Business Associate Agreement
Reference summary for covered entities. The executed BAA controls over this summary.
When a BAA is required
If you are a Covered Entity under HIPAA and use protected health information (PHI) in the application, a Business Associate Agreement must be executed before uploading PHI. Contact your account representative to execute.
Safeguards committed under the BAA
PHI is encrypted at rest (AES-256) and in transit (TLS 1.2+). Access is role-based (CNA/LPN/RN/IP/DON/Admin) and enforced in the database with row-level security, with MFA and 15-minute automatic logoff. See the Security & HIPAA Readiness page for the full control list.
Breach notification
We will notify you within 24 hours of discovery of a confirmed breach of unsecured PHI, with the facts known at that time and updates as the investigation proceeds.
Return and destruction
Upon termination, upon written request, PHI is returned or securely destroyed within 30 days, except where retention is required by law (for example, 6-year immutable audit logs).
De-identified data
De-identified, aggregate data may be used for case studies only with your prior written authorization, per 45 CFR §164.514. PHI is never used for marketing.
This page is a reference summary, not the executed agreement, and is not legal advice.