HIPAA Business Associate AgreementThis Business Associate Agreement ("BAA") is entered into by and between EasyTheraNotes ("Business Associate") and the healthcare provider using our platform ("Covered Entity"), and is made effective as of the date the Covered Entity first accesses or uses the EasyTheraNotes platform (the "Effective Date").
1. Definitions
For purposes of this Agreement, the following terms shall have the meanings set forth below:
- "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act and the Omnibus Rule, and all implementing regulations.
- "PHI" means Protected Health Information as defined in 45 CFR § 160.103, limited to the information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
- "ePHI" means Electronic Protected Health Information as defined in 45 CFR § 160.103.
- "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 CFR § 164.402.
- "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined in 45 CFR § 164.304.
- "Subcontractor" means a person to whom Business Associate delegates a function, activity, or service, other than in the capacity of a member of the workforce of such Business Associate.
2. Obligations of Business Associate
Business Associate agrees to the following obligations:
- Permitted Uses and Disclosures: Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law. Business Associate shall use PHI solely to provide clinical documentation services, AI-assisted note generation, audio transcription, calendar management, patient record management, and HIPAA-compliant video conferencing (EasyTelehealth) as described in the EasyTheraNotes Terms of Service.
- Appropriate Safeguards: Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in accordance with 45 CFR Part 164, Subpart C.
- Reporting: Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this Agreement, any Security Incident, or any Breach of unsecured PHI, without unreasonable delay and in no case later than thirty (30) calendar days after discovery.
- Subcontractors: Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of the Business Associate agrees to the same restrictions and conditions that apply to the Business Associate under this Agreement.
- Access to PHI: Business Associate shall make available PHI in a Designated Record Set to Covered Entity within fifteen (15) business days of a request, to satisfy Covered Entity's obligations under 45 CFR § 164.524.
- Amendment of PHI: Business Associate shall make PHI available for amendment and shall incorporate any amendments to PHI as directed by Covered Entity, in accordance with 45 CFR § 164.526.
- Accounting of Disclosures: Business Associate shall make available information required to provide an accounting of disclosures in accordance with 45 CFR § 164.528.
- HHS Access: Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with HIPAA.
- Minimum Necessary: Business Associate shall limit its use, disclosure, or request of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 CFR § 164.502(b).
3. Permitted Uses and Disclosures
Business Associate may use or disclose PHI as follows:
- To perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the EasyTheraNotes Terms of Service, provided that such use or disclosure would not violate the HIPAA Privacy Rule if done by Covered Entity.
- For the proper management and administration of Business Associate, provided that disclosures are required by law or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential.
- To de-identify PHI in accordance with 45 CFR § 164.514(a)-(c) for purposes of analytics and service improvement, provided that de-identified data cannot be re-identified.
- To provide data aggregation services to Covered Entity as permitted by 42 CFR § 164.504(e)(2)(i)(B).
4. Subcontractors and Business Associates
EasyTheraNotes engages the following subcontractors, each of which has executed a BAA covering the services they provide:
| Subcontractor | Services | PHI Handling |
|---|
| Amazon Web Services (AWS) | Cloud infrastructure: DynamoDB (database), S3 (storage), Cognito (authentication), SES (email), CloudWatch (monitoring), Amazon Chime SDK (video conferencing) | Stores and processes ePHI; encrypted at rest (AES-256) and in transit (TLS 1.2+). Chime SDK: real-time encrypted video/audio, no recording or storage |
| OpenAI | AI-powered clinical note generation (GPT-4o) and audio transcription (Whisper API) | Processes PHI transiently; zero data retention policy under BAA; PHI not used for model training |
| Google Cloud (Vertex AI) | Advanced AI processing and clinical data analysis via Vertex AI platform | Processes PHI transiently; zero data retention under BAA; PHI not used for model training |
Each subcontractor BAA includes provisions for: permissible uses and disclosures, appropriate safeguards, breach notification obligations, return or destruction of PHI upon termination, and compliance with all applicable HIPAA requirements.
5. Security Safeguards
Business Associate implements the following safeguards to protect ePHI:
- Encryption: AES-256 encryption at rest for all stored ePHI; TLS 1.2+ encryption in transit for all data transmissions.
- Access Controls: Role-based access control, unique user identification via AWS Cognito, multi-factor authentication (MFA), and automatic session timeout.
- Audit Logging: Comprehensive audit trails via AWS CloudWatch and CloudTrail recording all access to ePHI.
- Data Backup: DynamoDB Point-in-Time Recovery (PITR) with continuous backups retained for 35 days; daily on-demand backups retained for 90 days.
- AI Processing Security: PHI sent to AI providers is limited to the minimum necessary; no PHI in system-level prompts; zero data retention by AI vendors; contractual prohibition on training with PHI.
- Audio Data: Audio recordings are encrypted during upload, processed for transcription, and permanently deleted immediately after transcription is complete.
- Telehealth Security: Video sessions via Amazon Chime SDK use end-to-end encryption. No audio or video is recorded or stored. Session metadata is retained for 30 days with automated TTL expiration. Each session uses unique meeting credentials that expire upon session end.
- Vulnerability Management: Regular security assessments, vulnerability scanning, and timely patching of identified vulnerabilities.
6. Breach Notification
- Discovery and Reporting: Business Associate shall report to Covered Entity any Breach of unsecured PHI without unreasonable delay and in no case later than thirty (30) calendar days after discovery of such Breach.
- Content of Notification: The notification shall include: (a) identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; (b) a brief description of what happened; (c) a description of the types of unsecured PHI involved; (d) any steps individuals should take to protect themselves; (e) a description of what Business Associate is doing to investigate, mitigate harm, and protect against further breaches.
- Cooperation: Business Associate shall cooperate with Covered Entity in the investigation, mitigation, and remediation of any Breach and shall comply with all applicable breach notification requirements.
- Mitigation: Business Associate shall take prompt corrective action to cure any breach and mitigate any harmful effects of the breach to the extent practicable.
7. Term and Termination
- Term: This Agreement shall be effective as of the Effective Date and shall remain in effect for the duration of the underlying service agreement between Business Associate and Covered Entity.
- Termination for Cause: Either party may terminate this Agreement if the other party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) days of receiving written notice of the breach.
- Effect of Termination: Upon termination, Business Associate shall return or destroy all PHI received from, or created or received on behalf of, Covered Entity. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.
- Survival: The obligations of Business Associate under this Section shall survive the termination of this Agreement.
8. Obligations of Covered Entity
- Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI.
- Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI.
- Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522.
- Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule if done by Covered Entity.
- Covered Entity warrants that it has obtained all necessary consents and authorizations from individuals as required by HIPAA for the use and disclosure of PHI by Business Associate.
9. General Provisions
- Regulatory References: Any reference to a section of HIPAA or its implementing regulations shall mean the section as in effect or as amended.
- Amendment: The parties agree to take such action as is necessary to amend this Agreement from time to time to comply with the requirements of HIPAA and its implementing regulations.
- Interpretation: Any ambiguity in this Agreement shall be resolved to permit compliance with HIPAA.
- No Third-Party Beneficiaries: Nothing in this Agreement shall confer upon any person other than the parties and their respective successors or assigns any rights, remedies, obligations, or liabilities.
- Governing Law: This Agreement shall be governed by and construed in accordance with applicable federal law, including HIPAA. To the extent not preempted by federal law, the laws of the state in which the Covered Entity practices shall apply.
- Indemnification: Business Associate shall indemnify and hold harmless Covered Entity from and against any claims, losses, or damages arising from Business Associate's breach of this Agreement or violation of HIPAA.
10. Contact Information
For questions about this Business Associate Agreement or to report a security concern, please contact:
Notice: By creating an account and using the EasyTheraNotes platform, Covered Entity acknowledges and agrees to the terms of this Business Associate Agreement. This BAA is incorporated by reference into the EasyTheraNotes Terms of Service.