creates, receives, maintains, or transmits Protected Health Information on behalf of a covered entity or business associate must execute a BAA with the entity that engaged them. When a healthcare SaaS company uses Intercom or Zendesk to manage customer support tickets, and those tickets contain PHI, Intercom and Zendesk are business associates under HIPAA. A BAA must be in place. If it is not in place, the healthcare SaaS company is in violation of the HIPAA Privacy Rule regardless of whether any data breach or misuse has occurred. Both Intercom and Zendesk offer HIPAA-compliant configurations and BAA execution for enterprise accounts. The problem is not that the vendors are unwilling: the problem is that most healthcare SaaS companies that came to these platforms through self-service or startup-tier accounts did not receive the BAA as part of their onboarding, did not request it, and have not reviewed their data handling configuration to ensure it meets HIPAA standards. The AI features of these platforms, in particular Fin and Zendesk AI, may process ticket content in ways that are not covered by a standard BAA. Before enabling AI features on support tickets that may contain PHI, the BAA must be executed, the platform's HIPAA configuration must be activated, and the data handling scope must be reviewed against the BAA terms. This review is a prerequisite for AI deployment in the healthcare SaaS context, and Ignited Nepal completes it before any configuration work begins.
After
HIPAA Business Associate Agreements are in place with AI support vendors, closing the compliance gap that most healthcare SaaS companies carry unknowingly from the day they enable AI features on a support platform that processes PHI.
Before
The business case for AI support automation in the US market is typically framed around the cost per human-handled ticket, which the industry benchmark places at $8 to $15 for a B2B SaaS or e-commerce support operation. If a business handles 500 tickets per week and 60% of them could be resolved by AI, the achievable annual cost reduction from that deflection is $1.25 million to $2.3 million at the industry benchmark range. This is a straightforward calculation. It is also a calculation that the majority of US businesses that have deployed Zendesk AI or Intercom Fin have not performed, because they have not measured their current deflection rate and have not calculated their actual cost per human-handled ticket. Without this measurement, the AI platform subscription is an undifferentiated technology cost rather than an investment with a measured return. Management cannot evaluate whether the current AI configuration is generating value, whether knowledge base improvements would increase the return, or whether the AI deployment should be expanded to additional channels or query categories. The deflection rate measurement requires configuring the Zendesk or Intercom reporting to distinguish AI-resolved from human-handled tickets and defining the resolution criteria correctly. The cost per ticket calculation requires dividing the total support team cost (salaries, benefits, tools, management overhead) by the total weekly ticket volume. Neither calculation is technically complex, but both require deliberate setup that most businesses have not done.
After
The AI deflection rate is measured against the cost per human-handled ticket, making the relationship between AI investment and support cost reduction visible and creating the accountability framework for ongoing AI optimisation decisions.
Before
SOC 2 Type II is the standard security and compliance attestation for enterprise software vendors in the US. When a US business evaluates an AI support tool for enterprise deployment, the security questionnaire from the IT or InfoSec team will request the vendor's SOC 2 Type II report as a baseline requirement. If the vendor cannot provide a current SOC 2 Type II attestation, the procurement will be blocked. Most major AI support platforms (Intercom, Zendesk, Salesforce Einstein) have SOC 2 Type II attestations available. The problem is not vendor compliance: the problem is that the attestation has not been requested, reviewed, and documented by the business as part of the deployment. For financial services businesses and healthcare technology companies, the SOC 2 documentation process is further complicated by sector-specific requirements: the business may need to verify not just the vendor's SOC 2 status but specific controls within the report that are relevant to their regulatory obligations (FINRA, SEC, HIPAA, SOX). Ignited Nepal manages this documentation process as a defined project deliverable: we request the SOC 2 Type II report from the vendor, review the relevant controls against the business's regulatory context, and produce a documented compliance summary that the IT security team can use for internal sign-off. This moves the deployment from the compliance review queue to the configuration phase without requiring the business to assign internal security resources to a vendor evaluation process.
After
SOC 2 vendor compliance is documented for IT security review, removing the procurement blocker that has prevented financial services and enterprise SaaS businesses from deploying AI support tools their teams have been evaluating for months.
Before
The most common reason US businesses are not getting the AI deflection rate their support platform is capable of delivering is that the knowledge base was never properly built for AI use. A knowledge base built for human agents to reference is structured differently from a knowledge base built for AI retrieval. Human-readable articles often have long introductions, general context sections, and information organised by product category rather than by query type. AI retrieval systems perform best with articles that begin with a direct answer to a specific question, use headings that match the language of customer queries, and contain specific accurate information without the contextualising narrative that makes human-readable content more accessible. When Zendesk AI suggests an incorrect article or an article that only partially answers the customer's question, the root cause is almost always in the knowledge base structure and coverage, not in the AI model's capability. A ticket for "how do I add a team member to my account?" should retrieve an article that begins with the exact steps for adding a team member, not an article about account management that mentions team members in a general context several paragraphs in. When the knowledge base is restructured for AI retrieval and the coverage gaps for the top ticket categories are filled, the resolution accuracy and deflection rate improve substantially. This restructuring work is the highest-return investment in AI support performance for US businesses that already have a support platform deployed.
After
Zendesk AI and Intercom Fin resolve the Tier 1 query volume they were purchased to handle, because the knowledge base has been rebuilt for AI retrieval and the coverage gaps that caused escalations have been filled.