intakeScribe abhix-aiLog inSign up
Legal

Business Associate Agreement

Draft — pending review by legal counsel. Not a binding agreement.
Important: This BAA must be signed before transmitting any Protected Health Information (PHI) through the intakeScribe API. To execute a BAA, contact support@intakescribe.abhix-ai.com.

1. Purpose

This Business Associate Agreement ("BAA") is entered into between the Covered Entity (the customer) and abhix-ai ("Business Associate") to satisfy the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the HITECH Act, and their implementing regulations.

2. Definitions

Terms used but not otherwise defined in this BAA shall have the same meaning as those terms in 45 CFR Parts 160 and 164. Key terms include: "Protected Health Information" (PHI), "Covered Entity," "Business Associate," "Breach," "Security Incident," and "Subcontractor."

3. Permitted Uses and Disclosures

Business Associate may use or disclose PHI only: (a) as necessary to perform the services described in the underlying Service Agreement; (b) as required by law; or (c) for the proper management and administration of Business Associate's operations, provided that any such disclosure is required by law or Business Associate obtains reasonable assurances from the recipient. Business Associate shall not use PHI for any commercial purpose.

4. Safeguards

Business Associate agrees to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI as required by the HIPAA Security Rule (45 CFR Part 164, Subpart C). These include encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, audit logging, and workforce training.

5. Breach Notification

Business Associate agrees to report to Covered Entity any use or disclosure of PHI not provided for by this BAA, including Breaches of Unsecured PHI, within 60 calendar days of discovery. Notification will include: identification of individuals affected, description of the PHI involved, steps taken to mitigate harm, and corrective actions taken.

6. Subcontractors

Business Associate shall require any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate to agree to restrictions and conditions at least as stringent as those in this BAA. Current subprocessors handling PHI include Anthropic (inference) and Railway (hosting). A current list is available upon request.

7. Term & Termination

This BAA is effective upon execution and remains in effect until the termination of the underlying Service Agreement. Either party may terminate the BAA if the other party materially breaches any provision and fails to cure within 30 days of written notice. Upon termination, obligations regarding the protection of PHI shall survive.

8. Return or Destruction of PHI

Upon termination, Business Associate will, at Covered Entity's direction, return or destroy all PHI received from, or created or received on behalf of, Covered Entity. If return or destruction is infeasible, Business Associate will extend the protections of this BAA to the PHI and limit further use or disclosure to those purposes that make return or destruction infeasible.