Business Associate Agreement (BAA)

Last updated: July 7, 2026

When This BAA Applies

This BAA is required only when a Customer creates, receives, maintains, or transmits Protected Health Information (PHI) through the Conversify platform. It is not signed by default. You can sign this BAA electronically through the HIPAA Portal after subscribing to the HIPAA Portal add-on ($39/month) on the Add-ons page. Do not onboard any health data until the BAA is signed.

1. Definitions

Capitalized terms used but not defined in this BAA have the meanings given to them under HIPAA, including the Privacy Rule (45 C.F.R. Part 160 and Subparts A and E of Part 164) and the Security Rule (45 C.F.R. Part 160 and Subparts A and C of Part 164).

"PHI" means Protected Health Information as defined under HIPAA.

"Breach" has the meaning given under 45 C.F.R. §§ 164.401 and 164.402.

"Security Incident" has the meaning given under 45 C.F.R. § 164.304.

2. Permitted Uses and Disclosures of PHI

Business Associate may use and disclose PHI only:

To perform the Services described in the Terms of Service on behalf of Covered Entity

To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c)

For internal administration, legal compliance, and quality improvement

To report violations of law to appropriate authorities

Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity.

3. Safeguards

Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards including:

Encryption of PHI in transit (TLS 1.2+) and at rest (AES-256)

Role-based access controls limiting PHI access to authorised personnel

Regular security risk assessments and remediation

Workforce training on HIPAA compliance

Audit controls logging access to PHI

4. Breach Notification

Following discovery of a Breach of unsecured PHI, Business Associate shall notify Covered Entity without unreasonable delay and no later than 48 hours after discovery, including:

The nature of the Breach and types of information involved

The individuals affected

Steps taken or to be taken to investigate and mitigate

Any steps Covered Entity should take

5. Security Incidents

Business Associate shall report any Security Incident within 48 hours of discovery, excluding trivial incidents (pings, port scans, unsuccessful login attempts) which shall be logged but not individually reported.

6. Subcontractors

Business Associate shall ensure subcontractors agree in writing to the same restrictions as this BAA. A list of subprocessors is maintained at /subprocessors. 30 days’ notice before adding a new subprocessor that processes PHI.

7. Access to and Amendment of PHI

Within 15 business days of a request, Business Associate shall make PHI in a Designated Record Set available to Covered Entity and incorporate amendments as directed.

8. Accounting of Disclosures

Business Associate shall maintain and provide information for accounting of disclosures for the 6 years prior to a request, within 15 business days.

9. Government Access

If Business Associate receives a request from the HHS Secretary, it shall make PHI available and notify Covered Entity within 48 hours.

10. Destruction or Return of PHI

Upon termination, Business Associate shall return or destroy all PHI within 30 days. If infeasible, continue to protect and limit further use.

11. Audit Rights

Covered Entity may audit annually with 30 days’ notice, by itself or a third-party auditor under NDA.

12. Term and Termination

This BAA terminates upon termination of the Services or Covered Entity’s written notice. 30-day cure period for material breaches.

13. Limitations

Liability subject to Terms of Service limitations. This BAA does not authorise use of PHI in violation of HIPAA. Business Associate does not warrant AI outputs constitute medical advice.

14. Miscellaneous

This BAA supplements the Terms of Service. In case of conflict, this BAA controls for PHI.

Governed by laws of Malta and applicable US federal law (HIPAA).

Amendments must be in writing and signed by both parties.

May be executed electronically.

15. Execution

Covered Entity (Customer)

Name: _________________________________

Title: _________________________________

Signature: ____________________________

Date: _________________________________

Business Associate (AppBrewers)

Name: _________________________________

Title: _________________________________

Signature: ____________________________

Date: _________________________________

The HIPAA Portal add-on (including electronic BAA signing) is coming soon. Once available, you will be able to sign the BAA electronically via the HIPAA Portal after subscribing to the add-on. You can also contact legal@conversify.app for assistance.

Business Associate Agreement | Conversify