Security posture should be operational, not abstract
The best answers describe the workflow: when the BAA is sent, how access is limited, what gets configured before launch, and how incidents are communicated.
That level of detail is more useful than a generic compliance badge on its own.