When This BAA Applies
This BAA is required only when a Customer creates, receives, maintains, or transmits Protected Health Information (PHI) through the Conversify platform. It is not signed by default. You can sign this BAA electronically through the HIPAA Portal after subscribing to the HIPAA Portal add-on ($39/month) on the Add-ons page. Do not onboard any health data until the BAA is signed.
1. Definitions
Capitalized terms used but not defined in this BAA have the meanings given to them under HIPAA, including the Privacy Rule (45 C.F.R. Part 160 and Subparts A and E of Part 164) and the Security Rule (45 C.F.R. Part 160 and Subparts A and C of Part 164).
"PHI" means Protected Health Information as defined under HIPAA.
"Breach" has the meaning given under 45 C.F.R. §§ 164.401 and 164.402.
"Security Incident" has the meaning given under 45 C.F.R. § 164.304.
2. Permitted Uses and Disclosures of PHI
Business Associate may use and disclose PHI only:
To perform the Services described in the Terms of Service on behalf of Covered Entity
To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c)
For internal administration, legal compliance, and quality improvement
To report violations of law to appropriate authorities
Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity.
3. Safeguards
Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards including:
Encryption of PHI in transit (TLS 1.2+) and at rest (AES-256)
Role-based access controls limiting PHI access to authorised personnel
Regular security risk assessments and remediation
Workforce training on HIPAA compliance
Audit controls logging access to PHI
4. Breach Notification
Following discovery of a Breach of unsecured PHI, Business Associate shall notify Covered Entity without unreasonable delay and no later than 48 hours after discovery, including:
The nature of the Breach and types of information involved
The individuals affected
Steps taken or to be taken to investigate and mitigate
Any steps Covered Entity should take
5. Security Incidents
Business Associate shall report any Security Incident within 48 hours of discovery, excluding trivial incidents (pings, port scans, unsuccessful login attempts) which shall be logged but not individually reported.
6. Subcontractors
Business Associate shall ensure subcontractors agree in writing to the same restrictions as this BAA. A list of subprocessors is maintained at /subprocessors. 30 days’ notice before adding a new subprocessor that processes PHI.
7. Access to and Amendment of PHI
Within 15 business days of a request, Business Associate shall make PHI in a Designated Record Set available to Covered Entity and incorporate amendments as directed.
8. Accounting of Disclosures
Business Associate shall maintain and provide information for accounting of disclosures for the 6 years prior to a request, within 15 business days.
9. Government Access
If Business Associate receives a request from the HHS Secretary, it shall make PHI available and notify Covered Entity within 48 hours.
10. Destruction or Return of PHI
Upon termination, Business Associate shall return or destroy all PHI within 30 days. If infeasible, continue to protect and limit further use.
11. Audit Rights
Covered Entity may audit annually with 30 days’ notice, by itself or a third-party auditor under NDA.
12. Term and Termination
This BAA terminates upon termination of the Services or Covered Entity’s written notice. 30-day cure period for material breaches.
13. Limitations
Liability subject to Terms of Service limitations. This BAA does not authorise use of PHI in violation of HIPAA. Business Associate does not warrant AI outputs constitute medical advice.
14. Miscellaneous
This BAA supplements the Terms of Service. In case of conflict, this BAA controls for PHI.
Governed by laws of Malta and applicable US federal law (HIPAA).
Amendments must be in writing and signed by both parties.
May be executed electronically.
15. Execution
Covered Entity (Customer)
Name: _________________________________
Title: _________________________________
Signature: ____________________________
Date: _________________________________
Business Associate (AppBrewers)
Name: _________________________________
Title: _________________________________
Signature: ____________________________
Date: _________________________________
The HIPAA Portal add-on (including electronic BAA signing) is coming soon. Once available, you will be able to sign the BAA electronically via the HIPAA Portal after subscribing to the add-on. You can also contact legal@conversify.app for assistance.