BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement ("Agreement") is entered into as of _____________ ("Effective Date") by and between HIPAA CHAT SERVICE LLC, provider of the HIPAA Chat service ("Business Associate"), and _____________________________ ("Covered Entity") (each a "Party" and collectively the "Parties").
Recitals
Covered Entity wishes to use HIPAA Chat, a software-as-a-service AI work assistant operated by Business Associate, in connection with which Business Associate may create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity. The Parties enter this Agreement to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 CFR Parts 160 and 164 (the "HIPAA Rules").
1. Definitions
Terms used but not otherwise defined in this Agreement have the meanings given in the HIPAA Rules, including: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information ("ePHI"), Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured PHI, and Use. "PHI" in this Agreement means PHI created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
2. Obligations and Activities of Business Associate
Business Associate agrees to:
(a) not Use or Disclose PHI other than as permitted or required by this Agreement or as Required by Law;
(b) use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided for by this Agreement, including without limitation the technical safeguards described in Exhibit B;
(c) report to Covered Entity any Use or Disclosure of PHI not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required at 45 CFR § 164.410, and any Security Incident of which it becomes aware, as follows: (i) an initial report without unreasonable delay and in no case later than five (5) business days after Discovery of a suspected Breach; (ii) a supplemental report containing the information required by 45 CFR § 164.410(c) within fifteen (15) calendar days of Discovery, to the extent then known, supplemented as information becomes available; (customers frequently negotiate these windows — counsel should confirm final timelines; the regulatory outer bound for the Business Associate's report is sixty (60) days). The Parties agree that unsuccessful Security Incidents that occur routinely (pings, port scans, denied login attempts, malware blocked at the perimeter) that do not result in unauthorized access to or acquisition of PHI are hereby reported generically by this sentence and require no further notice;
(d) in accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate with respect to such PHI. Business Associate's Subcontractors as of the Effective Date are listed in Exhibit A (including Amazon Web Services, Inc., with which Business Associate maintains an executed Business Associate Addendum);
(e) make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.524, within fifteen (15) calendar days of a written request. The Parties acknowledge that HIPAA Chat conversation content is workforce work product and is generally not part of a Designated Record Set maintained by Covered Entity; the Parties will cooperate in good faith on any Individual request;
(f) make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 CFR § 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under that section;
(g) maintain and make available to Covered Entity the information required to provide an accounting of Disclosures as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.528;
(h) to the extent Business Associate is to carry out one or more of Covered Entity's obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s);
(i) make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules; and
(j) limit its requests for, Uses of, and Disclosures of PHI to the Minimum Necessary to accomplish the intended purpose.
3. Permitted Uses and Disclosures by Business Associate
(a) Business Associate may Use or Disclose PHI only as necessary to perform the services of the HIPAA Chat platform for Covered Entity: processing user-submitted content (chat messages, uploaded documents, voice audio) to generate responses, documents, transcriptions, and speech through the AI and speech services described in Exhibit A; storing conversation history, files, tasks, and audit records within Covered Entity's isolated tenant; and operating, securing, and supporting the service.
(b) Business Associate may Use or Disclose PHI as Required by Law.
(c) Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, and may Disclose PHI for such purposes if the Disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, Used or further Disclosed only as Required by Law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
(d) Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity as permitted by 45 CFR § 164.504(e)(2)(i)(B).
(e) Business Associate may de-identify PHI in accordance with 45 CFR § 164.514(a)–(c). Information de-identified in accordance with 45 CFR § 164.514(b) (whether by the Safe Harbor method or Expert Determination) is not PHI and is not subject to this Agreement, and Business Associate may use, retain, disclose, and commercialize such de-identified information, and aggregated information that does not identify Covered Entity or any Individual, for any lawful purpose without restriction.
(f) AI processing. PHI submitted to the service is processed transiently through Amazon Bedrock (an AWS HIPAA Eligible Service operating under Business Associate's BAA with AWS) solely to generate the requested response. Model prompts and outputs are not retained by the model provider, are not used to train models, and Business Associate does not permit AWS service teams to use customer content for service improvement. When the service issues a web-search query, it is instructed by policy to formulate the query so that it excludes resident, client, and staff identifiers; this is an operational instruction to the model, not a guaranteed technical filter, and the search provider is not engaged under a BAA and should not receive PHI.
4. Obligations of Covered Entity
Covered Entity shall: (a) notify Business Associate of any limitation(s) in its Notice of Privacy Practices, any changes in or revocation of permission by an Individual, and any restriction on Use or Disclosure of PHI agreed to under 45 CFR § 164.522, in each case to the extent such change affects Business Associate's Uses or Disclosures; (b) not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity (except as permitted for a Business Associate under Sections 3(c)–(d)); and (c) be responsible for the acts and omissions of its workforce members' use of the service, including the content they submit.
5. Term and Termination
(a) Term. This Agreement is effective as of the Effective Date and terminates when all PHI is returned or destroyed pursuant to Section 5(c), or, if return or destruction is infeasible, when protections are extended pursuant to Section 5(c)(ii).
(b) Termination for Cause. Either Party may terminate this Agreement (and the underlying services agreement, at Covered Entity's option) upon material breach of this Agreement by the other Party that remains uncured thirty (30) days after written notice.
(c) Effect of Termination. Upon termination for any reason: (i) Business Associate shall return or destroy all PHI received from, or created, maintained, or received on behalf of, Covered Entity that Business Associate or its Subcontractors still maintain, and retain no copies — for the HIPAA Chat service this means deletion of the Covered Entity's tenant data (conversations, files, tasks, and voice artifacts), with backup and point-in-time-recovery copies aging out on the platform's documented schedule not to exceed thirty-five (35) days; (ii) if return or destruction is infeasible (e.g., audit records retained as Required by Law), Business Associate shall extend the protections of this Agreement to such PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, for so long as it is maintained. Business Associate shall certify deletion in writing upon request.
(d) Sections 2, 3(c), and 5(c) survive termination to the extent PHI is retained.
6. Miscellaneous
(a) Regulatory references. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.
(b) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as required for compliance with the HIPAA Rules. No amendment is effective unless in writing and signed by both Parties.
(c) Interpretation. Any ambiguity shall be interpreted to permit compliance with the HIPAA Rules.
(d) No third-party beneficiaries. Nothing in this Agreement confers any right or remedy on any person other than the Parties.
(e) Relationship to services agreement. This Agreement supplements the services agreement between the Parties; in the event of conflict concerning PHI, this Agreement controls.
Exhibit A — Services and Subcontractors
Service. HIPAA Chat (hipaachat.io): an AI work assistant for [skilled-nursing / ABA] operators — chat, document generation (xlsx/docx/pdf/pptx), document upload and analysis, dictation and voice conversation, background tasks, regulatory reference search, and provider search.
Subcontractor. Amazon Web Services, Inc. — cloud infrastructure. Business Associate has an executed AWS Business Associate Addendum (in force since August 7, 2026) covering this workload's AWS account, and uses exclusively AWS HIPAA Eligible Services in connection with PHI: Amazon ECS/Fargate, Elastic Load Balancing, Amazon CloudFront, Amazon S3, Amazon DynamoDB, Amazon SQS, Amazon SNS, Amazon Bedrock (Anthropic Claude models; HIPAA-eligible model families only), Amazon Transcribe, Amazon Polly, Amazon Cognito, Amazon CloudWatch, AWS Secrets Manager, AWS KMS, Amazon Route 53, Amazon ECR, AWS CodeBuild.
Non-PHI vendors. Web search (Tavily, Inc.) is not engaged under a BAA and is not intended to receive PHI: the assistant is instructed by policy to exclude resident, client, and staff identifiers from outbound search queries (an operational instruction to the model, not a guaranteed technical filter). Payment processing (when enabled) handles billing contact data only, never PHI.
Exhibit B — Security Summary (current state)
- Encryption in transit: TLS 1.2+ on every network hop, including content-delivery-edge to origin.
- Encryption at rest: AWS-managed KMS encryption on all object storage and databases.
- Tenant isolation: per-tenant data partitioning enforced server-side on every read/write path; independently adversarially tested.
- Access control: unique user identities (Amazon Cognito), immutable tenant binding, role-based authorization, session expiry.
- Audit: application audit log, request logs with 90-day retention, infrastructure alarms with operator notification.
- Data lifecycle: uploaded/derived tenant files auto-expire after 90 days; conversations retained until deleted by the user or tenant off-boarding; point-in-time recovery enabled on databases.
- PHI-free notifications: mobile push payloads are static strings containing no user content.
(End of draft. Header/footer notice repeats on every page of the rendered PDF.)
