Business Associate Agreement

Reference summary for covered entities. The executed BAA controls over this summary.

When a BAA is required

If you are a Covered Entity under HIPAA and use protected health information (PHI) in the application, a Business Associate Agreement must be executed before uploading PHI. Contact your account representative to execute.

Safeguards committed under the BAA

PHI is encrypted at rest (AES-256) and in transit (TLS 1.2+). Access is role-based (CNA/LPN/RN/IP/DON/Admin) and enforced in the database with row-level security, with MFA and 15-minute automatic logoff. See the Security & HIPAA Readiness page for the full control list.

Breach notification

We will notify you within 24 hours of discovery of a confirmed breach of unsecured PHI, with the facts known at that time and updates as the investigation proceeds.

Return and destruction

Upon termination, upon written request, PHI is returned or securely destroyed within 30 days, except where retention is required by law (for example, 6-year immutable audit logs).

De-identified data

De-identified, aggregate data may be used for case studies only with your prior written authorization, per 45 CFR §164.514. PHI is never used for marketing.

This page is a reference summary, not the executed agreement, and is not legal advice.