Business Associate Agreement

Last updated: 2026-10-09 (version 2026-10-09)

This Business Associate Agreement ("BAA") is between the customer accepting it ("Covered Entity") and SafeBridge ("Business Associate") and applies to the extent SafeBridge creates, receives, maintains or transmits Protected Health Information ("PHI") on behalf of Covered Entity through the Service, as required by the Health Insurance Portability and Accountability Act of 1996 and its regulations, as amended by the HITECH Act (together, "HIPAA"). Capitalized terms not defined here have the meanings in HIPAA (45 CFR Parts 160 and 164). If Covered Entity is itself a business associate, "Covered Entity" includes it in that role.

1. Permitted uses and disclosures

2. Safeguards

Business Associate will use appropriate safeguards and comply with the HIPAA Security Rule with respect to electronic PHI to prevent use or disclosure other than as provided by this BAA. These include administrative, physical and technical safeguards such as encryption in transit and at rest, access control, unique user authentication, audit logging and separation of each customer's stored data.

3. Reporting; breach notification

Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA, any Security Incident of which it becomes aware (unsuccessful attempts such as pings and port scans are reported in aggregate form only, on request), and any Breach of Unsecured PHI, without unreasonable delay and in any event within 10 business days of discovery (and sooner where required by law). The report will describe, to the extent known, the nature of the event, the PHI and individuals involved, what Business Associate has done to mitigate it, and a contact for further information. Business Associate will cooperate in Covered Entity's investigation and notifications to individuals, regulators and media, as Covered Entity determines.

4. Subcontractors

Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as this BAA. Covered Entity acknowledges that Business Associate uses Google Cloud as a subcontractor to host the Service.

5. Individual rights

Within 15 days of Covered Entity's request, Business Associate will make PHI in a designated record set available so Covered Entity can meet its access obligations under 45 CFR 164.524, make PHI available for amendment and incorporate amendments under 164.526, and provide the information needed for an accounting of disclosures under 164.528. Business Associate will forward to Covered Entity any request it receives directly from an individual. Covered Entity is responsible for responding to individuals.

6. Books and records

Business Associate will make its internal practices, books and records relating to PHI available to the Secretary of Health and Human Services for determining compliance with HIPAA. To the extent Business Associate carries out a Covered Entity obligation under the Privacy Rule, it will comply with the requirements that apply to Covered Entity.

7. Covered Entity responsibilities

Covered Entity will send PHI to the Service only as permitted by HIPAA, will notify Business Associate of limitations in its notice of privacy practices or restrictions on use or disclosure of PHI that may affect Business Associate, and is responsible for the security of its own systems, including the edge server it operates, until PHI reaches the Service. Covered Entity will not ask Business Associate to use or disclose PHI in a way that would violate HIPAA.

8. Term and termination

This BAA takes effect when Covered Entity accepts it and remains in effect while Business Associate holds PHI. Either party may terminate the Terms of Service and this BAA if the other materially breaches this BAA and does not cure the breach within 30 days of notice; if cure is not possible, termination may be immediate.

9. Return or destruction of PHI

On termination, Business Associate will, where feasible, return or destroy all PHI it maintains in any form, and retain no copies. A trial account that is not converted is treated as terminated when the trial ends; Business Associate will hold the data for a reasonable period (up to 90 days) so Covered Entity can request export, and then destroy it. Storage versioning and backup retention may delay physical deletion; during any such period the protections of this BAA continue. If return or destruction is infeasible, Business Associate will extend this BAA's protections to the PHI and limit further use and disclosure to the purposes that make return or destruction infeasible. Business Associate will certify destruction on request.

10. General

This BAA is governed by the same law as the Terms of Service. It supersedes any conflicting term of the Terms of Service regarding PHI. Any ambiguity is resolved to permit compliance with HIPAA. Changes in HIPAA law automatically apply, and the parties will amend this BAA as needed. Nothing here creates rights in third parties.

Contact: support@safebridge.io.