Business Associate Agreement

Pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
and the Health Information Technology for Economic and Clinical Health Act (HITECH)

⚠ DRAFT — FOR ATTORNEY REVIEW ONLY. This document is a sample template prepared for legal review. It has not been reviewed by a licensed attorney and should not be used as a binding legal agreement until approved by qualified healthcare counsel. Zelavox makes no representation that this template is legally sufficient, complete, or appropriate for any particular jurisdiction or use case.

Recitals

This Business Associate Agreement ("Agreement") is entered into as of the date last signed below ("Effective Date") by and between:

Zelavox, a company operating at zelavox.io ("Business Associate"); and

[COVERED ENTITY NAME], a [type of entity] located at [address] ("Covered Entity").

Covered Entity and Business Associate are collectively referred to herein as the "Parties."

WHEREAS, Covered Entity is a "Covered Entity" as defined under HIPAA; and

WHEREAS, Business Associate provides AI-powered document analysis services ("Services") to Covered Entity, and in connection with providing such Services, may receive, create, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity; and

WHEREAS, HIPAA and HITECH require that Covered Entity and Business Associate enter into a Business Associate Agreement prior to Business Associate receiving, accessing, or processing any PHI on behalf of Covered Entity;

NOW, THEREFORE, in consideration of the mutual promises and covenants contained herein, the Parties agree as follows:

1. Definitions

Unless otherwise defined herein, all capitalized terms shall have the meanings assigned to them under HIPAA, HITECH, and their implementing regulations, including 45 CFR Parts 160 and 164.

"Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under 45 CFR Part 164, Subpart E, which compromises the security or privacy of the PHI.
"Business Associate" has the meaning given at 45 CFR § 160.103.
"Covered Entity" has the meaning given at 45 CFR § 160.103.
"HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
"Protected Health Information" or "PHI" has the meaning given at 45 CFR § 160.103, limited to the PHI created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
"Security Incident" has the meaning given at 45 CFR § 164.304.
"Services" means the AI-powered document analysis services provided by Zelavox to Covered Entity, including document upload, processing, analysis, and return of results.
"Subcontractor" means any third party engaged by Business Associate to assist in the performance of Services that involves the creation, receipt, maintenance, or transmission of PHI.

2. Obligations of Business Associate

2.1 Permitted Uses and Disclosures

Business Associate may use or disclose PHI only as follows:

  1. As necessary to perform the Services on behalf of Covered Entity;
  2. As required by law;
  3. As permitted by this Agreement;
  4. As otherwise permitted under the HIPAA Rules, provided that such use or disclosure would also be permissible by Covered Entity.

Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity.

2.2 Zero Data Retention

Business Associate operates a strict zero data retention architecture with respect to PHI:

  1. PHI transmitted to Business Associate for analysis is processed entirely in volatile memory (RAM) and is never written to persistent storage, disk, database, or any other permanent medium;
  2. PHI is permanently and irreversibly deleted from memory immediately upon completion of the analysis for which it was submitted, typically within ten (10) seconds of receipt;
  3. Business Associate does not retain, backup, log, or archive the content of any PHI at any point;
  4. Audit logs maintained by Business Associate record that a document was processed but do not record the content of that document or any PHI contained therein;
  5. Business Associate's AI provider is contractually bound to equivalent zero data retention standards with respect to any PHI transmitted for analysis.

2.3 Safeguards

Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI, including:

  1. Encrypting all PHI in transit using TLS 1.2 or higher;
  2. Processing PHI in isolated, access-controlled environments;
  3. Restricting access to systems that process PHI to authorized personnel only;
  4. Implementing access controls, authentication, and audit logging on all systems;
  5. Conducting regular security assessments of systems that process PHI.

2.4 Subcontractors

Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement. Business Associate shall obtain written agreement from all such Subcontractors prior to disclosing PHI to them.

2.5 Prohibition on Unauthorized Use

Business Associate shall not:

  1. Use or disclose PHI other than as permitted or required by this Agreement or as required by law;
  2. Use PHI to train, fine-tune, or improve any AI or machine learning model;
  3. Sell PHI or use PHI for any commercial purpose other than providing the Services;
  4. Disclose PHI to any third party except as permitted under this Agreement.

2.6 Individual Rights

Given Business Associate's zero data retention model, Business Associate does not maintain PHI beyond the duration of each transaction. To the extent Business Associate holds any PHI at the time of a request, Business Associate shall:

  1. Provide access to PHI in a Designated Record Set to Covered Entity or, as directed, to an Individual, within the timeframes required by 45 CFR § 164.524;
  2. Make any amendment to PHI in a Designated Record Set as directed by Covered Entity pursuant to 45 CFR § 164.526;
  3. Provide an accounting of disclosures as required by 45 CFR § 164.528.

2.7 Reporting

Business Associate shall report to Covered Entity:

  1. Any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, without unreasonable delay and in no event later than fifteen (15) calendar days after discovery;
  2. Any Breach of Unsecured PHI, without unreasonable delay and in no event later than thirty (30) calendar days after discovery, in accordance with 45 CFR § 164.410;
  3. Any Security Incident of which Business Associate becomes aware, without unreasonable delay.

Given Business Associate's zero data retention architecture, the scope of any potential Breach is limited to PHI actively being processed at the time of the incident, typically a window of less than ten (10) seconds.

2.8 Books and Records

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's or Business Associate's compliance with the HIPAA Rules.

3. Obligations of Covered Entity

3.1 Notice of Privacy Practices

Covered Entity shall notify Business Associate of any limitation in Covered Entity's Notice of Privacy Practices that affects Business Associate's use or disclosure of PHI.

3.2 Individual Permissions

Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose PHI, to the extent that such changes affect Business Associate's permitted or required uses and disclosures.

3.3 Restrictions

Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent that such restriction affects Business Associate's use or disclosure of PHI.

3.4 Permissible Requests

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.

3.5 Authorization

Covered Entity represents and warrants that it has obtained all necessary authorizations, consents, and permissions to submit PHI to Business Associate for processing under this Agreement.

4. Term and Termination

4.1 Term

This Agreement shall be effective as of the Effective Date and shall continue in effect until terminated by either Party in accordance with this Section 4, or until the Services Agreement between the Parties is terminated, whichever occurs first.

4.2 Termination for Cause

Either Party may terminate this Agreement immediately upon written notice if the other Party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) days of receiving written notice of the breach.

4.3 Effect of Termination

Given Business Associate's zero data retention model, upon termination of this Agreement:

  1. Business Associate will have no PHI to return or destroy, as no PHI is retained beyond each transaction;
  2. Business Associate shall certify in writing to Covered Entity that no PHI is held by Business Associate or its Subcontractors;
  3. The provisions of this Agreement that by their nature should survive termination shall survive, including Sections 2.5, 2.7, 3, 5, and 6.

5. Miscellaneous

5.1 Regulatory References

Any reference in this Agreement to a section of HIPAA, HITECH, or their implementing regulations means the section as in effect or as amended.

5.2 Amendment

The Parties agree to amend this Agreement as necessary to comply with changes in applicable law. Either Party may terminate this Agreement if the Parties are unable to agree on an amendment required to bring the Agreement into compliance with applicable law.

5.3 Interpretation

Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Rules.

5.4 No Third Party Beneficiaries

Nothing in this Agreement shall confer any rights or remedies upon any person other than the Parties and their respective successors and permitted assigns.

5.5 Entire Agreement

This Agreement constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, understandings, negotiations, and discussions, whether oral or written, relating to such subject matter.

5.6 Governing Law

This Agreement shall be governed by and construed in accordance with the laws of [STATE], without regard to its conflict of law provisions, and applicable federal law including HIPAA and HITECH.

5.7 Severability

If any provision of this Agreement is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

6. Limitation of Liability

Business Associate's liability under this Agreement shall be limited to direct damages and shall not exceed the total fees paid by Covered Entity to Business Associate in the three (3) months preceding the event giving rise to the claim. In no event shall Business Associate be liable for indirect, incidental, consequential, special, or punitive damages.

Given Business Associate's zero data retention architecture, Business Associate's exposure to liability arising from unauthorized disclosure of PHI is inherently limited to the brief window during which PHI is actively being processed, typically less than ten (10) seconds per transaction.

Signatures

IN WITNESS WHEREOF, the Parties have executed this Business Associate Agreement as of the Effective Date.

Zelavox
(Business Associate)

Authorized Signature
Printed Name
Title
Date

[Covered Entity Name]
(Covered Entity)

Authorized Signature
Printed Name
Title
Date